Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Enterprise AI agents need governance before they receive access to sensitive data or operational systems. Unlike tools that only generate text, agents may make decisions and take actions with limited human supervision. Organizations therefore need to know which agent acted, what it was allowed to do, who delegated the task, and when a person must approve a consequential action.

Why AI agents change the governance problem

An AI agent can pursue a goal by making decisions and taking actions, rather than stopping at a generated answer. That shift makes identity, authorization, and accountability central design questions: the organization must govern not only what an AI system produces, but also what it can do.

NIST’s National Cybersecurity Center of Excellence (NCCoE) describes this challenge in a February 2026 concept paper on software and AI agent identity and authorization. The paper is a proposal for project work, not a completed technical standard. It explores how identity standards and practices might help organizations distinguish agents from people, control agent entitlements, and connect delegated actions to user identities where appropriate. Read the NIST NCCoE concept paper.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That is the enterprise imperative: delegate useful work without losing control of authority or the ability to account for actions. A governance program should make those controls part of deployment design, not a review added after an agent has been connected to business systems.

Use NIST’s AI RMF to structure lifecycle risk work

NIST released version 1.0 of its AI Risk Management Framework (AI RMF) on January 26, 2023. It is voluntary guidance for incorporating trustworthiness considerations into AI design, development, use, and evaluation. Its four functions—govern, map, measure, and manage—organize risk work across an AI system’s lifecycle. The functions can be applied in ways suited to an organization’s needs and resources. NIST says AI RMF 1.0 is being revised as part of the White House AI Action Plan, so it should not be described as an unchanging or mandatory rule. NIST’s AI RMF overview and the AI RMF Core describe the framework.

Function What it addresses How it applies to an agent
Govern Organizational policies, responsibilities, oversight, and risk-management practices. Assign accountable owners; keep an inventory of agents and systems; establish review, monitoring, and safe decommissioning practices.
Map The system’s context, intended use, potential impacts, affected parties, components, and dependencies. Document the task, connected data and services, users affected, and the consequences if an action is wrong. Use that context to inform whether to design, develop, or deploy the system.
Measure Assessment of risks and system characteristics. Define how the organization will test the agent against its intended task and boundaries, and what evidence is needed before granting or expanding access.
Manage Prioritizing and responding to identified risks throughout the lifecycle. Choose mitigations, monitor operation, respond to incidents, and revisit permissions or deployment decisions as conditions change.

Governance is cross-cutting, not a one-time approval gate. NIST’s AI RMF Core says that “Attention to governance is a continual and intrinsic requirement for effective AI risk management over an AI system’s lifespan and the organization’s hierarchy.” The practical implication is to maintain ownership and oversight after launch, including when an agent’s task, connected systems, or operating context changes.

Distinguish lifecycle guidance, maturity models, and identity work

These approaches address related but different needs. None is established by the available evidence as a universal winner or as a binding regulation. Choose based on the problem you need to solve and the level of operational detail your organization can support.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Approach Purpose Status and useful distinction
NIST AI RMF 1.0 Lifecycle risk management organized around govern, map, measure, and manage. Voluntary framework released in 2023 and currently under revision, according to NIST. It offers a broad structure that organizations can adapt to their context.
SANS AI Security Maturity Model Staging AI security maturity. SANS describes its model as having five maturity stages; its announcement says the appropriate target depends on adoption pattern, industry, regulatory environment, and risk tolerance. Stage names are not stated in the cited announcement. SANS announcement, May 12, 2026.
NIST NCCoE agent identity and authorization project Explore identity standards and practices for agent identity, entitlements, and delegation. The February 2026 document is a concept paper describing proposed work and soliciting stakeholder feedback. Implementation-oriented guidance and a possible practice guide are desired outcomes, not completed deliverables.

When evaluating any approach, check whether it helps your organization assign owners, define controls, collect evidence, and set a review cadence—not only whether it states principles. A maturity target should reflect the organization’s sector, jurisdiction, risk tolerance, deployment pattern, staffing, and existing governance obligations.

Make identity and delegated authority explicit

For every agent connected to a business system, decide how it will be identified and how its authority will be represented. The NCCoE concept paper focuses on differentiating agent identities from human identities, authorizing agent rights and entitlements, and linking a user identity to an agent when that relationship is needed for delegation controls and accountability.

