Evidence note: UK duties depend on the activity, sector and law involved. This article translates current official guidance into operational design questions; it does not claim that one universal “AI agent law” exists.

Businesses are moving from AI that drafts or recommends to AI that can select tools, communicate, update records and trigger actions. The productivity opportunity is real. So is the change in responsibility.

An AI agent is not accountable for the business outcome. The organisation deploying it remains responsible for what the workflow permits and what happens when it fails.

Seven controls to define before an agent can act

1. Identity

Every production agent should be identifiable. Logs and approvals lose value if activity disappears into a generic automation account.

2. Bounded authority

State what the agent may read, create, alter, send, approve or spend. “Help with customer service” is not a permission model.

3. Least-privilege access

Give the workflow only the data and tools necessary for its defined task. Separate retrieval from alteration, and routine actions from high-impact ones.

4. Approval gates

Identify actions that require an informed person before execution. The reviewer must be able to challenge the recommendation rather than merely click approve.

5. Exception handling

Unknown, conflicting or high-risk cases need a safe route. An agent should not improvise simply because the happy path ended.

6. Monitoring and evidence

Retain the input, relevant context, tool calls, output, approval and resulting action at a level proportionate to risk and privacy.

7. Intervention and revocation

Operators need a tested way to pause, constrain or disable the agent and recover from an incorrect action.

Official UK direction is already practical

The Competition and Markets Authority’s 2026 guidance says businesses remain responsible when an AI agent used with consumers acts illegally. The UK Government’s Data and AI Ethics Framework calls for named oversight, challenge routes and human intervention in risky or high-impact situations. These are not abstract values: they translate into permissions, records, escalation and decision ownership.

Direct answer: what is AI agent governance?

AI agent governance is the operational system that defines an agent’s identity, access, permitted actions, approval thresholds, monitoring, exceptions, intervention route and accountable human owner. A policy document helps only when those controls are built into the workflow.

From automation idea to controlled implementation

SOS approaches business AI automation by mapping the work first: what repeats, what evidence matters, what can be automated, what must remain human and what happens when the system is uncertain. The result can be configured for the customer without pretending every process should be autonomous.

Sources

Translate governance principles into identity, permissions, evidence, intervention and revocation controls.

Use the AI agent governance framework ↗