AI Agent Governance and Accountability
AI agent governance is how an organisation controls what its autonomous agents may do and assigns responsibility for what they did. It rests on three things: delegated, attenuated authority so an agent holds only the powers it was granted; a policy plane that gates action as allow, deny, or escalate; and a named accountable human who answers for the agent. Governance is the difference between deploying capability and deploying it responsibly.
The question few answer
Most agent work is about making agents capable. Governance answers the question that follows and that far fewer address: when an autonomous agent acts, who authorised it and who is responsible? An estate that cannot answer that cannot safely deploy agents at all.
The mechanisms are concrete: least-privilege authority, a deny-by-default policy engine, human-in-the-loop for consequential actions, and an audit trail so every action can be traced. Accountability resolves to a named human — not because machines are untrustworthy, but because someone must answer.
Questions
Who is responsible when an AI agent acts?
The human or organisation that authorised it, established through the delegation chain. Accountability is assigned before the agent acts, not reconstructed after.
When should an agent ask a human?
When an action is consequential or falls outside the policy it was given. Escalation is designed in as a normal outcome, not treated as a failure of autonomy.
Where this lives in the estate
FlashyOS — the governance and policy surface
Keep reading
By Michael Gord · published 2026-09-27 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.