A practical guide to governing agents where the action actually happens: the tool call. What to enforce, how to map it onto the stack you already run, and how to prove what every agent did.
The agents are already in production. The sign-offs are not.
As of the 2026 field data, 81% of teams have moved agents past planning into testing or live use. Only 14% report full security sign-off. That gap is the story of enterprise AI right now, and it is not the product of slow-moving security teams.
It is the product of a genuinely new problem. Every governance system you own assumes the entity taking an action and the person accountable for it are the same. An agent breaks that assumption. It acts on someone’s behalf, so for the first time the actor and the accountable party come apart, and the controls you already trust were never built for that.

Most teams’ first instinct is to build guardrails. But a guardrail lives in or around the model, which is exactly the thing that gets prompt-injected, jailbroken, or simply confused. The agent jumps the rail in the first thirty seconds, and everything downstream, the payment, the deletion, the email, goes through anyway. Guardrails protect the reasoning layer, and they stop there. The moment an agent stops analyzing and starts acting, you need governance.
We wrote The AI Agent Governance Playbook for the team that has to close that gap. It is a practitioner’s guide to governing agents at the action layer, built around the one question every tool call has to answer: can this agent, on behalf of this user, take this action, right now?
What’s in the playbook
The playbook is divided into three parts that together will help govern your AI agent systems.
- AI agent governance concepts you need to know:
- Why governing an agent is not governing a person, and where the accountability gap comes from.
- The layers of governance, from the model down to the network, and why the tool call is the highest-leverage place to enforce.
- Why governance has to be married to the actions runtime, the single path every tool call travels, to enforce anything at all.
- The ROI that begins to unlock once you’ve established AI agent governance patterns you can approve once and scale from there.
- Frameworks you can build against:
- The six things to enforce at the action layer: authorization at the intersection of user and agent, policy-as-code, deny-by-default, step-up approval for high-impact actions, immutable audit, and deployment isolation. Each one comes with what breaks without it and how to verify you actually have it.
- A reference architecture for mapping governance onto the identity, DLP, and SIEM systems you already run, instead of standing up a parallel stack.
- A mapping to NIST AI RMF, ISO/IEC 42001, the EU AI Act, and the OWASP LLM Top 10, plus autonomy tiers and a phased rollout that takes you from the first workflow to the hundredth.
- Pull-outs worth keeping:
- A one-page guardrails-vs-governance decision map for what belongs at each layer.
- An enforcement-readiness checklist you can score your own program against today.

Get the playbook
Enter your details and you can download The AI Agent Governance Playbook immediately.
For more, see all our AI agent governance content.