AI Agent Governance and Accountability

AI agent governance is how an organisation controls what its autonomous agents may do and assigns responsibility for what they did. It rests on three things: delegated, attenuated authority so an agent holds only the powers it was granted; a policy plane that gates action as allow, deny, or escalate; and a named accountable human who answers for the agent. Governance is the difference between deploying capability and deploying it responsibly.

Question
Who authorised it, and who is responsible
Controls
Authority, policy, escalation, audit
Default
Deny; escalate the uncertain
Accountability
A person, not a field

The question few answer

Most agent work is about making agents capable. Governance answers the question that follows and that far fewer address: when an autonomous agent acts, who authorised it and who is responsible? An estate that cannot answer that cannot safely deploy agents at all.

The mechanisms are concrete: least-privilege authority, a deny-by-default policy engine, human-in-the-loop for consequential actions, and an audit trail so every action can be traced. Accountability resolves to a named human — not because machines are untrustworthy, but because someone must answer.

Questions

Who is responsible when an AI agent acts?

The human or organisation that authorised it, established through the delegation chain. Accountability is assigned before the agent acts, not reconstructed after.

When should an agent ask a human?

When an action is consequential or falls outside the policy it was given. Escalation is designed in as a normal outcome, not treated as a failure of autonomy.

Where this lives in the estate

FlashyOS — the governance and policy surface

Keep reading

related
Delegated Authority for AI Agents
related
What Is AI Agent Identity?
related
What Is an Autonomous Agent Organization (AAO)?
related
The Consent Layer of the Agentic Internet
related
Verify, Don’t Trust: Verification for AI Agents
related
What Is an Agent Policy Engine (and Why Deny-by-Default)?
related
When Should an AI Agent Escalate to a Human?
related
How Do You Audit an Autonomous AI Agent?
related
Kill Switches and Dead-Man’s Switches for Autonomous Organizations
referenced by
AAO vs DAO: What Is the Difference?
referenced by
How Do Autonomous Agents Pay?
referenced by
Provenance for Autonomous Actions
referenced by
How Should AI Agents Authenticate?
referenced by
Zero-Trust Architecture for AI Agents
referenced by
Human-in-the-Loop vs On-the-Loop vs Autonomous Agents
referenced by
Why AI Agents Need Institutions, Not Just Capabilities
referenced by
AI Agents vs Bots: What Is the Difference?
referenced by
Agentic AI vs Generative AI
referenced by
The Seven Layers of the Agentic Internet
referenced by
What Is Agent Memory?
referenced by
Who Is Liable for an Autonomous Agent Organization?
referenced by
Agent-Native Finance: AI Agents in Financial Services
referenced by
Agent Compliance and Regulation
referenced by
Managing the Risk of Autonomous Agents

By Michael Gord · published 2026-09-27 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.