Governance, risk and sovereignty
Every agent sits on an official register with a named owner and a risk tier, the records kept grow with the risk, and any agent can be stopped fast.
Target state
In short: Every agent is on an official register with a named owner and a risk tier, and the records kept grow with the risk.
A governed agent estate. The agent registry (the official list of agents) is the compliance inventory, aligned with the registration machinery of the EU AI Act. Every agent carries two tiers. The autonomy tier says how much it may do without a person. The classification-plausibility tier says how likely it is to count as high-risk under the Act. The evidence kept follows the tier. There is an evidence floor for all production agents. Agents that could plausibly classify as high-risk get instrumentation at the level Article 12 of the Act requires. Kill switches and incident runbooks are wired before autonomy expands. Provenance-carrying grounding makes answers citable by construction: each answer carries the record of where its information came from. Board reporting is fed from the registry and live telemetry, not bespoke decks. Sovereignty (where data may be stored and processed) is satisfied by routing each deployment by its data classification. This layer is where accountability for the whole agent estate sits.
layer · architecture
The registry-centred evidence machine
The agent registry is the compliance inventory; evidence posture is two-tiered, and deployment is classification-routed for sovereignty.
- 01Control
Control
Agent registry
Owner, purpose, risk tier, tools and credentials, model and prompt versions
- 02Control
Control
Risk tiers
Observe / Advise / Act-with-approval / Autonomous
- 03Evidence
Evidence
Evidence floor
Per-action logs retained, named oversight, provenance-carrying grounding
- 04Evidence
Evidence
Article-12-grade tier
For plausibly high-risk workloads
- 05Boundary
Boundary
Kill switch
Wired before autonomy expands
- 06System
System
Classification-routed deployment
Data class selects region and estate
Diagram description: Governance topology with the agent registry as hub feeding risk tiering, two-tier evidence capture, kill switch, classification-routed deployment, and board reporting. The map contains Agent registry: Owner, purpose, risk tier, tools and credentials, model and prompt versions; Risk tiers: Observe / Advise / Act-with-approval / Autonomous; Evidence floor: Per-action logs retained, named oversight, provenance-carrying grounding; Article-12-grade tier: For plausibly high-risk workloads; Kill switch: Wired before autonomy expands; Classification-routed deployment: Data class selects region and estate. Its connections are registry to tiers; tiers to floor; tiers to art12 for plausible high-risk; registry to kill; registry to routing.
- Component
- Agent registry
- Responsibility
- Compliance inventory: owner, purpose, risk tier, tools and credentials, model and prompt versions
- Control it hosts
- Alignment with Article 49/71 registration; named accountable owner; tier assignment
- Where it runs
- Governance platform or the catalogue estate you already run
- Component
- Tiering and gates
- Responsibility
- Assign autonomy and classification-plausibility tiers per agent
- Control it hosts
- Observe, Advise, Act-with-approval and Autonomous gates; documented Article 6(4) self-assessments
- Where it runs
- Governance workflow tooling
- Component
- Evidence store
- Responsibility
- Retain per-action logs, oversight records, documentation
- Control it hosts
- Six-month log retention floor (Article 26); tamper-evident storage; Annex IV documentation for the plausible tier
- Where it runs
- SIEM (security information and event management) and log estate plus GRC (governance, risk and compliance) evidence storage
- Component
- Provenance-carrying retrieval
- Responsibility
- Store chunks and sources alongside embeddings
- Control it hosts
- Citation by construction; source provenance on every grounded claim
- Where it runs
- The retrieval estate
- Component
- Kill switch and incident machinery
- Responsibility
- Stop agents fast; report serious incidents
- Control it hosts
- Article 14(4)(e) stop capability; Article 73 timelines; tested runbooks
- Where it runs
- Agent platform and control-tower tooling
- Component
- Regulatory watch
- Responsibility
- Track milestones; re-verify dated facts
- Control it hosts
- Quarterly re-verification rhythm; board reporting from live data
- Where it runs
- Compliance function, fed from registry telemetry
Mechanisms
The registry as compliance inventory
In short: The agent list doubles as the compliance inventory the law expects, with a named owner for every entry.
