Governing Agentic AI: Practical Steps for Managing AI Agents Safely

George Ryan
|
Consultant at URM
Neil Jones
|
Senior Consultant at URM
|
PUBLISHED on
09
October
2026
Article Summary

In this blog, George Ryan and Neil Jones, explore the growing use of AI agents and agentic AI and the risks these systems pose, including:

  • How generative AI, AI agents and agentic AI differ
  • The key risks associated with agentic systems
  • Practical controls organisations can implement to improve oversight, accountability and security
  • How established AI governance frameworks such as ISO/IEC 38507 (ISO 38507), ISO/IEC 42001 (ISO 42001) and the NIST AI Risk Management Framework (RMF) can support the responsible use of AI agents.

‍

Many organisations exposed to AI today simply use it through a chat function.  You prompt, and the AI responds, generating new content, such as text.  AI agents differ fundamentally to this.  Rather than simply responding, they can reason, plan, take actions and reassess their plans without needing human intervention.  Beyond simple AI agents, organisations can utilise agentic AI, often consisting of multiple agents working together providing a system-level capability.  While this increased autonomy can unlock significant business benefits, it also introduces additional risks and complexity, making effective governance and oversight even more important.

In practice, the first governance challenge is often not a failure resulting from the use of AI.  It is discovering to what extent teams are already experimenting with agents, connecting them to business systems and granting permissions before ownership and oversight have been agreed.  This is why organisations should establish visibility and accountability early, rather than waiting until agentic AI becomes business-critical.

How do AI agents and agentic AI work in practice?

Unlike generative AI, which typically supports individual tasks, agentic AI can coordinate activities across multiple functions.  If we consider AI agents as the different members of a football team, then the agents are the players, working together but with different roles (e.g., goalkeeper, defence, midfield attack), governed by the manager, to achieve the goal of winning the match.

Consider the use of AI in the onboarding of new employees in an organisation:

What is the need for governance of agentic AI?

When used correctly, AI agents and agentic AI can be a business enabler.  Unlike general purpose AI tools, AI agents can be tailored to specific business objectives and workflows.  They can introduce significant benefits, such as increasing operational efficiency, aiding in decision making, improving customer experience and identifying trends.  

However, this comes at a trade-off.  As we have seen with organisations adopting increasingly advanced AI capabilities, greater autonomy is often accompanied by a greater potential for unintended outcomes.  Improper usage can significantly increase your organisation’s risk, as the complex interactions of the different agents can be difficult to predict, test and manage.  Without appropriate governance, these risks can lead to a range of adverse outcomes, such as unintended information disclosure, service disruption, reputational damage, and financial impacts, to name but a few.

AI governance is already crucial for organisations using generative AI seeking to manage AI-related risks effectively.  If you are looking to further increase your organisation’s AI capability through agents, strong governance becomes even more essential due to their greater autonomy and complexity, as well as their increased capacity to create widespread impacts if they fail or behave unexpectedly.

My agents only use established AI models, why should I care?

Often, organisations build agents using existing AI models instead of creating their own models from scratch.  However, taking this approach does not relieve your organisation of its responsibilities.  Although it would be easy to assume that governance of the models used is solely the responsibility of the model creators, your organisation is responsible for how it uses the model, i.e., how it behaves, what it can access, and what actions it can perform.

Critically, you need to govern the agent, not the model.  Whilst the same model can be used for both generative AI purposes (chat, drafting) and agentic systems (autonomous actions, decisions), these very different uses require separate governance.

In our earlier onboarding example, we had agents for onboarding, IT support, facilities, HR as well as the generative AI itself.  Each of these agents, even if using the same underlying model, have different access, instructions and capabilities, which in turn necessitate subtly different governance.

How do I start?

The first step is to understand your AI system landscape.  Start by identifying every agent involved in the agentic AI system and defining the scope of each one.  For each agent, establish what it is intended to do, who will use it or have access to it, which systems and information it needs access to, and which actions it can perform.  Then compare the access requested with the access genuinely required.  In our experience, this simple exercise often reveals unclear ownership, duplicated capabilities and permissions that are broader than the agent’s role requires.  As with an employee, an agent should only be permitted to access information and perform actions necessary for its role.

A useful lesson from governance reviews is not to rely solely on a central list of approved AI tools.  Speak to the teams designing workflows, ask which systems their agents can access and verify the permissions in practice.  The gap between an agent’s intended role and its actual access is often where the most significant risks emerge.

What risks should I be aware of, and what can I do?

The table below draws on the issues we most frequently encounter when discussing or reviewing AI agent deployments with organisations.  It sets out why each issue matters and the practical measures that can help reduce the risk.

