Blog · Architecture

The AI Agent Governance Gap: Why Existing Tools Are Not Enough

Eleye Abdi·3 July 2026·8 min read

AI agents are qualitatively different from the AI models that governance frameworks were designed to address. A language model that answers questions is a relatively contained system. It receives inputs, generates outputs, and does not independently act in the world. An AI agent is different: it perceives its environment, makes decisions, takes actions, and operates continuously without requiring a human to initiate each step.

Most enterprise AI governance frameworks were designed with the model paradigm in mind: model risk management, output validation, fairness assessment. These are important disciplines. They do not address the governance challenges that AI agents create. The gap between what existing frameworks cover and what AI agents require is the most significant unaddressed risk in enterprise AI governance in 2026.

AI agent governance is not model risk management applied to agents. Agents act. They have OAuth grants. They operate across platforms. They create cross-platform risk patterns. Existing MRM frameworks do not see this.

What Makes AI Agents Governance-Different

Agents act, models respond

A language model responds to a prompt. An AI agent acts on the environment: it reads emails, updates CRM records, sends external communications, queries databases, creates calendar events, triggers workflows. The governance implication is that agents create consequences that models do not, and those consequences are often difficult to attribute or reverse.

Model risk management focuses on output quality: is the response accurate, fair, unbiased? Agent governance focuses on action appropriateness: was the agent authorised to take this action, with this scope, on this data, with this consequence? These are different governance questions requiring different evidence frameworks.

Agents operate through identity grants, models do not

AI agents typically operate with OAuth grants: authorisations allowing them to act on behalf of users or as service identities. These grants define what the agent can access and do. They are created through multiple channels (IT-approved procurement, user-level authorisation, low-code platforms, embedded SaaS features) and are distributed across multiple platforms. No single administrative surface shows all of them.

Agents create cross-platform patterns, models do not

An AI agent that reads data on Google Workspace and acts on Microsoft 365 creates a cross-platform pattern that neither platform's admin console sees as a combined event. The governance risk is not the action on Google or Microsoft individually. It is the combination. Model risk management does not see this. GRC tools do not see this. Cross-platform pattern detection is the governance blind spot that agent-specific tooling is designed to close.

Further reading: Why Traditional GRC Tools Cannot Govern AI covers this in depth.

The Four Gaps in Existing Governance Frameworks

Gap 1: Model risk management does not cover agent actions

Model Risk Management governs the development, validation, and monitoring of AI models. It addresses model risk: the risk that a model performs worse than expected, introduces bias, or produces inaccurate outputs. It does not address agent risk: the risk that an agent takes actions it was not intended to take, with scope it was not intended to have. An agent using a well-performing model but operating with excessive OAuth grants is an agent risk, not a model risk. Existing MRM frameworks do not see it.

Gap 2: IT security tools do not enumerate agent OAuth grants comprehensively

Security tools (CASB, DLP, endpoint protection, SIEM) monitor security events and policy violations. They do not enumerate the population of AI agents with active OAuth grants across all major enterprise platforms. A CASB monitoring Microsoft 365 traffic does not see the Google Workspace Apps Script automation authorised by a user six months ago. The OAuth grant is a configuration state predating security monitoring, not a security event.

Gap 3: GRC tools govern what is in the register, not what is actually running

GRC tools depend on an inventory that someone else compiled. They cannot discover AI agents. They govern the registered agents, which in most organisations represents a subset of the actual population. The unregistered agents are invisible to GRC governance.

Gap 4: Compliance programmes address policies, not agent-level evidence

AI compliance programmes at most regulated firms are policy programmes: acceptable use policies, risk assessment frameworks, governance committees. Necessary, but they do not produce the agent-level evidence that Article 26 and the ICO framework require: a signed, current inventory of what agents are operating, how they are classified, what cross-platform patterns they exhibit, and what oversight is in place for each.

What Agent-Specific Governance Requires

  • Agent discovery through OAuth grant enumeration: programmatic querying of workspace admin APIs across all major platforms, including agents not formally approved
  • Cross-platform pattern detection: stitching together what agents are doing across platforms to identify compound risk patterns not visible within any single platform
  • Agent-level signed evidence: governance artefacts covering the agent estate as a whole, signed for regulatory examination

This is what AETHER Pulse provides. Designed around agent governance, not adapted from model risk management or IT security tooling. Discovery across seven platforms through admin API queries. Cross-platform detection of eight compound patterns. Signed evidence packs covering the agent estate at the level of detail Article 26 and FCA supervision require.

Frequently Asked Questions

Is AI agent governance the same as agentic AI safety?

No. Agentic AI safety addresses the risk that AI agents pursue goals in ways that are unsafe or misaligned with human values: a research problem at the frontier of AI development. AI agent governance addresses the enterprise risk that AI agents are operating without appropriate authorisation, oversight, and evidence: a practical compliance and risk management problem regulated firms need to address now.

What is the minimum viable AI agent governance programme?

Discovery, classification, and evidence, in that order. You cannot classify what you have not discovered, and you cannot evidence what you have not classified. The minimum viable programme runs discovery across all major platforms, classifies each agent by risk level, and generates signed evidence packs at monthly cadences.

Close the AI Agent Governance Gap →

Working on Article 26 readiness, deployer-side governance evidence, or AI agent risk at a regulated firm? We'd value 15 minutes of your perspective.

Start a conversation