AI agents don’t just answer questions. They access data, call tools, and take actions, often autonomously. Without a governance framework, it’s hard to answer basic questions:
What is this agent allowed to do?
Under whose authority is it acting?
How do we prove what happened when something goes wrong?
This session shows how to treat AI agents as first-class citizens in your existing governance model.
You’ll learn how to:
Explain governance as an overarching policy-and-accountability framework and distinguish it from, yet connect it to, safety, security, compliance, and observability.
Map the governance control surface across external actions, tool use, prompts, context and retrieval, memory and state, model behavior, and identity boundaries.
Identify core risk categories in agent workflows: access and data risks (unauthorized access, data leakage), behavioral risks (unsafe or unapproved actions, policy violations), prompt injection (direct and indirect), and oversight gaps.
Define autonomy boundaries for AI agents—what they may decide autonomously, what requires meaningful human approval, and what must remain human-only—using patterns like threshold-based approvals and separation of duties.
Apply least-privilege thinking to agent access and permissions, distinguishing between acting on behalf of a user and acting as a service account and understanding why conflating them introduces governance risk.
Design governance architecture and policy enforcement: where application- and platform-layer controls live, how to implement allowlists and denylists, action gating, rate limits, data handling rules, and memory governance.
Capture and structure audit artifacts across the agent lifecycle (logs, traces, decision records, tool calls, approvals) and define who owns rollback and cleanup when agents fail mid-task.
Operate continuous governance: change management for models and prompts, ongoing policy testing and red-teaming, and managing behavioral drift, configuration drift, and permissions creep over time.
Watch this session to turn “we should govern our agents” into concrete policies, controls, and evidence your stakeholders can rely on.