Risk

Why

Mitigation

Why

Excessive scope

A wider access scope for individual agents increases the likelihood of unintended actions or inappropriate use of data and systems.

Limit scope

Restricting agents to only what is necessary reduces unnecessary exposure.

Excessive permissions

An agent with too much permission has an increased likelihood of exceeding its defined scope, greatly increasing the impact and likelihood of unintended actions or inappropriate use of data and systems.

Limit Permissions

Permissions should be limited to what is necessary, ensuring agents can only perform the actions required for their scope (role).

Excessive resources

Unnecessary use of resources can increase cost and reduce efficiency.

Document the required resources

Limiting resource usage and documenting resources required will help you to understand what individual agents need.

Inconsistent outputs

Responses may vary depending on how a request is phrased or interpreted, leading to inconsistent outcomes.

Standardise rules and context

Providing predefined instructions and embedded context will facilitate consistent behaviour regardless of how inputs are framed.

Outdated or incorrect information

Reliance on outdated or incorrect data can lead to decisions or actions that do not align with current policy.

Use controlled and approved sources

Ensuring agents reference centrally managed and up-to-date sources improves accuracy and aligns outputs with current organisational standards. This should be supported by well-governed data management.

Incorrect or incomplete interpretation

Agents may not recognise when a situation falls outside defined policy or lacks sufficient clarity.

Enable escalation paths and boundaries

Allowing agents to flag uncertainty and escalate when necessary ensures complex or unclear situations are handled appropriately by the right teams.

Lack of visibility

Actions taken by agents may not be visible, making it difficult to understand behaviour or identify issues.

Implement monitoring and logging

Recording actions and outputs provides transparency, supports review, and enables you to identify patterns or improvement areas.

Unclear ownership

Without defined ownership, accountability for agent behaviour and outcomes may be unclear.

Assign clear ownership

Designating responsible individuals ensures accountability for maintenance, updates, oversight and communication of agent behaviour.

Lack of control or intervention

Without the ability to intervene, incorrect or unintended actions may continue without oversight or correction.

Introduce intervention controls

Providing the ability to pause, stop, or override agent activity allows humans to retain control where needed.

Shadow agents

Agents may be deployed without authorisation and go undiscovered, which means they then cannot be controlled as the organisation does not know they exist.

Control agent creation and deployment

Only a select number of employees should be able to make agents to reduce the chance of shadow agents being created. With the increasing complexity of agentic AI systems, it is conceivable that the AI system itself can spawn new agents, so it is essential to implement controls that prevent new agents being deployed without human oversight and authorisation.

Lack of testing

Agents may behave unexpectedly if not validated before deployment.

Conduct testing on small groups pre deployment

Validation and testing ensures the agent behaves as intended before being rolled out across your organisation.

Undocumented changes

Unmanaged changes can introduce errors or unexpected behaviour by altering how an agent operates.

Ensure change management covers agents

Change management ensures changes are being reviewed and approved, and there is a plan in place in the event of a change causing errors or unexpected behaviours. Change management will often work hand in hand with intervention controls, whereby the AI can be stopped to allow correction or back-out of a change before it causes significant harms.

Having a backup plan

Sometimes agents fail, but the task still needs to be performed.

Ensure business continuity for agents

Your organisation needs to be able to function if an agent is down or not working. It is necessary to fully understand the impact that an individual agent will have on overall system performance and whether it is safe to allow the system to continue operation without the agent that has failed. This may require having manual processes in place to replace individual agents or the entire system.


In practical terms, validation and/or verification should include routine tasks, unusual requests and situations where the agent should refuse, pause or escalate.  A technically successful response is not enough: reviewers should also confirm that the action was authorised, traceable and consistent with the organisation’s policies.  Starting with a limited user group makes it easier to observe behaviour and adjust controls before wider deployment.

Human oversight should be designed around decisions and consequences, rather than treated as a generic approval step.  Organisations should identify where a person must review an action before it occurs, where retrospective monitoring is sufficient and who has the authority and practical ability to stop the agent.  If intervention is too slow, too complex or assigned to someone without the necessary context, the control may exist on paper but fail in practice.

Before an agent is deployed, its accountable owner should be able to answer five questions: What is the agent permitted to do?  Which data and systems can it access?  When must it involve a person?  How will its actions be monitored?  What happens if it behaves unexpectedly or becomes unavailable?  If these questions cannot be answered clearly, the agent is unlikely to be ready for operational use.

Using established frameworks: ISO 38507, ISO 42001 and the NIST AI RMF

The controls outlined above provide a practical start point.  However, based on our experience helping organisations implement AI governance programmes, aligning with established frameworks can provide valuable structure and consistency, as well as providing stakeholders with increased assurance of your governance arrangements’ effectiveness and maturity.

