Governing agentic AI: what changes when software acts
Agents extend the AI governance problem from what people ask to what systems do. A brief on the identity, permission, and evidence questions that follow.
Assistants answer questions. Agents take actions. That distinction is the whole of the governance problem that agentic AI introduces.
When an agent books travel, files a ticket, modifies a record, or executes code, it does so under some identity, with some set of permissions, on behalf of some person or process. Existing AI governance, focused on which tools people use and what they submit to them, has little to say about any of that.
Three questions agents force
Under which identity does the agent act? Agents that share a service account are invisible in the audit trail. Agents that impersonate the requesting user inherit permissions that may be far broader than the task requires. Neither is acceptable at scale. Governance needs to see agent activity as agent activity, attributed to both the agent and its principal.
What is the agent permitted to do? Permission for an agent is not a single grant. It is a scope: the systems it may touch, the actions it may take, the data it may read or write, and the conditions under which a human must approve. Those scopes need to be defined, enforced through the controls that already govern access, and recorded.
What did the agent actually do? Evidence for agents means an attributable, time-stamped record of actions taken, not only prompts submitted. This is the same evidence discipline that applies to human AI use, extended to a new class of actor.
Continuity with what already works
The good news is that the governance foundation does not change. Discover the agents in operation. Attribute their activity to identities and principals. Assess it against policy and data sensitivity. Govern through approvals and exceptions. Contain through enterprise controls such as identity, endpoint, and network platforms. Evidence the outcomes against the frameworks that require them.
QAISG is extending QWatch along exactly that path, treating agents as a first-class category of AI activity rather than a separate product problem.
- Agentic AI
- Identity
- AI governance