AI governance: guardrails, approval gates and an audit trail for agents you already run
Governance for AI comes down to four questions you can answer on demand: what the agent may touch, who approved its last change, where that change is recorded, and how it can be undone. My work is to set up the controls that produce those answers, in the systems where your agents already run.
Key takeaways
- A policy document governs nothing. Controls in the system do.
- Most sites already have agents or assistants connected that nobody inventoried.
- Record-keeping and human oversight are named duties for high-risk systems under the EU AI Act.
What a governance engagement produces
- An inventory. Every assistant, agent, connector and API token that can read or write your systems, with its owner.
- Scoped access. Each one cut down to what its task needs.
- Approval gates on the actions that change configuration or data others depend on.
- One audit trail that records request, plan, approver and result.
- A reversal path for each class of change, tested once.
The principles behind the list are on the method page.
How the controls line up with the EU AI Act
Regulation (EU) 2024/1689 sets duties for high-risk AI systems, among them automatic logging of events (Article 12) and effective human oversight (Article 14). The full text is on EUR-Lex. An audit trail and an approval gate are the technical side of those two articles.
Whether one of your systems counts as high-risk is a legal classification for you and your counsel. I build the controls and document them; I do not give legal advice.
Where do-it-yourself governance stops
Teams usually get as far as a written policy and an admin setting that disables a feature. What is missing is enforcement between those two: an agent that is allowed, but only within limits, with a record. Building that takes someone who can read the platform’s permission model and the agent’s code.
When governance work is premature
If nobody uses AI against your systems yet and nothing is connected, there is little to govern. Write a one-page rule about which tools are allowed, and come back when the first agent is proposed. Building the gate together with that agent is cheaper than building it in advance.
This is often part of an FDE engagement. Before an agent can route tickets or answer from your knowledge base, the configuration underneath has to be right. The AI Readiness Audit finds out what needs fixing first, in two weeks, for a fixed $3,500.
Questions
We only use the vendor’s built-in assistant. Do we need this?
Can you govern agents another firm built?
Is this a one-off or ongoing?
Cannot say today what your AI tools are able to change? The audit starts with that inventory.
Fixed scope
Fixed scope, fixed price