  • Identify the agent: Keep agent identity distinct from a person’s identity so access systems and audit records can tell which kind of actor is involved.
  • Record the delegation: Where an action is performed on behalf of a user, retain the linkage needed to establish who delegated the task and under what authority.
  • Scope entitlements: Decide which systems, data, and actions the agent needs for its assigned task; do not treat access to one service as a reason to grant broad access elsewhere.
  • Set approval boundaries: Define which actions may proceed autonomously and which require human approval. The right threshold depends on the action’s context and risk; the concept paper does not prescribe one universal rule.
  • Preserve accountability: Ensure that consequential actions can be reviewed in context, including the agent identity and relevant delegation information.

These are design decisions, not a claim that one identity architecture or approval pattern fits every organization. The NCCoE paper describes a range from human-in-the-loop approval to autonomous action and identifies authorization and access delegation as project areas.

Use context and risk to decide what to deploy

Before granting access, map the work the agent is meant to perform and the environment in which it will operate. NIST’s map function is intended to clarify context, potential impacts, affected parties, system components, and dependencies; that information supports an initial decision about whether to design, develop, or deploy an AI system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Define the task and owner. State the intended use, the accountable business owner, and who can approve changes to the agent’s scope.
  2. Trace its operating context. Identify affected people, connected data sources and services, third-party software or data, and any operational dependencies.
  3. Assess the consequences of action. Consider what could happen if the agent makes an incorrect recommendation, accesses inappropriate information, or takes an unintended action.
  4. Set the allowed autonomy. Specify the actions the agent may take, those it may recommend only, and those that require approval before execution.
  5. Test and review evidence. Decide what testing supports the intended use and access level, and how ongoing monitoring or incidents will trigger a review.
  6. Plan for change and retirement. Reassess when the task, data, dependencies, or permissions change, and define how access will be removed when the agent is no longer needed.

This sequence is an operational way to apply lifecycle risk thinking; it is not a prescribed NIST deployment procedure. NIST’s AI RMF Core also emphasizes governance outcomes involving third-party risks, organizational responsibilities and training, human-AI oversight, testing, incident identification, feedback, and contingency processes.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Match the governance design to the use case

The NCCoE concept paper identifies three enterprise areas for possible focus, emphasizing settings where organizations can maintain greater control and visibility over agents and accessed systems. They are use cases under consideration, not evidence of universal adoption or guaranteed success.

Possible use case Examples in the concept paper Governance consideration
Workforce efficiency and decision support Calendar management, assessing or creating policy documents, and generating decision recommendations. Such work may call for managed delegated access across multiple data sources. Define which actions are administrative assistance and which could affect a decision or record.
Security operations Analyzing security information and recommending or taking actions. NIST notes the higher risk associated with sensitive security data. Carefully scope access and distinguish recommendations from actions that change security controls or systems.
Software development and deployment Automated processes and entitlements or authorization in deployment pipelines using agents. Define which pipeline actions an agent can perform and how its permissions and delegated authority are controlled across deployment steps.

Use the same risk-management structure across these areas, but do not assume they need identical permissions or approval rules. The data involved, the consequences of an action, and the systems reachable by the agent differ by use case.

Keep legal and organizational requirements in view

The AI RMF is voluntary guidance, and the NCCoE document is a concept paper; neither by itself establishes the legal obligations that apply to a particular deployment. Requirements depend on jurisdiction, sector, and use. Because no particular country, industry, or deployment is specified here, this article cannot assign a specific legal duty. Organizations should map their applicable obligations separately and confirm current requirements before making compliance or procurement decisions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What a workable enterprise program should leave behind

A governance effort is useful when it results in clear operating decisions and evidence, not merely a framework label. For each deployed agent, an organization should be able to answer:

  • What task is the agent intended to perform, and who owns that use?
  • Which agent identity, data, systems, and actions are in scope?
  • Who delegated the work, and what information links that delegation to consequential actions?
  • Which actions can occur autonomously, which need review, and who provides that review?
  • What testing, monitoring, incident response, and reassessment apply?
  • How will permissions be changed or removed when the agent’s purpose ends?

NIST’s framework supplies a lifecycle structure for those decisions; the NCCoE project points to the specific identity and authorization problem that grows when systems act with delegated authority. Treating those as complementary concerns gives an enterprise a more practical foundation for adopting agents while retaining control.