Each registry entry records owner, purpose, risk tier, tools and credentials, and model and prompt versions. This is a filing duty, not hygiene. The Digital Omnibus kept registration (in simplified form) even for systems self-assessed out of high-risk under Article 6(3), and the registry aligns with the Act's Article 49/71 registration machinery. Around the registry sits the minimum viable agent governance pattern. It has a registry, a named accountable owner, autonomy risk tiers (Observe, Advise, Act-with-approval, Autonomous), approval gates, per-action audit, a kill switch, and an incident runbook. The pattern converges across sources. The standards scaffolding is young but real. ISO 42001, the International Organization for Standardization's AI management standard, has about 350 certified organisations; no official register exists, so that count is flagged. ISO 42005 covers impact assessment (May 2025). ISO 42006 sets requirements for certification bodies (Jul 2025). The Cloud Security Alliance (CSA) has published an agentic AI profile of the NIST AI Risk Management Framework (AI RMF), from the US National Institute of Standards and Technology.
The two-tier evidence posture
In short: Every production agent keeps a basic set of records, and agents that might count as high-risk under EU law keep much more.
The floor applies to all production agents: a registry entry, per-action audit logs retained for at least six months, named oversight, and provenance-carrying grounding. The six-month retention is the deployer duty in Article 26, which also requires competent oversight and informing workers. Instrumentation at the level Article 12 requires applies to the tier that could plausibly classify as high-risk. That tier includes systems that touch employment, credit, or essential services, and Copilot-class multi-purpose systems under the draft presumption. The honest line, stated plainly: no regulator or auditor has endorsed retrieval provenance, the source trail kept by retrieval, as satisfying Article 12. The demand side is already institutional. Forty percent of boards assign AI oversight to a committee, up from 11 percent a year earlier (ISS, Institutional Shareholder Services, 2026). Sixty-two percent reserve agenda time (NACD, the National Association of Corporate Directors, 2026). Only 28 percent of internal-audit leaders are confident they can audit AI risks, and only 21 percent of organisations report a mature agentic governance model (Deloitte). Gartner finds that organisations which operationalise AI TRiSM (trust, risk and security management) are 3.4 times as likely to report high governance effectiveness.
Provenance-carrying grounding, mechanically
In short: Store each retrieved passage with its source, so every answer can show where it came from without detective work afterwards.
Retrieval stores chunks (the pieces documents are split into) and their sources alongside the embeddings (the numeric fingerprints used for search). The chain then holds by construction rather than by reconstruction: source, chunk with its source pointer, embedding, retrieval, claim, citation. It is necessary, not sufficient. Action and decision logs, capture of oversight interventions, retention and integrity controls, and Annex IV technical documentation are deliberate additions, not by-products. Evidence from 2026 converges. Compliance-by-construction argument graphs pair grounded retrieval with a provenance ledger in the W3C PROV standard, from the World Wide Web Consortium (arXiv 2604.04103, Apr 2026). Explicit-provenance agent architectures are linked to AI Act accountability (arXiv 2605.17169, May 2026). Harness-engineering work addresses auditability (arXiv 2607.08028, Jul 2026). NIST AI 600-1, the US standards body's profile for generative AI, centres provenance. Auditor-side demand has an incident behind it: a Big Four firm partially refunded the Australian government over fabricated citations (Oct 2025). Calling this the highest-leverage single evidence component is the authors' position.
Regulatory geometry, with dates
In short: The EU moved its high-risk AI deadlines back, but transparency duties already apply and the draft high-risk rules read broadly.