ISO 38507 adds an important governance perspective by providing guidance to governing bodies on how to oversee and govern the use of AI within their organisations.  For agentic AI, this is particularly relevant because greater autonomy and interconnected decision-making can create consequences that extend beyond individual systems or technical teams.  Governing bodies should therefore ensure that AI use remains aligned with organisational objectives, risk appetite, legal obligations and corporate values, while management establishes the processes and controls required to deliver that direction.

At the management-system level, ISO 42001 and the NIST AI Risk Management Framework (RMF) provide useful structures for organisations looking to govern AI and AI agents responsibly.*  Of particular note is that much of the information and control that needs to be established would be brought out in an AI system impact assessment (AIIA), the completion of which is a key requirement of ISO 42001.  These assessments can be completed in accordance with your organisation’s preferred approach, such as that defined within ISO/IEC 42005:2025.

*To learn more about these frameworks, their purpose, and the similarities and differences between them, read our blog on Artificial Intelligence Frameworks and Regulations: ISO 42001, the NIST AI RMF and the EU AI Act.

For organisations at an early stage in their AI journey, a proportionate first month could focus on four activities:

  • Identify agent use cases and owners
  • Record the systems, information and actions available to each agent
  • Agree where human review or intervention is required
  • Test one limited use case before wider deployment.

This will not replace a complete governance programme, but it will provide the visibility needed to prioritise the next steps.

Closing Thoughts

AI agents and agentic AI have the potential to deliver significant business benefits, but their autonomy and interconnected nature introduce risks that organisations must understand and manage.  Our practical experience points to a simple lesson: governance is most effective when it develops alongside the use case, not after the technology has already become embedded.  Organisations that define ownership, boundaries, oversight and intervention arrangements at the outset are better positioned to realise the benefits of AI agents safely and sustainably.

How URM Can Help?

With extensive, cutting-edge AI governance expertise, URM can provide experienced ISO 42001 consultants to guide you through the entire process, from initial assessment through to ISO 42001 certification and help support implementation of governance arrangements that align with ISO 38507.

Our support includes:

AI gap analysis

A structured review of your current approach against ISO 42001 requirements, providing:

  • A clear view of where you meet the standard and where gaps exist
  • Prioritised, practical recommendations for remediation
  • A tailored roadmap to support your implementation journey.

Implementation and remediation support

Having established your current level of conformance, URM can offer hands-on guidance from an experienced AI consultant to help you align with the standards, including:

  • Working with you to build an ISO 42001-conformant AI management system (AIMS) or integrated management system
  • Supporting process and AI policy implementation, ensuring these reflect your organisation’s unique needs and ways of working
  • Assisting with the AI impact assessment process
  • Assessment of your governance approach against ISO 38507 and supporting the implementation of suitable governance arrangements.

Internal audit and certification readiness

Preparing your organisation for certification with confidence:

  • Independent internal audits to assess effectiveness of your AIMS and controls
  • Identification and remediation of any remaining nonconformities
  • Ongoing support through the ISO 42001 certification process.

Drawing on over 20 years of experience with management system standards, URM helps ensure your approach is not only conformant, but practical, proportionate and effective in real-world use.

George Ryan
George Ryan
Consultant at URM
George Ryan is a Consultant at URM, working predominantly with ISO 27001. He is an IASME certified Cyber Essentials and Cyber Essentials Plus Assessor.
Neil Jones
Neil Jones
Senior Consultant at URM
Neil is a Senior Consultant at URM, with over 20 years of ‘real world’ information security knowledge and experience, having worked in complex telecommunications, (multinational) financial services and professional services environments, with both regional and global responsibilities.

Receive a Bespoke AI Management System

URM tailors ISO 42001 solutions to your unique risks, sector, and culture—ensuring seamless integration into business-as-usual.
Thumbnail of the Blog Illustration
Other Standards
Published on
17/5/2024
ISO 42001 and AI Perspectives

URM’s blog explores ISO 42001, its intentions and structure, and the AI perspectives that will need to be considered by organisations implementing the Standard.

Read more
Thumbnail of the Blog Illustration
Artificial Intelligence
Published on
22/11/2024
Establishing Organisational Control Over Artificial Intelligence

URM’s blog discusses the need for policy in relation to the use of AI, real-world cases where AI has caused organisations issues & how to create an AI policy.

Read more
Thumbnail of the Blog Illustration
Other Standards
Published on
5/6/2024
ISO 42001 Artificial Intelligence Impact Assessments (AIIAs)

URM’s blog explores artificial intelligence impact assessments (AIIAs) and offers advice on how to conduct these assessments in full conformance with ISO 42001.

Read more
URM were super helpful and knowledgeable, talking and walking me through each one of the tests and providing some useful information on security and how to improve things in the future.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.