The focus shifts from static model review to runtime control over delegation, tool use, and execution scope. That matters because the security risk now sits in what the system can do during action, not only in what the model can generate. Governance must therefore follow behaviour, not just deployment.
From model review to behaviour review
Once governance has to cover agent behaviour, the question stops being “is the model acceptable?” and becomes “what is the system allowed to do, under which conditions, and with what oversight?” That changes the unit of control from output quality to runtime authority. The practical shift is that policy must follow the agent’s actions, not just the model’s deployment state.
For AI agents, that means governance has to evaluate delegation, tool access, action boundaries, and approval points as first-class controls. A model can be technically safe in isolation and still create unacceptable exposure once it can call tools, chain steps, or act on behalf of a user.
Behavioural governance also forces a different evidence standard. Static documentation tells you what was approved at release; runtime controls tell you whether the agent stayed within its assigned scope during operation. That is why behaviour-based governance usually needs logs, policy decisions, and revocation paths, not only model cards or pre-launch review notes.
Why runtime authority changes the risk profile
The central risk is that harm now comes from permitted action, not only from generated content. If an agent can access systems, move data, or trigger workflows, the exposure is defined by blast radius, not just by the correctness of its responses. Governance has to ask whether the agent can make a bad day worse by taking an action it should never have been able to take.
That shifts the main control question from “did we approve this model?” to “did we constrain the agent’s execution scope tightly enough?” The answer depends on whether access is task-scoped, whether high-impact actions require step-up approval, and whether the environment can distinguish ordinary output from consequential execution.
It also changes how exceptions are handled. With model-centric governance, an exception may be about quality, bias, or content safety. With agent-centric governance, an exception may be about delegated authority, uncapped tool use, or an overbroad route from prompt to production action.
What effective agent governance has to cover
Behaviour-based governance normally needs four control layers: identity or principal binding, delegated authority, tool and resource constraints, and event-level oversight. Those controls work together. If any one of them is missing, the agent can still behave within the model’s language limits while exceeding the organisation’s risk tolerance.
That is why this topic is better understood through AI Agent Authorisation Guide and Agentic AI Identity Guide: the point is not just to recognise an agent, but to bind its actions to a defined authority model and retirement path. Governance also needs detection and response capability, which is why AI Agent Observability, Audit and Incident Response Guide is relevant when you want to know whether the agent stayed inside policy after launch.
In practice, the strongest governance programmes tie policy to observable behaviour: what the agent may call, what it may change, which requests need human approval, and what gets suspended when risk rises. Without that linkage, “governance” stays advisory while the agent’s permissions remain operational.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and CSA MAESTRO address the attack surface, NIST AI RMF and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 42001:2023 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 42001:2023 | 4.2 — Understanding the needs and expectations of interested parties | Agent governance must define who authorizes and oversees runtime agent behaviour. |
| Recommendation — Define accountable owners and oversight expectations for agent actions. | ||
| NIST AI RMF | GOVERN — Govern | The subject is AI governance shifting to runtime behaviour, authority, and oversight. |
| Recommendation — Establish governance for delegated agent actions and escalation. | ||
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Agent behaviour control hinges on limiting delegated authority and excessive privileges. |
| Recommendation — Restrict agent privileges and require action-level authorization. | ||
| CSA MAESTRO | GOVERN — Governance | Agent behaviour governance requires policy, oversight, and operational control across autonomous workflows. |
| Recommendation — Tie agent autonomy to explicit governance and approval controls. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Runtime agent scope must be minimized to reduce damage from permitted actions. |
| Recommendation — Apply least privilege to constrain agent tool and system access. | ||
Practitioner Guidance
What to prioritise: Start with the actions that can create irreversible or externally visible impact, such as data movement, transaction initiation, configuration changes, and cross-system writes. Those are the places where behavioural governance must be strictest.
What to verify: Confirm that the agent’s effective permissions are narrower than its possible instructions. If the agent can reach a tool, endpoint, or workflow it does not need for the task, the governance model is too loose.
Decision rule: If an action can materially affect a production system, require a policy decision, an approval gate, or both before the action executes. If the action is low-risk and reversible, automate the decision only when you can still attribute and roll it back.
What practitioners underestimate: Monitoring alone is not governance if the system cannot prevent or contain the bad action. A well-logged policy violation that still executes is an incident response aid, not a governance control.
Practitioner takeaway: Behavioural governance succeeds when the organisation can bound, approve, and revoke agent action in real time, not when it can merely describe the model that produced the action.