AI Governance Library

Governing Agents: A Practitioner's Cross-Framework Reference

The central claim of this reference is that AI agents are not a variant of AI systems for which existing compliance mappings can be mechanically reused. They are a distinct governance category.
Governing Agents: A Practitioner's Cross-Framework Reference

⚡ Quick Summary

Governing Agents: A Practitioner's Cross-Framework Reference by Noah M. Kenney establishes that autonomous, tool-using AI agents constitute a distinct governance category that strains traditional compliance mechanisms. Extending the five-layer AI Governance Stack (Data, Model, System Integration, Control & Monitoring, and Audit & Evidence), the reference demonstrates how agentic planning, external tool execution, multi-turn memory, task delegation, and in-context adaptation alter regulatory risk profiles. It provides rigorous article-by-article and subcategory mappings across the GDPR, EU AI Act, NIST AI RMF (and Generative AI Profile AI 600-1), and ISO/IEC 42001:2023. To prevent compliance failure modes like controller-processor drift and purpose decay, the guide details operational runtime enforcement patterns—including policy-as-code guardrails, tool gating, tiered memory scoping, and structured decision envelopes—culminating in a 23-control catalog ready for enterprise deployment.

🧩 What's Covered

The reference provides a comprehensive operational blueprint for governing agentic AI across four major regulatory and voluntary regimes, organized into core technical areas:

  • Foundational Agent Taxonomy: Breaks down agent behaviors into five distinct capabilities—Planning and Reasoning (A1), Tool Use and External Action (A2), Memory and State (A3), Delegation and Multi-Agent Coordination (A4), and Adaptation/In-Context Learning (A5)—demonstrating how they shift governance weight toward Integration (L3) and Monitoring (L4).
  • GDPR Article-by-Article Analysis: Examines strains on core data protection provisions, including personal data in reasoning traces (Art. 4), purpose drift (Art. 5(1)(b)), multi-action lawful bases (Art. 6), accidental special-category processing (Art. 9), subject access across vector stores and tool logs (Art. 15), complex erasure across retrieval indices (Art. 17), and automated decision-making under Art. 22.
  • EU AI Act Overlay: Details high-risk classification under Annex III, narrow exceptions under Article 6(3), compound obligations combining GDPR and AI Act mandates, general-purpose AI (GPAI) downstream integrator duties (Arts. 51–55), and transparency disclosures (Art. 50).
  • NIST AI RMF & ISO/IEC 42001 Crosswalks: Maps the Govern, Map, Measure, and Manage functions (alongside AI 600-1 risks such as action confabulation) and ISO/IEC 42001 Clauses 4–10 and Annex A controls to agent architectures.
  • Runtime Enforcement Patterns: Defines concrete mechanisms including policy-as-code evaluated at four boundaries (intake, planning, tool, output), allowlist tool gating, tiered memory retention (reasoning traces, tool records, audit envelopes), delegation context propagation, and structured decision envelopes.
  • Agent Control Catalog: Supplies 23 numbered, outcome-based controls across the five stack layers (AG-L1-01 through AG-L5-07) ready for policy adoption.

💡 Why it matters?

Static pre-deployment governance models and traditional contract structures fail when applied to agents that dynamically invoke third-party tools, cross jurisdictional boundaries mid-session, and retain long-term state. This reference provides the technical and legal translation layer required to move governance from static policy documents into runtime enforcement code. By introducing practical constructs such as compositional Records of Processing Activities (ROPA), tiered retention architectures, and structured decision envelopes, it equips practitioners to satisfy compound regulatory obligations across data privacy, product safety, and AI risk management without crippling agent utility.

❓ What's Missing

The document explicitly notes several unresolved legal and technical frontiers in agent governance. It does not provide finalized legal solutions for dynamic joint controllership under GDPR Article 26 in decentralized multi-agent networks, leaving practitioners to rely on defensible defaults. Additionally, it highlights the lack of mature technological methods for model-level unlearning to satisfy erasure requests in parametric memory, and notes the current absence of standardized third-party assurance criteria for validating runtime policy-as-code engines and audit envelopes.

👥 Best For

AI governance officers, privacy counsel, compliance professionals, AI safety architects, machine learning platform engineers, and enterprise risk managers who are designing, evaluating, or deploying autonomous and tool-augmented AI agent systems in regulated environments.

📄 Source Details

  • Title: Governing Agents: A Practitioner's Cross-Framework Reference (Mapping GDPR, the EU AI Act, NIST AI RMF, and ISO/IEC 42001 to AI Agents)
  • Author: Noah M. Kenney (Digital 520, Disruptive AI Lab, Ethical Tech Forum)
  • Publication Year: 2026 (First Edition)
  • Publisher: Digital 520
  • Companion To: Governing Intelligence: Law, Privacy, Security, and Compliance in the Age of Artificial Intelligence (1st ed.)

📝 Thanks to

Curated and reviewed by Kuba Szarmach for the AI Governance Library.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.