Compyl

Governing AI Agents: The Security & Compliance Guide

July 08, 2026
Playbook · AI Agent Governance

Governing AI Agents: The Security & Compliance Guide

By Compyl ResearchUpdated July 20265 min read

Governing AI agents means treating every autonomous AI system as a non-human identity with an owner, an inventory record, least-privilege access, observable behavior, and continuous compliance checks. Gartner projects 40% of enterprise applications will embed AI agents by the end of 2026 — yet 92% of surveyed security leaders lack full visibility into their AI identities.

Key takeaways
  • Agents act, hold credentials, and change behavior — human IAM assumptions fail for them.
  • Five pillars: inventory, identity, least privilege, observability, continuous compliance.
  • 68% of employees use unapproved AI tools; shadow AI costs an average $412K/year.
  • ~1 in 4 compliance audits in 2026 will probe AI tool governance — map agent controls to your frameworks now.

Why agent governance is different from AI governance

Most AI governance programs were built for models: inventory the model, assess its risk, review outputs. Agents break that model in three ways. They act rather than answer — executing multi-step tasks across systems. They hold credentials — 71% of organizations report AI systems have access to core platforms like ERP, CRM, and financials, while only 16% govern that access effectively. And they change behavior — 47% of CISOs have observed agents exhibit unintended or unauthorized behavior. Human IAM assumes stable roles and clear accountability; agents have neither by default.

The five pillars of AI agent governance

Pillar What it requires Example control
1. Inventory Live register of every agent: purpose, owner, model, systems touched Registration gate before production; discovery scans for shadow agents
2. Identity Dedicated non-human identity per agent — never shared human credentials NHI lifecycle tied to a named owner
3. Least privilege Scoped, time-bound permissions matched to task Agents included in quarterly access reviews; write access needs human approval
4. Observability Full audit logging of actions and tool calls; anomaly detection Immutable action logs; alerts on out-of-pattern access
5. Continuous compliance Agent controls mapped to frameworks and tested automatically Continuous control tests; auto-collected evidence

Shadow AI: discovery comes first

You cannot govern agents you cannot see. Roughly 68% of employees use AI tools without IT approval and three in four CISOs have found unsanctioned generative AI in their environments. Tactics that work: network and SaaS telemetry on AI API traffic, identity-provider audits for unclaimed OAuth grants with AI scopes, expense reviews for AI subscriptions, and a two-week “register your agent, no questions asked” amnesty window.

Mapping agent controls to your frameworks

Framework Where agents fit
NIST AI RMF Govern: policies and ownership. Map: inventory. Measure: behavior monitoring. Manage: agent incidents.
ISO/IEC 42001 Annex A lifecycle, resource, and third-party AI controls extend to agents you build or buy
SOC 2 Logical access (CC6) and system operations (CC7) apply to agent identities and monitoring
ISO 27001 Identity/access and asset management — agents are assets with identities
EU AI Act Agents influencing consequential decisions may qualify as high-risk systems

A 90-day implementation plan

  1. Days 1–30 — See: run discovery across IdP, network, SaaS, and expenses. Stand up the agent register; assign an owner to every agent found.
  2. Days 31–60 — Control: issue dedicated identities, revoke shared credentials, scope permissions, add agents to access reviews, and define the no-autonomy boundary (payments, access grants, deletion, external comms).
  3. Days 61–90 — Prove: turn on action logging and anomaly alerts, map controls to frameworks, automate evidence — so “how do you govern AI agents?” has a one-click answer.

Compyl treats AI agents as first-class objects in your GRC program: inventory them alongside assets, include non-human identities in access reviews, map agent controls once across frameworks, and collect evidence continuously. For the flip side — using AI agents to run your GRC program — see The Agentic GRC Playbook.

Frequently asked questions

What is an AI agent, for governance purposes?
Any AI system that autonomously executes tasks or makes decisions across other systems. If it holds credentials and takes actions, govern it as an agent with an owner, inventory record, and scoped access.
Should AI agents be included in user access reviews?
Yes. Agents hold credentials like human users, and auditors increasingly expect non-human identities in review scope, each with a named human owner attesting to its access.
How many AI agents does a typical enterprise run?
2026 survey data puts the average at 37 deployed agents per enterprise, with more than half running without security oversight or logging.
Does SOC 2 cover AI agents?
SOC 2 has no agent-specific criteria, but agents fall under existing logical access, change management, and monitoring criteria — expect auditors to ask how agent identities are provisioned and reviewed.
What should AI agents never do autonomously?
Common boundaries: moving money, granting or modifying access, deleting production data, signing agreements, and external communications — each requiring logged human approval.

Govern your AI agents with Compyl

Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.

Request a demo →

About this guide. By Compyl Research. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.

Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies