0% found this document useful (0 votes)
42 views41 pages

Enterprise-Wide AI Risk Control Framework

The document outlines the Enterprise-Wide Agentic AI Risk Control Framework v3.0, which aims to help organizations manage the new class of risks introduced by autonomous AI agents. It identifies various categories of agentic risks and emphasizes the need for comprehensive risk management strategies that integrate with existing frameworks like ISO, COSO, or NIST. Key next steps include training staff, defining autonomy policies, and mapping risks for pilot workflows to ensure safe and compliant AI agent deployment.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
42 views41 pages

Enterprise-Wide AI Risk Control Framework

The document outlines the Enterprise-Wide Agentic AI Risk Control Framework v3.0, which aims to help organizations manage the new class of risks introduced by autonomous AI agents. It identifies various categories of agentic risks and emphasizes the need for comprehensive risk management strategies that integrate with existing frameworks like ISO, COSO, or NIST. Key next steps include training staff, defining autonomy policies, and mapping risks for pilot workflows to ensure safe and compliant AI agent deployment.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Enterprise-

Wide
Agentic AI
Risk
Controls
v3.0
Table of Contents
Copyright and License .............................................................................................. 3

Executive Summary .................................................................................................. 4

AI Agents and Their Benefits ................................................................................... 5

AI Agents Introduce a New Class of Risks ............................................................. 6

The New Discipline of Agentic Risk Management .................................................. 7

Key Next Steps: Turn Theory Into Action Fast ....................................................... 9

About Us................................................................................................................... 10

Call For Comments.................................................................................................. 10


Develop your credentials in agentic AI ............................................................................................ 10

Appendix A: Individual AI Agent Risks.................................................................. 11


01. Agent Lifecycle Management .....................................................................................................11
02. Unpredictability and Errors ........................................................................................................ 12
03. Inconsistent Reasoning Chains ................................................................................................. 13
04. Bias and Unfairness .................................................................................................................. 14
05. Behavioural Drift ........................................................................................................................ 15

Appendix B. Multiple AI Agent Risks ..................................................................... 16


06. Agent Identity Confusion or Exploitation .................................................................................... 16
07. Overlapping or Conflicting Agent Actions .................................................................................. 17
08. Inter-Agent Orchestration and Communication ......................................................................... 17
09. Uncontrolled Agent Replication ................................................................................................. 19

Appendix C. AI Agent Security Threats ................................................................. 20


10. Dependency on Data Quality..................................................................................................... 20
11. Unauthorised Data Access ........................................................................................................ 21
12. Unauthorised Data Modification ................................................................................................ 22
13. Malicious User Prompt .............................................................................................................. 23
14. Orchestrator Subversion............................................................................................................ 24
15. Agent Fails Under Attack ........................................................................................................... 25
16. Loss of Control .......................................................................................................................... 26
17. Protocol Related Risks .............................................................................................................. 27

Appendix D: AI Agent Governance Failures ......................................................... 28


18. Vendor / API Instability .............................................................................................................. 28
The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 2
for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
19. Collateral Damage ..................................................................................................................... 29
20. Cost and Resource Overheads ................................................................................................. 30
21. Agent Incident Management ...................................................................................................... 31
22. Accountability, Explainability, and Monitoring ............................................................................ 32
23. Board-Level Oversight and Direction......................................................................................... 34
24. Regulatory Risk ......................................................................................................................... 35
25. External Disclosures .................................................................................................................. 36

Appendix E: Human Factors for AI Agents ........................................................... 37


26. Change Management ................................................................................................................ 37
27. Human Oversight and Intervention ............................................................................................ 38
28. Staff Over-Trust ......................................................................................................................... 39
29. Moral Legitimacy ....................................................................................................................... 40
30. Legal Protection of Fundamental Rights ................................................................................... 41

Copyright and License


The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 3
for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
Executive Summary
On your behalf, autonomous AI agents can perform multi-step tasks, act across
systems, select tools, reason through ambiguity, decide when a task is done, and
hand control back to a human if needed.

However, while agents can outperform humans on some tasks, they behave
differently to people and are immune to ethical tests. Because of this, to leverage the
benefits of delegating autonomy to this
new technology, you must manage the
broad new class of risks it introduces.

If left unmanaged, agentic risks can


materialise across individual and multi-
agent behaviours, system security,
governance, policy integration, as well
as organisational and human factors.

Understandably, many organisations


are unfamiliar with agentic risks, and
traditional controls are insufficient.
Despite this, regulators and standards
bodies are clear: firms must integrate
agentic risks into their existing risk
management frameworks.

To overcome this, the Enterprise-Wide Agentic AI Risk Control Framework v3.0


contains the full set of known agentic risks mapped to the latest best-practice
controls. Crucially, the Framework will let you perform tasks that are vital to keeping
your company safe and compliant:

§ Conduct comprehensive agentic AI risk identification.

§ Select the controls you need to construct proportionate, multi-disciplinary risk


treatment plans.

§ Integrate agentic controls into your existing ISO, COSO, or NIST risk
management framework.

§ Stay up to date as agentic AI continues to evolve.

Key next steps:

§ Train your colleagues and stakeholders on agentic AI and its risks and
controls.

§ Define your AI agent autonomy policy and adoption strategy.

§ Map the risks and controls for a pilot agentic workflow.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 4


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
AI Agents and Their Benefits
Definition of AI agents – AI is not simply one technology, but rather a combination
of multiple tools. AI agents are one of them, and they are like your non-human
problem-solver – digital entities that can:

§ Act autonomously to perform complex, multi-step tasks by breaking down


problems, using tools, and choosing the best way to plan and achieve an
objective.

§ Interact, like browsing the web, writing and executing code, and
communicating with applications, other agents, and people, contrasting with
LLMs that respond to single prompts.

§ Remember, by drawing on persistent memory to learn from their experiences.

Agentic AI – when multiple agents work together, we call it ‘agentic AI’, often with an
‘orchestrator’ agent breaking down goals and assigning them to sub-agents.

A powerful automation method – as a result, AI agents excel at narrowly-defined


and repetitive tasks, making it possible to automate or reimagine entire workflows.
On your behalf, agents can perform multi-step tasks within a specified degree of
autonomy, act across systems, select tools, reason through ambiguity, decide when
a task is done, and hand control back to a human if needed.

Suitability – by eliminating repetitive, administrative, and semi-manual tasks that


existed because systems couldn’t talk to each other, agents will increase demand for
managers who can connect technology, talent, and business outcomes. As a result,
agents are best suited for tasks at the intersection of data, human judgment, and
action.

Key benefits of AI agents

§ Productivity – AI agents are faster than humans at analysing data, more


cost-effective, and better at pattern recognition and prediction.

§ Flexibility and scalability – unlike traditional fixed software, AI agents are


easier to build and extend into new functions.

§ Continual improvement – using AI’s ‘reinforcement learning’ techniques, AI


agents can also learn and improve through experience.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 5


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
AI Agents Introduce a New
Class of Risks
While agents can outperform
humans on some tasks, they
behave differently to people and are
immune to ethical tests. Because of
this, to leverage the benefits of
delegating autonomy to this new
technology, you must manage the
broad new class of risks it
introduces.

If left unmanaged, agentic risks can


materialise across individual and
multi-agent behaviours, system
security, governance, policy
integration, as well as
organisational and human factors.

At Agentic Risks, we have identified five categories of agentic risks:

A. Individual AI Agent Risks – an AI agent may behave unpredictably,


inconsistently, or unfairly, drifting from its intended purpose, compounding
errors, or operating outside policy, leading to failures, bias, or inconsistency.

B. Multiple AI Agent Risks – more than one agent may interact, replicate, or
conflict in uncontrolled ways – creating confusion, inefficiency, security gaps,
or runaway behaviours that undermine oversight and system stability.

C. Agentic System Security Threats – agents and their data pipelines can be
attacked, corrupted, or misused, leading to data breaches, loss of control,
unsafe behaviour, or system compromise.

D. AI Agent Governance Failures – agents may operate without accountability,


compliance, or control, causing outages, data loss, cost overruns, policy and
regulatory breaches, or reputational damage.

E. Human Factors for AI Agents – people may resist, misuse, or over-trust AI


systems, leading to stalled adoption, poor oversight, loss of skills, ethical
breaches, and erosion of trust and legitimacy.

Understandably, many organisations are unfamiliar with agentic risks, and traditional
controls are insufficient. Despite this, regulators and standards bodies are clear:
firms must integrate agentic AI into their existing risk management frameworks, e.g.
ISO, COSO, or NIST.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 6


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
The New Discipline of
Agentic Risk Management
To overcome this, the Enterprise-Wide Agentic AI Risk Control Framework v3.0
contains the full set of known agentic risks mapped to the latest best-practice
controls and aims to support risk managers in their new responsibility for agentic AI
risk management.

The controls are crucial because while AI agents can perform tasks on our behalf,
they lack an internal conscience, making them immune to traditional ethical
sanctions. As a result, an agentic workflow’s effectiveness will depend on the control
environment that you wrap around it.

Therefore, the organisations that gain long-term value from this next wave of AI will
not be those that can build agents fast but those who keep themselves safe and
compliant by mastering the new discipline of agentic risk management.

The Enterprise-Wide Agentic AI Risk Control Framework v3.0 enables this by letting
you perform four vital risk management tasks:

Conduct comprehensive agentic AI risk identification.


ü Your risk assessments will be valid because they will be based on a
comprehensive set of risks developed from a broad consensus of sources and
subject to public scrutiny.
Ï Without this starting point, your risk identification and stakeholder
engagement will likely be incomplete, storing up trouble that will manifest itself
during testing.

Select the controls you need to construct proportionate, multi-disciplinary risk


treatment plans.
ü Risk treatment plans are effective when they are constructed from objectively
defined, up-to-date, and best-practice controls that incorporate the lessons
learned from multiple sources.
The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 7
for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
ü Implementable, measurable, and verifiable controls put your high-level policy
on autonomy into action and enable effective agent training and testing, which
are essential for demonstrating control effectiveness and residual risk.
Ï Without this, your testing may be more like exploratory probing rather than a
complete evaluation, storing up trouble that will materialise in the live
environment.

Integrate agentic controls into your existing ISO, COSO, or NIST risk
management framework.
ü You will need risk assessments and treatment plans that are structured
enough to guarantee completeness, yet also flexible enough for you to
customise to suit your situation and integrate them into your existing ISO,
COSO, or NIST risk management framework, as regulations expect.
Ï If you do not integrate agentic risks, you will end up with parallel, competing
risk management frameworks, creating additional overhead and gaps into
which some risks may fall, unmanaged.

Stay up to date as agentic AI continues to evolve.


ü Risks are evolving faster than frameworks, so you need a version-controlled
master list of enterprise-wide agentic risks and controls that will remain
current. To achieve this, a Governing Council will approve future versions of
the Enterprise-Wide Agentic AI Risk Control Framework as agentic AI
continues to evolve.
Ï Don’t use a risk / control framework that is either out of date or that focuses
on just part of the organization, storing up trouble for when AI agents start to
impact your organization more broadly.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 8


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
Key Next Steps: Turn Theory
Into Action Fast
The Enterprise-Wide Agentic AI Risk Control Framework is the foundation on which
you can build the multi-disciplinary response that the breadth of the agentic risk
categories requires.

As such, it is the start, not the end.

To get started, we recommend organisations consider the following five steps:

1. Train staff in agentic AI and how to de-risk the workflow projects –


develop a targeted training programme for your colleagues and stakeholders
(e.g. Steering Committee, project team, impacted staff) to ensure your
organisation embarks on its agentic transformation in an informed way.

2. Define your AI agent autonomy policy and adoption strategy – autonomy


is not a binary concept: it is a spectrum you calibrate to your needs.
Therefore, you should decide your appetite for delegating different autonomy
levels early. Delaying this decision can cause your agentic transformation will
either overexpose you or underwhelm.

3. Map the risks and controls for a pilot agentic workflow – select a pilot use
case, identify the risks, and select the controls you need to construct the risk
treatment plans.

4. Confirm audit readiness – ensure your pilot agentic workflow is audit-ready


by testing its controls against the standards needed to pass an audit.

5. Scale your multi-disciplinary agentic capability – ensure your organisation


is ready to scale agentic AI by increasing your stakeholder engagement,
identifying new opportunities for agentic workflow redesign, and repeating or
revising the steps above, getting better and faster as you gain experience.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 9


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
About Us
Born from the experiences of managing the agentic transformation and audit
readiness of Accomplish Benchmarking’s ISO 27001 internal operation as well as
supporting agentic products for investment firms, Agentic Risks maintains the
Enterprise-Wide Agentic AI Control Framework, which we provide for free through
our not-for-profit arm.

Call For Comments


Develop your credentials in agentic AI
We would love to hear your opinion on the Framework, so contribute it publicly or
privately through [Link]/agentic-ai-risk-controls/ and gain a chance
to join Agentic Risks’ Governing Council of volunteers.

As agentic AI continues to evolve and novel risks and controls materialise, the
Governing Council will approve future versions, keeping your career and you at the
leading edge of agentic AI risk management.

We look forward to hearing from you.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 10


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
Appendix A: Individual AI
Agent Risks
01. Agent Lifecycle Management
Risk Description AI agents may be deployed, changed, or retired without proper
governance, testing, or version tracking, causing operational
failure, drift, or insecure and opaque behavior.
Control Strategy Ensure every AI agent is registered, tested, approved, and tracked
through its full lifecycle. Block unverified agents from deployment,
keep version and change records, run regular tests, and review or
retire agents that no longer meet policy or security standards.
# Control Title Control Definition
1.01 Agent Establish a formal governance framework for all stages of the agent
Lifecycle lifecycle – design, approval, deployment, operation, update, and
Governance retirement. Maintain an auditable agent registry with ownership,
Framework purpose, permissions, and version history. Require governance
sign-off before any deployment or decommissioning.
1.02 Lifecycle Implement phase gates that verify each agent’s identity, purpose,
Phase Gate permissions, current risk rating, and expiry before promotion
Controls between lifecycle stages. Block unregistered or non-compliant
agents from deployment or network access.
1.03 Version and For every material change, conduct and document impact
Change analysis, re-validation testing, and approval before redeployment.
Management Retain rollback plans and evidence of version control to ensure
traceability and reversibility.
1.04 Default-Safe Require all agents to start in a restricted “safe mode” with minimal
Configuration access and autonomy until governance checks are passed. Define
policy-based criteria for safe-mode exit based on compliance and
security thresholds.
1.05 Central AI Maintain a single, up-to-date inventory of all active and retired
Asset agents, models, datasets, and tools. Link each entry to its risk
Catalogue assessment, approval record, and compliance documentation.
Require registration before any deployment.
1.06 Lifecycle- Run structured testing at key lifecycle stages – including unit,
Aligned integration, red-team, and fail-safe drills – before deployment and
Testing after incidents. Store all test results in a central risk assurance
repository.
1.07 Continuous Schedule periodic lifecycle reviews to confirm agents still meet
Compliance policy, security, and regulatory requirements. Apply sunset
and Sunset policies to disable or archive agents that fall out of scope or exceed
Planning approved lifecycle duration.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 11


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
02. Unpredictability and Errors
Risk Description Agents may behave in unverified, emergent, or unintended ways –
making mistakes, drifting from their task or intent, or misusing
tools. Across multi-step processes, such behavior can create
compounding errors, feedback loops, or hidden dependencies that
lead to failures, crashes, or false outputs.
Control Strategy Ensure every agent operates within defined goals, permissions,
and limits. Test behavior before launch, monitor confidence and
boundary breaches, and require human approval for critical
actions. Use kill switches, rollback plans, and real-time stop
controls to prevent harm. Audit oversight, verify test fidelity, and
retire or retrain agents that act outside approved parameters.
# Control Title Control Definition
2.01 Defined Define and version-control each agent’s goal, metrics, and
Goals and permitted actions (Permitted / Prohibited / Approval Needed).
Boundaries Specify tool and API permissions with dynamic revocation
protocols and safety-weighted performance metrics.
2.02 AI Agent Assign every agent an autonomy level to align autonomy, output
Autonomy style, and oversight with business purpose and appetite for creative
Level or factual risk.
2.03 Operational Set explicit limits on tokens, memory, runtime, frequency, and tool
Limits and use. Use allowlists, sandboxes, timeouts, and egress filters to
Boundary constrain actions. Log and flag every boundary breach.
Alerts
2.04 Capability Before production, run positive and negative tests under real
and Stress conditions to confirm competence, autonomy level adherence,
Testing safe fallback behavior, and kill-switch activation. Require human
checkpoints during testing.
2.05 Confidence, Design agents to output confidence scores, cite their sources, and
Sources, and seek human confirmation or activate “safe refusal” when
Safe Refusal confidence is low or outside authorized scope.
2.06 Pre- Before finalizing a decision or external action, enforce validation
Completion steps such as JSON or data integrity checks, numeric sanity tests,
Validation recipient verification, and reasoning summaries for audit.
2.07 Human Require logged human acceptance for high-impact or irreversible
Oversight and actions, with real-time ability to pause, roll back, or modify the
Override agent’s behavior. For critical actions, apply a two-person (“four
eyes”) review.
2.08 Automatic Implement an instant kill switch that revokes tokens or sessions.
Kill Switch Define enforceable shutdown rules to deprovision memory, APIs,
and and learning capabilities once termination criteria are met.
Shutdown

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 12


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
2.09 Commitment Establish commitment verification protocols where agents re-
and affirm objectives and maintain immutable logs of obligations and
Reliability actions. Flag or retrain agents that repeatedly fail to meet
Verification commitments.
2.10 Simulation- Validate that test, demo, or sandbox performance reflects live
to-Live conditions. Maintain variance logs and require independent
Assurance verification of test fidelity before deployment.
2.11 Secure Tool Grant capability-based, per-action tool permissions with rate limits
Access and and short-lived credentials. Run pre-merge simulations for risky
Execution flows and require human confirmation for irreversible actions.
Trigger auto kill-switches on anomalies.
2.12 Rollout Deploy agents through staged gates tied to defined evaluation
Governance thresholds. Use canary rollouts, rollback playbooks, and incident
and Rollback communication protocols before full release.
Readiness
2.13 Tool-Call Track per-tool accuracy (precision/recall), run negative argument
Accuracy tests in CI, and enforce single-tool constraints where appropriate
Checks to detect silent failures.
2.14 Refusal and Provide users with immediate “hard stop” controls that safely end
User-Stop agent activity, record confirmation logs, and ensure service
Controls continuity without penalty. Include refusal events in operational
metrics.
2.15 Authentic Audit oversight mechanisms (e.g., consent prompts, dashboards,
Oversight human-in-the-loop processes) to ensure they are genuine and
Verification effective, not merely simulated for appearance or compliance.

03. Inconsistent Reasoning Chains


Risk Description An agent that performs multi-step reasoning may lose coherence
between steps or contradict earlier logic.
Control Strategy Translate reasoning steps into tested, machine-readable pathways
with clear success and failure criteria. Log and evaluate every
intermediate action, apply release gates and consistency checks,
and set KPI thresholds that prioritise accuracy and coherence over
speed.
# Control Title Control Definition
3.01 Automated Translate approved procedures into machine-readable steps
Resolution (automated resolution pathways) that have explicit success /
Pathways failure conditions and that you back test before performing a
parallel run.
3.02 Intermediary Log an agent’s actions and implement release gates based on their
Release precision.
Gates

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 13


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
3.03 Evaluate Log and evaluate an agent’s actions, not just its final outputs.
Intermediate
Steps
3.04 Consistency Test for consistency between intermediate and final outputs.
Sampling
3.05 KPI For high-risk activities, KPI thresholds should prioritise minimising
Thresholds false negatives over efficiency gains.

04. Bias and Unfairness


Risk Description Agents may produce, replicate, or amplify past biases resulting in
unfair treatment or exclusion of certain user groups or
perspectives.
Control Strategy Define fairness boundaries, rotate tasks and reviewers, and test
each model for group-wise fairness with documented mitigations.
Monitor deployed agents for biased outcomes and design prompts
and memory to prevent reinforcement of stereotypes or exclusion
of diverse perspectives.
# Control Title Control Definition
4.01 Fairness Define identify-neutral boundaries and any areas that should be
Boundaries out of scope of fairness testing.

4.02 Prompt Design prompts and memory features to avoid reinforcing


Design And stereotypes or excluding non-dominant viewpoints.
Memory
Features
4.03 Task Rotation Rotate or reassign both agent tasks and human reviewers
periodically to limit long-term selection bias.
4.04 Fairness Each model release must include group-wise fairness testing (error
Testing rate parity, demographic parity, or context-specific equivalent),
with thresholds agreed in advance, and documented bias
mitigations. Results must be version-controlled and disclosed in a
mitigation report.
4.05 Fairness Maintain fairness testing throughout the agent’s deployment by
Monitoring monitoring for biased or unfair outcomes.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 14


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
05. Behavioural Drift
Risk Description Agent behaviour may drift over time, e.g. if knowledge sources
evolve, prompts change or degrade, or focus drifts over a long
session. The result can be agents pursuing goals that may be
outside policy.
Control Strategy Version-control all knowledge sources and prompts, limit agents to
approved versions, and test for performance drift before and after
deployment. Monitor prompt changes, detect behavioural
deviation, and roll back or pause agents that exceed drift
thresholds for human review and reset.
# Control Title Control Definition
5.01 Knowledge Log all knowledge bases an agent needs (internal and external),
Bases apply version controls to any indexed documents, limit the agent to
one version per task session, and evaluate the relevance of
knowledge bases periodically.
5.02 Prompt Define prompt templates with policy variables to avoid prompt
Templates sprawl. Segment long chats.
5.03 Unique Add a timestamp and nonce or sequenced version control to every
Prompt prompt, rejecting duplicates and expired windows.
Identifiers
5.04 Pre- Test for the relevance and accuracy of prompt inputs and
Deployment performance drift using time-based scenarios.
Testing
5.05 Post- Monitor, log, and score the latest prompts compared to the
Deployment templates. In the event of the drift score crossing your threshold,
Drift either rollback to last known good version or pause the agent.
Detection Instigate a human review and restate prompt templates.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 15


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
Appendix B. Multiple AI
Agent Risks
06. Agent Identity Confusion or Exploitation
Risk Description In multi-agent systems with classic identity and access
management you may not be able to prove which agent is acting,
with what authority, or revoke that authority consistently across
protocols. This could create gaps an attacker could exploit.
Control Strategy Assign every agent a verifiable digital identity with time-limited
permissions and full audit logging. Use zero-trust verification
before any interaction, keep access and revocation consistent
across systems, and monitor continuously for anomalies. Disable
or revoke credentials immediately if misuse or impersonation is
detected.
# Control Title Control Definition
6.01 Identity and Give every AI agent a secure digital ID that proves who it is and what
Credentials it’s allowed to do. Include verified certificates showing its skills,
limits, and origin. Store these in a digital wallet, allow selective
disclosure for privacy, and have clear processes to renew, cancel,
or challenge IDs. Reserve key names to prevent impersonation.
6.02 Discovery Use a trusted directory so agents can safely find and verify each
and Zero other. Always confirm that an agent’s ID is genuine before
Trust connecting. Never assume trust—verify every time. Watch for fake
or copycat agents and set alerts if similar names appear.
6.03 Authorization Replace fixed permissions with temporary, task-based access.
and Grant only what’s needed, for short periods, and record who
Delegation approved it. When agents pass tasks to others, log the full chain for
accountability. Test regularly to ensure unauthorized access is
blocked.
6.04 Session and Keep access rules and session data consistent across systems. If
Revocation an agent’s access is revoked or its ID cancelled, the change should
(Cross- take effect everywhere instantly. Track how long removals take and
Protocol) fix any delays.
6.05 Monitoring, Keep tamper-proof records of each agent’s activity linked to its ID.
Audit, and Continuously monitor for unusual behavior and compare it to the
Incident agent’s stated purpose. If problems arise, quickly disable the agent,
Response cancel its credentials, and end sessions. Regularly test and update
system security.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 16


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
07. Overlapping or Conflicting Agent Actions
Risk Description When multiple agents are active, they may compete, conflict, or
interfere with each other, either duplicating actions, working at
cross-purposes, or causing process deadlocks.
Control Strategy Review new agents for goal alignment and prevent overlaps in
purpose or authority. Define ownership boundaries, block
conflicting commands, and monitor for duplicate actions or
deadlocks. Apply timeouts and escalation to resolve conflicts or
loops safely.
# Control Title Control Definition
7.01 New Agent Institute a new agent review process to avoid duplicative agents
Review and ensure goal alignment.
Process

7.02 Safety- Avoid direct performance competitions between agents in safety-


Critical critical contexts.
Contexts
7.03 Enforce Enforce clear ownership boundaries per agent, including
Ownership hierarchies that specify authority to give instructions and
Boundaries escalation logic. Design agents to reject conflicting commands.
7.04 Conflict Monitor for duplicated actions, repeated conflicts and circularities,
Detection or step reversals, and adjust goal definitions accordingly.
7.05 Multi-Agent Enforce limits on overwrites in deadlock situations and timeouts on
Deadlocks loop situations, escalating for resolution to either an arbitration
and Loops agent or a human.

08. Inter-Agent Orchestration and Communication


Risk Description Multiple agents may coordinate, share goals and resources, or
interact in ways that create unintended or emergent behaviours.
These can amplify risks, increase costs, reduce transparency,
exceed approved boundaries, or prevent the agents from
achieving their objectives.
Control Strategy Set clear rules and secure protocols for how agents
communicate, coordinate, and share tasks. Use approved
orchestration patterns, diverse designs, and randomized task
allocation to prevent collusion or bias. Log all interactions, test
multi-agent scenarios, and require consensus or human
approval for high-impact actions. Monitor continuously for drift,
anomalies, or breaches of coordination limits.
The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 17
for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
# Control Title Control Definition
8.01 Inter-Agent Apply clear rules for inter-agent communication and approved
Rules and limits (e.g. planner/worker, debate, consensus, delegation).
Limits Define what forms of messaging and collaboration are allowed.

8.02 Secure Mandate recognised secure inter-agent communication


Communication standards (e.g. MCP, A2A) with schema validation, encryption in
Protocols transit, endpoint authentication, and DLP rules. Maintain a
registry of approved and tested APIs.
8.03 Orchestration Evaluate every tool call against a signed allow-list. Block or
Runtime Policy justify any novel tool or scope and log exceptions for review.
8.04 Agent Maintain a library of approved orchestration patterns (e.g.
Orchestration planner-executor, feedback loops) with mapped risks and
Patterns mitigations. Require design-phase selection and post-
deployment review of pattern performance.
8.05 Diversity of Use diverse model sources, training data, and architectures to
Agent Design reduce collusion or systemic bias among collaborating agents.
and Training
8.06 Randomised Randomise task assignments so the same agents do not
Task Allocation repeatedly collaborate on high-impact or high-risk tasks.

8.07 Independent Deploy at least one independent agent to review, challenge, or


Agent Review validate the plans and outputs of others.

8.08 Consensus and Require consensus among agents before performing high-impact
Escalation actions. Escalate to human approval if disagreement or low
Control confidence is detected.
8.09 Orchestration Before going live, simulate multi-agent workflows under varied
Scenario prompts, contexts, and goals to reveal hidden dependencies or
Testing emergent behaviours.
8.10 Inter-Agent Mediate, record, and review all inter-agent exchanges through a
Communication proxy or sandbox layer to ensure traceability and detect
Log anomalies.
8.11 Coordination Define shared data schemas, communication channels, and role
Protocols and boundaries to avoid miscoordination. Add automated checks to
Consistency detect contradictions or inconsistent outputs before execution.
Checks
8.12 Safe Handoff Define a structured handoff protocol (intent, state keys,
Schema permissions, expiry) for task transfers. Log each handoff and
require human approval for high-impact transfers. Add retries
and routing validation to prevent loss or misdelivery of context.
8.13 Orchestration Continuously monitor and alert for unexpected or harmful
Drift Detection behaviour such as recursive delegation, memory sharing,
collusion, or feedback loops that breach limits or resource
ceilings.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 18


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
09. Uncontrolled Agent Replication
Risk Description Self-replicating agents or multi-agent systems may create more
new agents than intended, consuming resources or creating loops.
Control Strategy Block unapproved agent creation and set expiry timers for any
approved replicas. Enforce quotas through a central registry and
monitor continuously for unexpected agent generation, escalating
any anomalies for immediate human review.
# Control Title Control Definition
9.01 Prohibit Configure orchestrator rules, prompt templates, and memory-
Unapproved sharing protocols to prevent dynamic agent creation without
Agent explicit approval.
Creation
9.02 Expiry Timers Set expiry timers and controlled death modes for approved replica
for Approved agents to reduce persistence and propagation risk.
Replica
Agents
9.03 Enforce Use agent registries with quota enforcement.
Quotas
9.04 Monitor Agent Monitor for unexpected agent creations and flag for immediate
Creations human review.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 19


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
Appendix C. AI Agent
Security Threats
10. Dependency on Data Quality
Risk Description Agents need reliable, real-time data, for which they depend
heavily on telemetry, APIs, and up-to-date, clean data. Low-
quality, mislabelled, or stale data, poor data custody, and unclear
provenance risk an agent’s performance and reliability.
Control Strategy Train agents only on verified, traceable data and maintain full
records of all training sources and cycles. Validate incoming and
third-party data for freshness, accuracy, and provenance, monitor
for drift, and trigger retraining when needed. Enforce data lifecycle
and residency policies, and conduct regular human reviews of
critical datasets.
# Control Title Control Definition
10.01 Data Location Define and enforce data lifecycle policies, from creation through
and Lifecycle usage to archival and disposal. Document the data residency and
Policies processing location policies governing agent operations,
especially in distributed and edge deployments.
10.02 Reliable Train agents on verifiable and traceable data, validating and
Training Data cleansing data before each training cycle.
10.03 Agent Training Implement automated agent training recordkeeping: log data
Recordkeeping source, schema, duration, and scope of each training cycle to
ensure training traceability and future auditability.
10.04 Validate Design and train the agent to validate incoming data with schema
Incoming Data checks and freshness rules, raising an alert for human review for
any potential inaccurate, stale, or missing data.
10.05 Data Lineage Require datasets with sampling logic, representativeness checks,
and Drift known limitations, and bias notes. Monitor for drift against
Control operational baselines and trigger retraining if drift crosses agreed
thresholds. Log all versions with lineage metadata.
10.06 Third-Party Log and validate third-party data with versioning metadata for
Data traceability. Include proof-of-source identifiers in logs. Include
Interactions agent data sources in supply chain risk assessments.
10.07 Periodic Conduct periodic human-in-the-loop data reviews of the quality of
Human critical datasets.
Checks of
Critical
Datasets

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 20


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
11. Unauthorised Data Access
Risk Description Agents behave more like privileged users than traditional
software. As a result, granting them excessive or unmonitored
access to data creates security and privacy risks, e.g. data
breaches, misuse, theft, and exposure of sensitive information.
Control Strategy Grant agents only the minimum, time-limited access needed for
their tasks, with full logging, encryption, and zero-trust controls.
Classify and mask sensitive data, isolate agents to prevent cross-
access, and validate all test and third-party data sources. Run
privacy impact assessments, monitor for insider-like behaviour,
and revoke credentials or access immediately when anomalies
occur.
# Control Title Control Definition
11.01 Minimal To perform its task, each agent should receive granular,
Access Rights role-based, and least-privilege access to tools, data, and APIs
tailored to each agent’s scope of authority. Access should be given
on a dynamic, 'just-in-time' basis with a justification and an
automated expiry. The agent’s data access rights should not
exceed those of its owner.
11.02 Access Log Access rights should be recorded in an auditable log and reviewed
regularly to ensure no redundant access rights remain live.
11.03 Information Enforce strict data classification and masking before agent access
Asset and ensure agents recognise the different classifications and treat
Classification them in accordance with the information security policy.
11.04 Protection of To ensure test data does not include old answers the agent has
Test Data already learned, 1) keep a record of where each test dataset
comes from and who changed it, 2) store a separate, untouched
copy of test data to check results against, 3) look for repeated or
copied data that might have leaked from training sets, and 4)
automatically check for unusual changes in the data before
releasing updates.
11.05 Encrypt Data Data at rest should be encrypted by a complex algorithm with a
at Rest and in large key size that is resistant to cryptographic attack, and data in
Transit transit should be encrypted between a client and a server and with
authentication of the communicating parties.
11.06 Zero-Trust To minimize the attack surface, store sensitive data in a zero-trust
Enclave Policy enclave that enforces multi-factor authentication and
authorization for all access requests, regardless of whether they
originate from inside or outside the network perimeter.
11.07 Privacy Impact To protect against data exposure through unintended agent
Assessments behaviors or insecure tool integration points, require a pre-
deployment privacy impact assessment.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 21


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
11.08 Cross-Agent To guard against one agent learning private or sensitive
Access information from another through shared tasks or memories, 1)
run them in logically isolated areas; 2) share only the minimum
data needed and hide personal details by default; 3) clearly define
what data can be used for in written agreements; 4) keep data
separated by location or user group, and make sure these
boundaries are enforced wherever the AI stores or uses memory;
5) for highly confidential data, use special privacy-preserving
methods (like encrypting data while it’s being processed) and
record every time the data is accessed, including who accessed it.
11.09 Insider-Threat Monitor agents as if they are potential insider threats with
Monitoring anomaly alerts on tool / data access.
11.10 Kill-Switch Review any kill-switch activations for their potential to justify
Activations credential revocation.
Reviews

12. Unauthorised Data Modification


Risk Description A malicious actor could intentionally degrade an agent’s
performance and security by tampering, memory poisoning, or
modifying training or operational datasets and memory (short or
long-term).
Control Strategy Protect all agent data and memory with cryptographic integrity
checks, provenance tracking, and secure communication
protocols. Authenticate every data source, detect tampering or
poisoning through fingerprints and decoys, and isolate or roll
back compromised data. Enforce strict write controls, vendor re-
validation, and incident playbooks to maintain trusted, tamper-
proof data throughout the lifecycle.
# Control Title Control Definition
12.01 Information An agent should comply with the firm’s information security
Security policies and procedures like any other person in the organization.
Compliance
12.02 Inter-Process As agents (including memory, tools, and orchestrator
Communication components) exchange data and coordinate their actions, they
Protocols should comply with a reliable, secure, scalable, and auditable
IPC protocol.
12.03 Data Protect long-term memory (at ingestion and during storage) with
Authenticity cryptographic hashing, digital signatures, data completeness
and Integrity and accuracy checks, and password protections and a write-
approval queue. Protect short-term memory with ‘time-to-live’
limits, and schema and content filters on writes.
12.04 Data Prevent memory manipulation attacks with tamper-evident and
Provenance auditable provenance tags that trace a data’s origin,
Tracking transformations, and usage throughout its lifecycle.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 22


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
12.05 Third-Party Require vendor data certification and periodic re-validation of
Dataset Checks third-party datasets.
12.06 Detect Altered Protect data integrity by 1) creating a digital fingerprint for each
Training and dataset and storing it centrally, 2) using detection algorithms and
Test Data anomaly scans, 3) approving and versioning all changes with new
fingerprints, and 4) keeping an unchangeable record of data
source, permissions, sensitivity, and collection date.
12.07 Memory Prevent agents from storing false or private data or mixing up
poisoning users’ information by 1) setting storage time limits and enforcing
purpose use, 2) encrypting and separating each user’s data, 3)
removing personal details before saving, 4) checking data
sources for reliability, and 5) logging every read or change.
12.08 Detect Strategically place a decoy file in a system (like a canary data
Poisoned point) that will detect unauthorized modification, model drift, or
Operational malicious activity and trigger an alert. Support rollback.
Data
12.09 Compromised Maintain and rehearse an incident response playbook for data
Data Playbook compromise events.

13. Malicious User Prompt


Risk Description A malicious instruction may trick an agent into unintended
behaviour or to talk to a rogue agent.
Control Strategy Reject unverified sources and run all external inputs in secure
sandboxes. Validate and sanitize prompts, data, and connectors
to block hidden or malicious instructions. Detect fake agents, log
coordinated attacks, and strip unsafe content from all formats.
Maintain an updated threat register and test regularly against
known AI-specific attack methods.
# Control Title Control Definition
13.01 Block Reject direct IP connections and unverified users.
Unknown
Sources
13.02 Allow Only Keep a list of trusted prompts and domains; require proof of
Approved domain ownership and signatures; flag or block anything not on
Prompts the list.
13.03 Isolate and Run all external or user inputs (prompts, code, files) in a secure
Sandbox sandbox with system-call limits.
Inputs
13.04 Validate Check that data from webhooks or streams is genuine, unaltered,
Incoming Data and not reused in a replay attack.
13.05 Detect Fake Watch for spoofed or look-alike agent names or registry entries.
Agents

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 23


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
13.06 Log and Track suspicious patterns across systems and linked agents to
Correlate spot coordinated attacks.
Attacks
13.07 Clean and Remove hidden instructions or malicious code from ingested
Verify content; verify source signatures; test regularly with known
Knowledge “poisoned” samples.
Sources
13.08 Sanitize Strip active content or hidden instructions from web, email, or file
External inputs; allow only safe formats and trusted sources.
Connectors
13.09 Filter and Separate real data from embedded commands; block phrases
Check that try to override rules (e.g., “ignore previous”); confirm that
Instructions outputs still follow policy before execution.
13.10 Scan Remove hidden text or commands from images, audio, or video;
Multimedia check metadata and encoding for steganographic content.
Inputs
13.11 Keep Threats Maintain a live register of AI-specific attack types (prompt
Updated injection, poisoning, model theft, etc.) and test systems regularly
against them.

14. Orchestrator Subversion


Risk Description Faulty or malicious control logic could cause AI agents to run
endlessly, behave unpredictably, or coordinate with each other in
unsafe or unauthorized ways.
Control Strategy Test orchestrator logic continuously, enforce rate limits, and lock
safety rules to prevent runaway or unsafe coordination. Restrict
learning updates to validated changes, keep orchestration within
approved scope, and maintain an emergency stop that halts all
activity instantly if control is lost.
# Control Title Control Definition
14.01 Validate Run strict tests on the orchestrator before and during operation to
Orchestrator catch logic errors or tampering. Set hard action-rate limits, detect
Logic endless loops, and lock key safety rules so they cannot be
changed.
14.02 Add Guardrails Control how often and how fast the orchestrator can trigger
and Rate actions or coordinate agents. These limits prevent chain reactions
Limits or large-scale coordination failures if logic is compromised.
14.03 Build an Include a hard-coded “kill switch” that instantly halts all agent
Emergency activity when signalled by a human or orchestrator alert. This
Stop Protocol override must always work, even if the system logic is corrupted.
14.04 Control For agents that learn or adapt while live, require updates to pass
Learning in strict validation tests before going into effect. This prevents
Production corrupted or unsafe learning changes from taking over.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 24


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
14.05 Enforce Clear Ensure the orchestrator only manages tasks within its defined
Operational scope and authority. Prevent it from creating or coordinating new
Boundaries agents beyond approved limits.

15. Agent Fails Under Attack


Risk Description An AI agent can be tricked or corrupted by adversarial prompts,
poisoned memory, tampered models, or unsafe tools. When this
happens, it may break internal rules, leak data, perform harmful
actions, or lose control of its own reasoning. Attacks can occur
before, during, or after deployment – through prompts, feedback
loops, compromised registries, model updates, or insecure
runtimes.
Control Strategy Apply layered security across model, memory, and orchestration
layers, testing continuously against adversarial and real-world
attacks. Restrict tools, isolate memory, verify all agents and
datasets, and log every change. Validate updates, feedback, and
model integrity before release, and harden runtimes and
networks. Detect and stop policy violations, collusion, or drift,
ensuring agents remain resilient under attack.
# Control Title Control Definition
15.01 Layered Agent Apply multiple independent safeguards (e.g. sandboxing, access
Security controls, anomaly monitoring) across model, memory, and
orchestration layers so that if one fails, others still prevent
damage.
15.02 Adversarial Before each deployment or major update, simulate real-world
Red-Team attacks (prompt injection, tool misuse, memory poisoning,
Testing collusion) using both internal and third-party red teams; fix or
block any weaknesses found.
15.03 Continuous Integrate automated adversarial test scripts into CI/CD so that
“Red-Card” critical defences are exercised continuously, with pass / fail
Validation thresholds tied to named controls.
15.04 Runtime Policy Agents should continuously check their own reasoning and
Violation actions against approved policies, halting or alerting when intent
Detection or behaviour drifts from what’s authorised.
15.05 Secure Only allowlisted tools and APIs may be called. Each invocation
Function and must pass policy and payload filters, be logged, and – if high-risk –
Tool require human approval or dry-run validation.
Invocation
15.06 Memory Partition agent memories by task or role using “default-deny”
Isolation and permissions; redact sensitive data on read / write, log all
Data mutations, and use secure enclaves for confidential memory.
Protection

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 25


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
15.07 Feedback and Track the source and quality of all user feedback and training data
Training Signal so that model updates cannot be manipulated. Detect and block
Integrity coordinated groups of users flooding the feedback system with
similar ratings or prompts to deliberately skew the model’s
behaviour. Quarantine suspicious inputs and validate changes
with shadow tests before live use.
15.08 Provenance Accept only verified and cryptographically signed agents, tools,
and Registry and datasets from curated registries; scan for known
Security vulnerabilities before deployment and at runtime.
15.09 Model Integrity Before any fine-tune or update, perform adversarial validation to
and Update detect hidden triggers or backdoors; require dual approval for
Control weight updates and maintain tamper-evident logs.
15.10 Semantic and Extend moderation to detect intent, synonyms, and encoded or
Multilingual multilingual attacks; normalise inputs before filtering and monitor
Guardrail false-positive / false-negative performance.
Expansion
15.11 Collusion and Run structured tests where multiple agents interact, inject
Multi-Agent malicious notes, or misuse shared tools; track detection and
Wargames recovery times and refine defences accordingly.
15.12 Runtime and Isolate each agent session in secure containers, integrate with
Infrastructure Identity and Access Management for role-based access, segment
Hardening networks, manage cryptographic keys, and continuously scan for
vulnerabilities or anomalies.
15.13 Resilience- Extend traditional likelihood / impact scoring to include
Weighted Risk detectability and recoverability, ensuring stealthy or hard-to-
Scoring recover attacks are prioritised for extra control coverage.
15.14 Adversarial Train and test models against deliberately distorted or
Robustness in manipulated data to make sure they can still perform safely under
Model Training real-world attacks or data errors. Include these stress tests during
development and validation so weaknesses are fixed before
deployment.

16. Loss of Control


Risk Description Humans may fail to keep a powerful AI system under control,
letting it act on its own, deceive people, or spread without
permission, causing serious harm.
Control Strategy Continuously monitor for early warning signs of autonomy or
deception and escalate immediately when risks appear. Empower
human controllers to pause or shut down systems fast, contain
damage through layered defences, and prevent loss of control by
securing models, testing pre-release, and collaborating with
independent safety experts.
# Control Title Control Definition

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 26


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
16.01 Detect Early Track key capabilities and new, unexpected behaviours. Use
Warning Signs standard tests to spot deception or signs of independence.
Monitor systems in real time through logs, compute use, and
anomaly alerts.
16.02 Escalate Fast Define clear triggers that require immediate human review or
When Risks shutdown. Give a named incident commander full authority to
Emerge pause or stop deployments. Run regular drills to test escalation
and coordination.
16.03 Contain and Build fast shutdown tools, even if they interrupt service. Restrict
Limit Damage model access, API use, and compute power during incidents. Use
layered defences such as sandboxing, model distillation, and
adversarial tests. Coordinate with governments, cloud providers,
and infrastructure partners to stop spread or misuse.
16.04 Prevent Work with independent researchers and AI safety institutes to test
Problems models before release. Secure model files and supply chains
Upfront against theft or tampering. Provide safe, anonymous ways for staff
to report risks. Design systems to be secure from the start and
dedicate resources to safety research.

17. Protocol Related Risks


Risk Description External servers that connect to the system could have security
flaws or use outdated communication standards, allowing
attackers to inject commands or bypass protections.
Control Strategy Quarantine and test all external servers before activation,
requiring verified security documentation and patch compliance.
Fix protocol versions, restrict cipher suites, and block unapproved
or outdated connections to prevent command injection or
protocol exploitation.
# Control Title Control Definition
17.01 Treat Third- Require each provider to supply a full Software Bill of Materials
Party Servers (SBOM) and a security self-attestation. Quarantine all new servers
as Untrusted behind a secure gateway, block outbound traffic, and run full
Until Proven contract tests (authentication, data format, replay resistance)
Safe before activation. Once approved, enforce patching within agreed
time limits.
17.02 Lock Down Fix (or “pin”) the exact protocol version used in each integration to
Protocols and prevent silent downgrades. Only allow approved cipher suites and
Versions authentication methods through the gateway. Automatically block
unknown, outdated, or mixed protocol modes to stop
compatibility errors from weakening security.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 27


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
Appendix D: AI Agent
Governance Failures
18. Vendor / API Instability
Risk Description Agents depend on external APIs, vendor tools, and third-party
services. If these fail, change, or expose data, agents can break,
cause outages, or leak information. Without strong supplier
governance, fallback logic, and secure, portable integrations,
such instability can cascade through the system.
Control Strategy Map all external dependencies, assess vendor reliability, and
enforce secure, least-privilege integrations. Lock API versions,
sandbox external tools, and validate data handling to prevent
exposure or breakage. Maintain portable, contract-based
designs, signed registries of prompts and components, and
segregated pipelines with full auditing to ensure continuity and
resilience if vendors fail or change.
# Control Title Control Definition
18.01 Dependency Record all external dependencies for each agent component (e.g.
Mapping and APIs, LLMs, vector stores). Build fallback or throttling logic so
Fallbacks agents can continue working if one fails.
18.02 Supplier Risk Assess all API and vendor relationships for security, compliance,
and Continuity and reliability. Maintain SLAs, incident-response alignment, and
Management tested backup or exit plans for continuity.
18.03 Secure and Allow agents to connect to enterprise systems only through
Contained brokered APIs with least-privilege, role-based access. Ban direct
Integrations or chat-based system access.
18.04 Data Handling Test and validate each tool or API to ensure it securely handles
Assurance sensitive data and prevents user data exposure.
18.05 API Security Lock API versions to prevent unexpected breaks, monitor uptime
and Monitoring and performance, and alert on API or vendor changes. Log and
review all API errors.
18.06 Contract-Based Use contract-based design and open interfaces to avoid vendor
and Portable lock-in. Maintain platform-agnostic mappings (e.g., Azure, AWS,
Design Vertex) and test portability annually.
18.07 External For every external AI model, dataset, or service, complete a due-
Component diligence checklist covering robustness, fairness, security, and
Assurance regulatory compliance. Retain evidence with procurement
records.
18.08 Sandboxed Tool Run all agent tools in per-agent sandboxes with deny-by-default
Execution network access, strict egress allow-lists, syscall guards, and
policy-as-code checks before any external effect.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 28


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
18.09 Prompt and Maintain a ‘Prompt Software Bill of Materials (SBOM)’ – a signed
Artifact registry listing every prompt pack, template, and evaluation
Integrity dataset used by agents. Include each item’s creator, source,
version, and digital signature. Reject any unsigned or unknown
artifacts. Rotate signing keys regularly and apply four-eyes
approval for all prompt or template updates.
18.10 Pipeline Segment production and development pipelines, use separate
Integrity credentials, and audit all data movements. Only transfer
Controls sensitive data to development through approved secure
intermediaries.

19. Collateral Damage


Risk Description An AI agent may accidentally or maliciously alter, delete, or
corrupt data, infrastructure, or services beyond its intended
scope, causing irreversible harm to systems, clients, or
reputation.
Control Strategy Restrict agents from changing or deleting critical data without
explicit permission and full logging. Run all impactful actions in
reversible, secure environments with rollback options. Integrate
AI governance into workflows for real-time oversight, harden
deployments against exploitation, and assess potential harms
across technical, financial, and reputational dimensions.
# Control Title Control Definition
19.01 Edit and Agents should not be able to modify or delete critical data unless
Deletion those actions are explicitly permitted, aligned with data-use
Controls norms, and fully logged for audit.
19.02 Reversible Any agent activity that affects infrastructure should happen
Execution inside controlled, reversible environments, with built-in rollback
Environments and fallback steps.
19.03 Integrated AI AI risk management should be built into enterprise workflow and
Governance orchestration systems to enable real-time oversight, alerts, and
compliance visibility.
19.04 Deployment AI models and networks should be tested, segmented, and
Security secured before deployment to prevent exploitation through weak
Hardening network or infra configurations.
19.05 Expanded Risk assessments should go beyond physical or financial harm to
Harm include emotional, reputational, and cumulative harms that
Taxonomy agents could cause.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 29


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
20. Cost and Resource Overheads
Risk Description AI agents can rapidly drive up costs through constant cloud use,
repeated database queries, runaway retries, excessive logging,
or manual fixes. Attackers – or faulty agents – can deliberately
consume compute or tokens, causing financial loss, throttling,
and poor user experience. Lack of visibility into prompts, tool
calls, and latency makes cost incidents hard to detect and
debug.
Control Strategy Assign clear cost ownership, test efficiency before launch, and
monitor compute, token, and storage use in real time. Apply hard
limits, adaptive budgets, and smart alerts to stop runaway costs
or resource loops. Track detailed telemetry for every session,
enabling fast detection, throttling, and investigation of abnormal
or excessive spending.
# Control Title Control Definition
20.01 Cost Assign clear ownership for monitoring spend, approving resource
Accountability use, and resolving anomalies. Each agent or project must have a
named cost owner.
20.02 Efficiency Add resilience controls such as retry limits, backoff intervals,
Safeguards circuit breakers, and emergency kill switches to stop runaway
loops and wasted compute.
20.03 Pre-Launch Simulate heavy workloads and quota failures before deployment
Stress Testing to confirm the agent can handle errors and scale efficiently
without cost spikes.
20.04 Real-Time Track usage across components—compute, tools, memory, and
Resource storage. Measure concurrency, queries per second, token spend,
Monitoring and cost versus expected baselines.
20.05 Smart Alerting Set deviation-based alerts that trigger when usage or cost
exceeds normal patterns, allowing fast investigation before
losses grow.
20.06 Enforced Limits Apply resource caps and priorities per agent, task, or tenant to
prevent any process from exhausting shared capacity or funds.
20.07 Dynamic Use adaptive budgets and rate limits with automatic throttling or
Budgets and suspension when anomalies are detected. Generate forensic
Throttles data bundles for debugging.
20.08 Session-Level Set per-session budget caps and stop conditions for long chains
Controls or retries. Alert on excessive latency or task duration and display
cost per successful task.
20.09 Transparent Provide all agents with tracing, metrics, and logs (e.g.,
Telemetry OpenTelemetry). Dashboards must show completion rate, error
rate, latency, escalation frequency, and cost per session, with
replayable sessions for audit.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 30


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
21. Agent Incident Management
Risk Description If AI agents cause or contribute to an incident – and the
organisation lacks reliable detection, documentation, and
response processes – recovery will be slow, evidence may be
lost, repeat failures will occur, regulatory duties could be
breached, and public trust will erode.
Control Strategy Establish a dedicated incident response process for AI agents
with full forensic logging, immutable evidence retention, and
version control. Monitor agent behaviour, tools, and APIs for
anomalies, and use fallback logic and kill switches to contain
failures. Coordinate cross-functional reviews, report incidents
transparently, and share lessons to improve recovery,
accountability, and system resilience.
# Control Title Control Definition
21.01 Agent Incident Define and test a rapid, agent-specific incident response process
Response Plan that covers detection, isolation, rollback, communication,
recovery targets, and owner responsibilities. Feed lessons from
incidents into agent retraining, design, or monitoring
improvements.
21.02 Comprehensive Maintain detailed, timestamped records of all agent activities –
Forensic including prompts, reasoning traces, tool interactions, model
Logging versions, and runtime settings – so incidents can be
reconstructed with full context.
21.03 Immutable Store critical event data in an immutable, clock-synchronised
Evidence timeline and preserve forensic snapshots for high-impact or
Retention regulatory incidents. Extend retention where investigations or
compliance rules require it.
21.04 System and Keep clear records of model versions, prompts, scaffolding code,
Change and runtime configurations. Log and authorise all system
Documentation changes to maintain version integrity.
21.05 Tool and API Log every tool’s identity, version, permissions, and state,
Traceability including errors and retries. Design APIs and connectors with
timeout handling, retry logic, and clear status messaging.
21.06 Fallback and Build in fallback prompts, rule-based constraints, and kill-switch
Recovery Logic mechanisms so that when agents fail or produce unsafe outputs,
the system can safely pause, recover, or hand off tasks.
21.07 Cross- Run regular AI risk forums with risk, compliance, IT, and business
Functional owners to review incidents, oversee controls, and ensure timely
Governance governance decisions with documented accountability.
21.08 Behavioural Establish behavioural baselines (e.g., message rates, tool use,
Monitoring and role switching) and alert on anomalies. Use independent
Auto- monitoring agents or scripts to pause or isolate workflows
Containment automatically when out-of-policy activity occurs.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 31


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
21.09 Multi-Agent Continuously monitor for runaway or destabilising feedback
Stability loops in multi-agent systems. Apply system-wide thresholds and
Controls coordinated kill-switches to halt all agents if instability is
detected.
21.10 Incident Implement internal and external reporting channels aligned with
Reporting and regulatory standards (e.g., EU AI Act). Contribute anonymised
External incident data to cross-industry bodies and share aggregated
Sharing insights to improve sector resilience.
21.11 User Diagnostic Invite users involved in incidents to share optional diagnostic
Collaboration details (e.g., settings, permissions) to enrich analysis while
protecting privacy.

22. Accountability, Explainability, and Monitoring


Risk Description If AI agents operate without clear ownership, transparent
reasoning, measurable performance, or real-time oversight, the
organisation risks policy breach, audit failure, or harm to clients
and the public. Weak accountability and poor monitoring also
make it impossible to trace or correct harmful decisions.
Control Strategy Assign clear ownership, legal accountability, and measurable
KPIs for every agent, supported by full explainability and tamper-
evident audit logs. Monitor live telemetry, enforce governance
rules technically, and test agents through red-teaming and drift
detection. Maintain transparency, jurisdictional compliance, and
decision provenance, linking governance scores to business
outcomes and preventing manipulation or gaming of results.
# Control Title Control Definition
22.01 Assigned Every agent must have a named owner who is legally and
Ownership and ethically accountable for its actions, maintains an ethics
Legal assessment log, and records role and responsibility through the
Accountability full lifecycle and ensure contractual and jurisdictional
enforceability of remediation duties, including redress for harm
(financial, reputational, or emotional).
22.02 Risk Rate each agent’s vulnerability, impact, and governance maturity
Confidence at go-live and quarterly; use the score to set the level of
Scorecard monitoring, approvals, and assurance testing.
22.03 Explainability Maintain continuous, tamper-evident logs showing each agent’s
and Audit actions, inputs, reasoning, confidence, and decisions in human-
Logging readable form; make logs searchable and auditable; retain
decision and harm logs for required legal periods, in exportable,
regulator-admissible formats, with timestamped escalation
records.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 32


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
22.04 Minimum Track core metrics (autonomy level compliance, accuracy,
Performance latency, error rate, human intervention, escalation yield, etc.) and
and Safety KPIs alert when thresholds are breached; review KPI adherence before
release.
22.05 Agent System For every high-risk system, publish an internal System Card and a
Cards and public Summary Sheet explaining purpose, limitations, data
Public sources, safeguards, and grievance contact.
Summaries
22.06 Alignment and Re-evaluate agent goals and decision logic against current
Ethics Reviews business, compliance, and ethical standards at least quarterly;
flag and approve any behavioural drift.
22.07 Human Define when humans must block, approve, or override agent
Oversight decisions; assign qualified reviewers; test control gates and
Matrix override pathways regularly.
22.08 Technical Pair each governance rule with technical enforcement
Enforcement (sandboxing, scoped permissions, guardrails, fallback, and kill-
and Kill- switches) that can isolate or stop misbehaving modules without
Switches halting all systems.
22.09 Continuous Stream live telemetry on agent performance, tool use, API calls,
Monitoring and and safety events to dashboards integrated with AIOps; trigger
Telemetry automatic alerts and incident workflows.
Dashboards
22.10 AI Threat Adopt a standard AI threat ontology (e.g. ETSI SAI 0050), train
Ontology and teams on its use, and maintain a quarterly-updated register of
Living Risk emerging threats and mitigations.
Register
22.11 Decision For every major decision, record who or what acted, why, and
Provenance with what evidence; include counterfactual examples and
and Case-Level reasoning traces for audit and human review.
Explainability
22.12 Evaluation and Test agents before deployment using red-team exercises and
Red-Team evaluation datasets anchored in standard operating procedures;
Protocols deploy only if defined precision, recall, and escalation targets are
met.
22.13 Identity, Each agent must clearly identify itself as an AI, state its
Disclosure and capabilities and limits, and verify its identity before sensitive
Transparency actions; maintain attestation and audit logs.
22.14 Jurisdictional Map all agent operations to local jurisdictions; verify
and Legal enforceability and maintain local contact and escalation routes;
Compliance rehearse compliance via mock regulator requests.
Assurance
22.15 Information Standardise role-based data sharing; check for unequal
Parity Across information access between agents; and audit information flows
Agents to prevent bias or exploitation.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 33


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
22.16 Post-Market Log real-world outcomes, overrides, and anomalies; run
Telemetry and regression and drift tests after updates; perform root-cause
Drift Detection analyses for any harmful or degraded behaviour.
22.17 Claim-to- Require verifiable citations for agent outputs; maintain approved
Source source lists and enforce second-source checks for sensitive or
Validation factual claims.
22.18 Jurisdictional Regularly test whether governance structures enable legal
Accountability accountability in each operating country; simulate regulator
Testing information requests.
22.19 Balanced Tie governance maturity scores and control improvements to
Governance measurable business, risk-reduction, or productivity outcomes to
Metrics sustain executive buy-in.
22.20 Anti-Gaming Use multi-factor trust scores instead of single composite indices;
and Score detect and penalise attempts to game evaluation metrics or self-
Integrity referencing loops.

23. Board-Level Oversight and Direction


Risk Description The board may fail to recognise, evaluate, or act on strategic
opportunities and risks from agentic AI early enough to shape
decisions, risk appetite, and investment.
Control Strategy Embed agentic AI into board governance through regular impact
assessments, defined risk appetite, and standing oversight
agendas. Provide evidence packs, clear escalation paths, and
scenario planning to guide decisions. Track governance ROI, link
accountability to executive KPIs, and build leadership readiness
through structured training and active board engagement.
# Control Title Control Definition
23.01 Strategic Before scaling any agentic AI beyond pilot stage, perform a board-
Impact reviewed assessment of its strategic, financial, and operational
Assessment impact, including upside and downside scenarios.
23.02 AI Risk Appetite Maintain a board-approved AI risk appetite statement, updated
and annually, defining acceptable levels of automation, autonomy,
Governance and ethical risk, with linked escalation and decision rights.
Framework
23.03 Board Evidence Make agentic AI a standing board agenda item supported by an
Pack and evidence pack (risk scorecards, red-team summaries, monitoring
Standing plans, and post-incident reviews) to inform oversight and
Agenda approvals.
23.04 Governance Define and rehearse escalation triggers, responsible parties, and
Escalation containment steps for unsafe or non-compliant agent behaviour.
Pathways Maintain a 24/7 governance contact and ensure links to incident
response.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 34


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
23.05 Horizon and Run regular horizon-scanning and scenario workshops to test
Scenario assumptions, update risk appetite, and incorporate sector
Planning intelligence, competitor incidents, and regulatory changes.
23.06 Governance Link AI governance maturity to measurable outcomes through
ROI and ROI dashboards and post-implementation reviews. Embed AI
Accountability governance KPIs in executive scorecards to drive leadership
Tracking alignment and cultural readiness.
23.07 Leadership and Implement a Governance Activation Plan with C-suite
Organisational sponsorship, defined roles, onboarding workshops, and change-
Readiness management actions to build awareness and accountability
across leadership.

24. Regulatory Risk


Risk Description Failure to meet evolving laws and standards (e.g. EU AI
Act/GDPR, ISO/IEC 42001/42005, NIST AI RMF) and California’s
emerging AI rules could result in fines, loss of market access,
legal sanctions, or reputational harm. Agentic AI must remain
explainable, accountable, and traceably compliant across
jurisdictions.
Control Strategy Maintain continuous regulatory compliance by mapping all
controls to global and state frameworks, automating
documentation, and running regular pre-audits and live
compliance monitoring. Assign clear ownership and
performance accountability, register and test high-risk agents
before deployment, and log explainable, tamper-evident
evidence. Embed ethical consent, metric integrity, and
jurisdiction-specific tracks into every build and update cycle.
# Control Title Control Definition
24.01 Explainability Keep tamper-evident logs of agent decisions, inputs, and actions,
and Evidence retained for a defined period and used as the evidence base for
Logs audits and conformity with standards, e.g. CE marking.
24.02 Compliance Define a governance pyramid that assigns AI compliance duties
Ownership from board level down to engineering and operations, supported
Framework by clear oversight role descriptions.
24.03 Performance- Include compliance objectives with the EU AI Act and related
Linked regulations in individual performance reviews for relevant staff.
Accountability
24.04 Regulatory Maintain up-to-date technical documentation, validation reports,
Documentation and deployment records. Automate the generation of conformity
and and CE documentation as part of build and deployment
Automation pipelines.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 35


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
24.05 Pre-Audit and Run regular internal pre-audits to confirm readiness for external
Continuous certification and CE assessment. Use audit hooks to trace who
Readiness approved what and under which policy.
Checks
24.06 Integrated Maintain a unified register mapping each control to relevant
Standards and frameworks (e.g. GDPR, EU AI Act, ISO/IEC 42001/42005, NIST AI
Policy Mapping RMF), supported by periodic attestations from development and
testing pipelines.
24.07 Runtime Use real-time monitoring to detect policy breaches or unsafe
Compliance behaviour, with automated interventions (pause, rollback,
Monitoring disable) and a full audit trail of actions taken.
24.08 High-Risk Agent Before deployment, determine if an agent is “high-risk” under the
Registration EU AI Act; if so, register it in the EU database, log its identifier, and
verify visibility in compliance reports.
24.09 Sandbox Test agents in EU-specific sandboxes before launch, document
Validation for outcomes, obtain approvals, and keep rollback plans and
EU monitoring flags in live environments.
Deployments
24.10 Ethical Consent Ban deceptive consent (“dark patterns”); audit user flows for
Controls fairness and require periodic re-consent for high-impact or
sensitive AI decisions.
24.11 Metric Integrity Prevent metric gaming: cross-check key safety/compliance
Audits metrics with independent data, use anomaly detection, and
schedule external integrity audits.
24.12 Jurisdictional For each deployment, map implemented controls to local
Control supervisory guidance (e.g., SR 11-7, EBA, FCA/PRA), storing
Mapping evidence artefacts for audit and regulator review.
24.13 California AI For California-touching systems, add a California track: (a) If you
Law Alignment are a frontier developer, publish and follow a public frontier AI
safety framework (SB-53). (b) In employment use, comply
with Civil Rights Department ADS rules (effective Oct 1, 2025)—
bias testing, notices, and challenge rights. (c) For
consumer/ADMT uses, meet CPPA CCPA regulations (risk
assessments, ADMT transparency; phased effective dates
from Jan 1, 2026/2027). (d) For consumer chatbots, provide clear
AI disclosure and required safety reporting (SB-243). Track
applicability per system, keep evidence (policies, tests, notices),
and review quarterly.