The Digital Omnibus moved the high-risk regime. The Council gave final approval on 29 Jun 2026, and publication in the Official Journal (OJ) was reported on 24 Jul 2026; verify against EUR-Lex. Annex III stand-alone systems moved from 2 Aug 2026 to 2 Dec 2027. Annex I embedded systems moved to 2 Aug 2028. Two things are live since 2 Aug 2026 regardless. The first is Article 50 transparency: disclosing AI interaction and marking synthetic content, with a grace period to 2 Dec 2026 for pre-existing systems. The second is the Commission's full enforcement powers over general-purpose AI (GPAI) models: documentation requests, model evaluation, and fines. The cause of the delay was standards slip. The European standards bodies' joint committee, CEN-CENELEC JTC 21, missed its deadline. Prioritised deliverables are promised for Q4 2026, and industry estimates more than 12 months of compliance work per standard. The draft classification guidelines (19 May 2026; consultation closed 23 Jul 2026; not final) tilt broad. They set a materially-influence test for employment tools. They add an anti-splitting rule: spreading functions across several tools does not evade classification. Profiling is always high-risk. Broadly marketed multi-purpose systems are presumed to encompass high-risk uses unless clearly excluded everywhere. Article 25 flips deployers to providers on rebranding, substantial modification, or repurposing. Customising and rebranding a general-purpose chatbot as an internal assistant likely triggers provider status (Freshfields). Enforcement capacity is thin: 9 of 27 member states had fully designated authorities as of 17 Jun 2026 (sources disagree between 8 and 9). Finland was first with full powers (1 Jan 2026). No AI-Act-specific enforcement action against an enterprise is publicly reported as of Aug 2026.
The sovereignty map, dated
In short: Data-location rules keep changing in the EU, India, the US and China, so the data's sensitivity decides where it runs.
EU Data Act, applicable since 12 Sep 2025: cloud switching charges are cost-based now and banned from 12 Jan 2027. Audit contracts for auto-renewal traps. The proposed Cloud and AI Development Act (CADA) of 3 Jun 2026 introduces a four-level cloud sovereignty framework tied to public procurement. The EU provider share fell from roughly 29 percent to 15 percent across 2017 to 2022. EUCS (the EU cybersecurity certification scheme for cloud services) remains unresolved and may be superseded. India: the Digital Personal Data Protection (DPDP) Rules were notified on 13 Nov 2025 and are phased. Consent managers and enforcement start from 13 Nov 2026, with full effect on 13 May 2027. The Reserve Bank of India (RBI) runs ahead of the horizontal law with two documents. They are its FREE-AI report (Framework for Responsible and Ethical Enablement of AI, Aug 2025) and its draft Model Risk Management guidance (24 Jun 2026). US state churn: Colorado's act was repealed and replaced (Senate Bill 26-189 signed 14 May 2026, obligations from 1 Jan 2027). California's Senate Bill 53 (SB 53) and Assembly Bill 2013 (AB 2013) and Texas's TRAIGA (Texas Responsible Artificial Intelligence Governance Act) took effect on 1 Jan 2026. Federal pre-emption pressure comes via executive order. China: labelling rules for AI-generated content (AIGC) took effect 1 Sep 2025. The Anthropomorphic Interactive Services Measures took effect 15 Jul 2026. Draft agent-specific rules have circulated since May 2026. The architecture answer is classification-routed deployment: data classification determines region and estate, and sovereignty is increasingly satisfiable inside managed sovereign offerings.
Kill switches and incident machinery
In short: You must be able to stop any agent instantly and report serious incidents on time; test both before widening autonomy.
The stop capability now exists in three forms. First, a product feature: ServiceNow AI Control Tower added real-time agent kill switches at Knowledge 2026 (May 2026) [vendor]. They cover Amazon Web Services (AWS), Azure, Google Cloud Platform (GCP), and Microsoft 365 (M365). Second, a draft regulatory mandate: RBI's draft Model Risk Management guidance (24 Jun 2026) asks for kill switches, human oversight, and risk-based model tiering across regulated entities; verify against rbi.org.in. Third, the EU hook: Article 14(4)(e), the stop button. A capability gap stands. Governance platforms (OneTrust continuous monitoring and agent detection, Mar 2026 [vendor]; Credo AI, Holistic AI, and watsonx.governance [vendor]) govern inventory, risk workflow, policy mapping, and evidence storage. Enforcement at runtime is still mostly a separate product. Incident machinery is wired before autonomy expands: runbooks, drills, and reporting against the Article 73 timeline. The draft serious-incident guidance (Sep 2025) is oriented to single systems. The gap in multi-agent incident reporting is a documented hole: emergent cross-agent incidents have no reporting frame (TechPolicy.Press, Jan 2026).
