David W. Koran · CyberAB Registered Practitioner Advanced · ISO/IEC 27001 Auditor and Implementer dkoran@davidkoran.com · (802) 335-2662
AI Governance White Paper

Agentic AI Governance: Before an AI Agent Gets Authority to Act

An Executive Control Framework for Authorizing, Limiting, and Auditing AI Agents

David W. Koran August 2026 12 pages PDF

Download the White Paper

The question the paper answers

The question that separates one generation of business AI from the next is not whether a company uses artificial intelligence but whether an AI system holds authority to act. A tool that drafts a message for a person to review operates under a different set of concerns than a tool that sends the message itself, schedules the delivery, executes the payment, or changes the record. The second kind of system is an agent, and an agent requires a form of governance most organizations have never applied to software: the deliberate grant, limitation, and audit of authority.

This paper gives management a control framework to apply before that authority is granted. It is written for executives, owners, and the counsel and advisors who support them, in the language of controls they already operate: access authorization, signature authority, spending limits, segregation of duties, and accountability for actions taken.

No system, however it arrives, exercises authority to act until the decisions have been made and recorded. The rule can be adopted without purchasing anything, and it converts the vendor update path from a surprise into a routine review.

From the paper, on the standing rule

The eight decisions

The framework consists of eight management decisions, made and documented before an agent operates. What the agent may read, stated positively by data class, with external content treated as untrusted input. What actions it may execute, with financial and operational limits stated as numbers and tested before deployment. Where human approval is required, set by consequence and reversibility rather than model quality. What identity and privileges the agent operates under, distinct, attributable, and least-privileged, with segregation of duties intact. How its actions are logged, monitored, and reconstructed through an observable evidence trail at the system boundary. What the vendor is responsible for, in writing, before authority is granted. How the agent is shut down and its actions reversed, tested in advance. And how its authority expires and is renewed on a risk-based cycle, with agent incidents routed through the processes the company already runs.

The decisions are consistent with risk management and governance themes in the NIST AI Risk Management Framework and ISO/IEC 42001, and with the agent-specific standards work NIST opened in 2026 on agent identity, authorization, and the monitoring of deployed AI systems. The references anchor every regulatory and framework claim to its canonical source.

How agents actually arrive

The paper examines three arrival paths: deliberate procurement, a vendor update that adds an agentic capability to a tool the company already approved, and unapproved adoption by an employee. The vendor update path deserves the most attention, because it bypasses every existing checkpoint. The tool was approved before it could act, and no procurement review is triggered because nothing was procured. The framework is built so that this path becomes a routine review rather than a discovery after the fact.

A worked example with a completed decision record

The framework is applied end to end at a 50-person precision machining business, the same company that appears throughout this series, when a platform vendor ships a release adding a send-on-behalf assistant and an auto-reply capability, both enabled by default. The review runs the eight decisions in a single meeting, sets numerical limits and an approval threshold, tests the boundaries, declines one capability the vendor enabled by default, and produces a signed AI Agent Authority Decision Record. The completed record appears in the paper as a filled-in form, not a blank template, covering risk classification, owners, authorization scope, limits, identity, logging, monitoring, testing, vendor responsibility, shutdown, reauthorization, and incident routing.

A governance process that produces no refusals over time is worth examining, since the pattern suggests the review is confirming decisions rather than making them.

From the paper, on the declined capability

Read the full paper

Twelve pages, including the eight-decision framework, the worked example, and the completed AI Agent Authority Decision Record.

Download the PDF

Questions this paper answers

Short answers below; the paper treats each in full.

What makes an AI agent different from a chatbot or drafting tool?

A generative tool produces content that a person then reviews and uses; a person stands between the output and the world. An agent can act on its own within a defined scope: it sends the message, books the appointment, places the order, updates the record, or initiates the payment. The property that matters for governance is delegated authority, the point at which software can alter the state of the business without a person touching the change.

When does an AI feature need agent-level governance?

The trigger is authority to act, not the sophistication of the model. When a system can communicate externally, change a record, initiate a transaction, or commit the company in any way without a person releasing each action, it should pass through the eight decisions before it operates, however the capability arrived.

What if the agent arrived in a vendor update we never separately approved?

This is the arrival path that deserves the most attention, because it bypasses every existing checkpoint: the tool was approved before it could act, and no procurement review is triggered because nothing was procured. The answer is a standing rule that no system exercises authority to act until the framework decisions have been made and recorded, which converts a vendor update from a surprise into a routine review.

Can an AI agent be allowed to read Controlled Unclassified Information (CUI)?

Not until the agent, its connected systems, any service providers involved in its operation, and its data paths have been scoped under DFARS 252.204-7012 and the CMMC scoping requirements at 32 CFR 170.19. Export controlled technical data requires a separate analysis under the ITAR or the EAR, because those questions turn on who can receive the information, not only on which system holds it.

What should management document when approving an agent?

A signed authority decision record covering the system and feature, risk classification, owners, read and action authorization, numerical limits, the approval threshold, identity and privilege, logging, monitoring, testing completed, vendor responsibility, any declined capability, the shutdown and rollback procedure, the reauthorization date, and incident routing. The paper includes a completed example of the record.

How often should an agent's authority be reviewed?

Authority should carry a risk-based expiration date. Six months is a practical starting point for an agent holding meaningful authority, with immediate review following any material change to the model, the tools, the data sources, the permissions, or the vendor terms.

About the author

David W. Koran is a CyberAB Registered Practitioner Advanced (RPA) and the founder of a consulting practice serving Defense Industrial Base contractors and their legal counsel. His work focuses on CMMC readiness, enablement, and implementation. He holds ISO/IEC 27001 certifications as an auditor and implementer, is an Associate Member of the American Bar Association Section of Public Contract Law, and is the author of The CMMC Decision.

He can be reached at dkoran@davidkoran.com or (802) 335-2662.