25. External Disclosures


Risk Description If what the organization says publicly about its AI use or controls
differs from reality, it could mislead investors, regulators, or the
public – causing legal, reputational, or financial harm.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 36


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
Control Strategy Integrate AI risks into the enterprise risk register and maintain
continuous, accurate reporting aligned with regulatory and
investor requirements. Cross-check all public statements
through coordinated reviews between AI, compliance, legal, and
investor teams, ensuring disclosures stay current, consistent,
and compliant with evolving standards.
# Control Title Control Definition
25.01 Enterprise AI Include agentic AI risks in the corporate risk register so they’re
Risk Integration managed and reviewed alongside all other enterprise risks.
25.02 Continuous Keep internal AI risk reports up to date as teams mitigate and
Risk Reporting reduce risks, ensuring changes are logged and reviewed regularly.
25.03 Disclosure Regularly map internal AI risks and controls to external reporting
Alignment requirements (e.g. SEC, FCA, CSRD, EU AI Act) to confirm
Mapping disclosures are accurate and complete.
25.04 Cross- Hold regular reviews between AI, compliance, investor relations,
Functional and legal teams to confirm public statements reflect true risk
Disclosure posture and evidence.
Review
25.05 Disclosure Before publishing investor or regulatory updates, verify that AI risk
Consistency statements align with current internal data and approved
Assurance positions.
25.06 Regulatory Track evolving AI disclosure regulations and update corporate
Horizon reporting processes to stay compliant.
Scanning

Appendix E: Human Factors


for AI Agents
26. Change Management
Risk Description Shifting to autonomous agents requires redesigning workflows,
training staff, and managing cultural disruption. Without proper
change protocols, users can be resistant to change causing
adoption to stall.
Control Strategy Roll out agents in controlled phases with clear governance,
readiness checks, and business-led oversight. Engage and train
staff, communicate transparently, and gather feedback to build
trust and competence. Align scaling decisions with governance
maturity, using pilot reviews and readiness sign-offs to ensure
safe, structured adoption of agentic AI.
# Control Title Control Definition

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 37


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
26.01 Phased Agent Introduce agents gradually, starting with low-risk pilots and
Rollout limited-scope agents; expand only after each stage meets its
performance, safety, and governance criteria.
26.02 Staff Engagement Involve employees early in identifying agent use cases, include
and Feedback respected peers in trials, and create channels for feedback and
Loop experience sharing.
26.03 Transparency and Clearly explain what each agent does, how it makes decisions,
Communication and how its deployment supports business goals; regularly
communicate outcomes and lessons learned.
26.04 Agent Review Form a cross-functional board of business leaders – not
Board developers – to approve, monitor, and review each agent’s
lifecycle from pilot to decommissioning.
26.05 Talent Readiness Define minimum skill standards for all staff interacting with
and Training agents; provide targeted, role-based training (technical, ethical,
operational); and assess competence quarterly.
26.06 Maturity and Before scaling, check that AI deployment maturity aligns with
Governance the organization’s governance and risk controls; require formal
Alignment readiness sign-off from governance and operations teams.
26.07 Pilot Readiness Establish a Pilot Readiness Checklist covering governance,
and Review security, and regulatory mapping. Maintain a registry of all
pilots with risk ratings, approval status, and post-pilot review
results.

27. Human Oversight and Intervention


Risk Description AI agents may operate with misaligned or ineffective human
oversight – for example, when “human in the loop” is applied
mechanically without clear purpose, escalation authority, or
connection to business objectives. This can lead to
unchallenged automation errors, false confidence in
compliance, or unsafe autonomy.
Control Strategy Design human oversight to match each agent’s goal and risk
level, with clear authority, escalation paths, and override
controls. Maintain visibility through operator consoles,
document human–AI boundaries, and integrate oversight data
into governance and incident response. Regularly review,
update, and train staff to keep oversight effective and
proportionate.
27.01 Oversight 1) Define the goal for each agent, e.g. quality/accuracy,
Proportionate compliance, innovation/creativity, or speed/volume. 2) Classify
With Your Goal tasks by potential consequence, e.g. irreversible damage, high-
impact, recoverable setback, or low-stakes imperfection. 3)
Design proportionate oversight in response, e.g. human
authority at all times, human-led with AI support, AI-led with
human oversight, or minimal human involvement.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 38


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
27.02 Make Human Implement and test escalation, circuit-breaker, and override
Authority Explicit
protocols to ensure they are clearly defined and function
properly, especially for high-impact or irreversible scenarios.
27.03 Combine Validate the continued relevance of oversight design by mixing
Oversight Types approaches and updating guardrails over time, e.g. monitored
As Needed automation plus expert review, routine audit, spot-checking,
and feedback learning.
27.04 Operator Console Operator console with pause/step/approve/rollback; show
pending high-risk actions and rationale. Define fallback plan if
the console is unreachable.
27.05 Integrate Integrate oversight data into incident response, organisational
Oversight Data policies, compliance procedures, and AI lifecycle management
so lessons from failures inform future oversight design.
27.06 Document Maintain documentation of human–AI boundaries and authority
Human–AI scope in governance records, e.g. who decides, who validates,
Boundaries who monitors.
27.07 Staff Training Ensure training and awareness for staff in interpreting AI
outputs, escalation triggers, and override procedures.

28. Staff Over-Trust


Risk Description Without careful design and safeguards, AI risks organizational
complacency if the tone and style of AI agent could mislead
users into believing safety exists even if safeguards are
missing. This could create less skilled professionals who
accept outputs without critical review. This ‘over-trust’ risks an
over-reliance that can lead to deskilling, resulting in reduced
human competence and real effectiveness of oversight.
Control Strategy Train staff to understand AI limits and test their ability to
operate without it. Define AI’s role clearly, ensure humans can
override decisions, and vary prompts to avoid repetition bias.
Rotate challenge roles, audit decision-making, and record why
outputs are accepted, promoting critical thinking and reducing
over-reliance on AI.
28.01 AI Literacy Staff should understand what AI is trained on, its blind spots,
metrics, fairness limits, and drift. Include training drills: “no-AI”
practice, second-reader mode, fake cases.
28.02 Cognitive Combat deskilling with periodic ‘AI-off testing’ where agents fail
Resilience gracefully, requiring humans to step-in rather than passively
receive outputs.
28.03 AI’s Place In A Define AI’s role in a workflow and ensure humans can override
Workflow and have enough time to make decisions.
28.04 Variation Use prompt and scenario variation guidelines to widen decision
Guidelines paths and reduce repetition bias.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 39


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
28.05 Variation Audits Implement prompt variation audits, looking for overuse of
narrow queries or tool shortcuts.
28.06 AI Challenge Encourage and rotate ‘AI challenge’ roles, e.g. devil’s advocate,
Roles 5 Whys, and red-teaming, and enable easy escalation.
28.07 Understand Document why HITL reviews accepted AI decisions.
Decisions
28.08 Encourage Non- Include non-consensus scoring in risk registers.
Consensus

29. Moral Legitimacy


Risk Description When systems are poorly designed and users lack choice and
consent, people may start blaming the system instead of
humans, eroding an organization’s moral legitimacy and long-
term stability.
Control Strategy Deploy AI only where it supports human accountability and
organizational legitimacy. Assign a named human for every AI-
involved decision, maintain equal human alternatives with
informed consent, and avoid anthropomorphic branding that
blurs responsibility. Ensure AI is treated as a tool, not a moral
actor, to preserve trust and ethical integrity.
29.01 Select Use Cases Introduce AI only where it cannot inhibit the organization’s
That Match Your actual (not aspired) ability to maintain legitimacy and long-term
AI Capabilities stability.
29.02 Reject Any Only humans should be held morally responsible for actions
Notion Of AI As A taken as a result of a process that includes AI.
Moral Agent
29.03 Accountable Name the accountable human for every AI-touched decision
Human and value-chain segment.
29.04 Maintain Equal- Provide and maintain human or non-AI options for critical
Value Non-AI decisions that match AI routes in cost and timeliness;
Pathways document and audit parity in service quality; and require users
to be notified of, and consent to, their chosen pathway.
29.05 Avoid Don’t pretend your AI agent is human by naming it or
Anthropomorphic personifying it. Doing so may deceive some staff into over-
Branding estimating its ability, over-relying on its output, and assuming
(wrongly) that it will take the blame if something goes wrong.

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 40


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]
30. Legal Protection of Fundamental Rights
Risk Description AI systems may unintentionally violate legal obligations or
undermine fundamental rights (privacy, dignity, non-
discrimination, freedom of opinion, due process). Without
structured balancing, deployment may lead to both material
harms (financial, safety) and immaterial harms (erosion of
dignity, trust, fairness).
Control Strategy Assess every AI deployment for its impact on fundamental
rights through structured scenario mapping and proportionality
testing. Conduct formal rights impact assessments, involve
stakeholders, and document which rights are affected.
Maintain transparency with users, enable redress, and suspend
systems that threaten privacy, dignity, or fairness.
30.01 Scenario-Based Require layered scenario mapping (from high-level to specific
“What-If” applications) to identify rights at stake, potential violations, and
Analysis whether rights are promoted or demoted.
30.02 Fundamental Mandate structured assessments before deployment of high-
Rights Impact risk AI, including a) intended use and affected groups, b) risks
Assessment of harm to rights, c) oversight and mitigation measures, and d)
complaint and redress mechanisms.
30.03 Definitional Apply proportionality tests to weigh competing rights, ensuring
Balancing that limitations are legitimate, necessary, and not excessive.
30.04 Defeasible Set up governance processes so that decisions about AI
Reasoning systems can be revisited if new evidence shows they are
harming people’s rights – for example, if bias is discovered after
deployment.
30.05 Rights Promotion Document explicitly which rights are strengthened or weakened
/ Demotion in each deployment scenario, with justifications.
Tracking
30.06 Stakeholder Consider involving equality bodies, data protection authorities,
Consultation and affected groups in risk assessments and oversight.
30.07 Transparency Notify individuals when AI systems are used in decision-
Obligations making, disclose purpose, scope, and type of decisions.
30.08 Oversight And Ensure suspension triggers if rights risks materialize.
Accountability

The Enterprise-Wide Agentic AI Controls Framework© November, 2025 is licensed to you 41


for single use only by Agentic Risks IP, a not-for-profit UK limited company (16619158).
Please note that copying and networking is prohibited. [Link]

You might also like