Design decisions
- Broad vs narrow AI Act classification (CD-14), a challenged default about how widely to assume the Act's high-risk rules apply. The answer is neither pole but a risk-tiered evidence posture. The legal current tilted narrow: the omnibus delivered what the Jul 2025 "Stop the Clock" letter from about 50 chief executives asked for, and the Commission had first refused. The interpretive current in practice tilts broad: materially-influence, anti-splitting, and the multi-purpose presumption. Enforcement is thin either way. So: the floor for all, and Article-12-grade records for the plausible tier. Re-verify on every regulatory milestone: final classification guidelines, first harmonised standards citations, first enforcement actions.
- Evidence-first, repositioned: the argument no longer rests on the moved deadline. It stands on four legs. Lead time: more than 12 months of compliance work per standard, with standards landing in Q4 2026. Obligations already live: Article 50 and GPAI enforcement since Aug 2026. Sectoral regulators moving faster: RBI. And board expectations. Classification risk is a slow fuse with broad interpretation. That is the condition under which early evidence is cheap insurance rather than panic spend.
Cross-cutting concerns
- #
- C1
- Concern
- Identity and access
- Treatment at this layer
- Registry binds identity to owner, tier, and permitted scope; sponsor accountability
- #
- C2
- Concern
- Observability
- Treatment at this layer
- Evidence telemetry (logs, oversight events) as a governance product; board reporting from live data
- #
- C3
- Concern
- Traceability and audit
- Treatment at this layer
- The layer's core: retained logs, tamper-evident evidence, Annex IV-shaped documentation for the plausible tier
- #
- C4
- Concern
- Grounding
- Treatment at this layer
- Provenance-carrying grounding as the citable-answer mechanism
- #
- C5
- Concern
- Impersonation
- Treatment at this layer
- Article 50 disclosure duties, live now: humans know when they interact with AI; synthetic content marked
- #
- C6
- Concern
- Sovereignty
- Treatment at this layer
- The dated map (Data Act, CADA, DPDP, US states, China); classification-routed deployment
- #
- C7
- Concern
- Privacy
- Treatment at this layer
- GDPR (General Data Protection Regulation) and DPDP alignment of memory and evidence retention; worker-information duties
- #
- C8
- Concern
- Safety and oversight
- Treatment at this layer
- Article 14 oversight design; kill switches (product, draft mandate, Act hook); fundamental rights impact assessment (FRIA) where applicable
- #
- C9
- Concern
- Cost
- Treatment at this layer
- Compliance cost tiered to classification plausibility; provider-flip avoidance as a design constraint
- #
- C10
- Concern
- Resilience
- Treatment at this layer
- Incident reporting machinery on the Article 73 timeline; multi-agent incident gap acknowledged
Evidence and limits
This layer's incident record is regulatory rather than a list of software vulnerabilities (CVEs). The operative facts are two. A Big Four firm gave a partial refund over fabricated citations (Oct 2025). No AI-Act-specific enforcement action against an enterprise has been publicly reported as of Aug 2026. Dates in flux carry flags. The omnibus OJ publication (reported 24 Jul 2026) and the provisional-agreement date show discrepancies across sources, as does the 8-versus-9 count of ready member states; verify against EUR-Lex. Vendor-published capability claims (ServiceNow, OneTrust, Credo AI, Holistic AI, watsonx.governance) carry [vendor] status. So do the analyst figures (Gartner: the governance-platform market passing $1 billion by 2030; the 3.4 times effectiveness multiple). Board and audit percentages are survey-based (ISS, NACD, Deloitte). The ISO 42001 count has no official register behind it. Compliance-cost figures are held to order of magnitude (tens of thousands for a deployer versus hundreds of thousands for a provider) because sourcing is weak. The guide declines to publish exact ranges. The provenance thesis is the authors' position, with converging support and no auditor or regulator endorsement. Re-verify before relying on this page: the final omnibus text, final classification guidelines, final Article 73 guidance, and the first JTC 21 standards citations in the OJ (the event that starts the compliance clock). Also re-verify first enforcement actions (checked quarterly), RBI model risk management finalisation, CADA's legislative progress, and China's agent-rules finalisation.
The research behind this page
Security and identity
Every agent gets its own registered, short-lived identity with minimal access, and a rules engine the agent cannot bypass approves or blocks each consequential action.
Observability and FinOps
How to see what every agent did, test every change before it spreads, and keep every agent's spending inside a limit its business sponsor owns.