5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

AI governance

AI agent governance: control before execution, evidence after

When software and AI agents are allowed to take financially or legally consequential actions, organisations need three things: control before execution, evidence after execution, and visibility into the cost of every action. Most AI governance material addresses model behaviour — bias, hallucination, alignment. That is a different problem. This guide is about the moment an autonomous system is about to do something: file a tax invoice, move money, change a record, decline an application. At that moment the question is not whether the model is good. It is whether the action is permitted, who authorised it, and what will survive to prove it.

How Barzel applies here Start free with BarzelVault

The distinction that matters

Three terms get used interchangeably and mean different things. Getting them apart is the first step, because they call for different engineering.

ConcernQuestionOperates
AI safetyDoes the model behave as intended?During training and evaluation
ObservabilityWhat did the system do?After execution
GovernanceIs this action permitted, and who says so?Before execution

The reason this matters is irreversibility. An invoice accepted into a national e-invoicing system receives an identifier and stays there — it can be corrected, never deleted. A payment that has cleared is a recovery exercise. A rejected application that reached the applicant is a complaint. Where the action cannot be undone, observability tells you what it will cost you. Only control before execution changes the outcome.

The five-layer model

A useful way to structure the work. Each layer answers a different question and fails differently.

  1. Identity — who or what is acting? Not the service account, but the specific process, agent instance or human behind it.
  2. Permission — what is this identity allowed to do? Scoped by action type, value, counterparty and data classification, not inherited wholesale from the account the integration was set up under.
  3. Policy — given this action, these arguments and this context, is it permitted, permitted-with-approval, or refused?
  4. Approval — where a human decision is required, who makes it, on what information, and within what time.
  5. Evidence — a tamper-evident record of all of the above, retained on the compliance clock and reconstructable years later.

Most deployed systems have layer 1 partially and layer 5 in the form of application logs. Layers 2 to 4 are where the actual governance lives, and they are usually the ones nobody built.

Why do AI agents break existing controls?

Three properties of agentic systems defeat controls designed for deterministic automation.

The action was never scoped as a decision

A model that outputs a credit score was built to make a decision and was governed as one. An agent asked to "resolve outstanding queries" may close accounts, issue refunds or decline applications as steps toward that goal. Nobody classified those as decisions, so nobody attached controls to them — but the law does not care what the workflow was called.

Permissions are inherited, not designed

An integration granted write access to a finance system holds it for a €200 transaction and a €200,000 one, for a five-year customer and one created this morning. The boundary was set by whatever account the integration was configured under. That is a boundary nobody chose, and therefore one nobody approved.

Behaviour is not reproducible

A deterministic process can be audited by re-running the same code on the same inputs. An agent cannot: the same prompt on the same model can produce a different result, and the model may have been replaced since. Unless you captured the model and policy version at the time, you cannot even establish whether the behaviour was correct then.

Which regulations apply to AI agents?

No regulation anywhere names AI agents. The obligations arrive through regimes that already governed whatever the agent touches — which means they apply now, not when an AI act lands.

RegimeWhat it demandsSince
UK — UK GDPR Arts 22A–22D "Meaningful human involvement" decides whether the regime engages; access to logic and a right to contest 5 Feb 2026
Switzerland — DSG Art. 21 Information duty and a right to human review of automated individual decisions 1 Sep 2023
Denmark — NIS 2-loven § 7 Management body must approve security measures personally and undergo training 1 Jul 2025
Germany — BSIG § 38 Management must implement and supervise risk-management measures; liability under company law 6 Dec 2025
California — CPPA ADMT rules Pre-use notice, opt-out, access to the logic, right to appeal ADMT duties 1 Jan 2027
EU — AI Act, as amended by Reg. (EU) 2026/1744 High-risk obligations deferred to 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I); transparency from 2 Aug 2026 In force 27 Jul 2026

Two observations worth carrying. First, the deferral of the EU high-risk deadlines removed a compliance driver many roadmaps were built on — sixteen months, in the Annex III case. Second, none of the others moved. The obligations that bite soonest for most enterprises are data protection and cyber, not AI law.

The cluster

How to scope AI agent permissions

Why inherited permissions are the default failure, and how to bound an agent by action type, value, counterparty and data class.

Approving AI agent actions before execution

Setting thresholds that catch real risk without creating a queue people rubber-stamp. Three response levels and what to record.

How to build an audit trail for AI agents

What to capture, why application logs do not qualify, and the two fields agents need that deterministic processes do not.

Preventing unauthorised AI agent actions

Scope creep, prompt injection reaching a tool call, and the controls that stop an action rather than reporting it.

Human-in-the-loop vs autonomous agents

When human involvement is meaningful in law, when it is decorative, and how to tell the difference from the outside.

MCP governance: managing MCP servers in an organisation

Inventory, trust boundaries, tool permissions and what the protocol leaves to you.

MCP security after the 2026-07-28 specification

What the release changed, why MRTR does not close the governance gap, and why CVE feeds are an unreliable instrument here.

FinOps for AI agents: cost per workflow and per action

Why agent cost distributions are wildly uneven, and what to measure so the outliers are visible.

Where should you start with AI agent governance?

If you have agents in production and no governance layer, the fastest diagnostic is not an audit. It is one question, asked of one real action:

Pick an action an agent took three months ago. Establish what triggered it, what data it acted on, which model and policy version were in force, whether anyone approved it, and what they were shown.

If that takes more than a few minutes, or needs a developer, you have observability and not evidence. That gap is the work — and it is the same gap whether the regulator asking is the ICO, the EDÖB, Styrelsen for Samfundssikkerhed or FINRA.

In practice

BarzelVault implements layers 2 to 5 as a layer agents pass through and cannot bypass: pre-execution authorization with immutable action hashing, deterministic risk scoring, policy-as-code, approval with expiry and escalation, credential isolation, atomic spend and action limits, and signed audit receipts. Barzel Central Gateway federates and routes the tool calls themselves; Barzel FinOps Atlas attributes cost to outcomes; BarzelOps runs governed cross-system workflows on top.

How Barzel applies here


By market

This guide is for information and does not constitute legal advice.

In practice

Permission before the action. Evidence after it.

The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.

430 days leftEU AI Act high-risk obligations (Annex III) apply from 2 December 2027

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Barzel Central Gateway

The AI governance control plane: one inventory and one policy layer across every MCP server and agent.

  • Registers and synchronises every tool; enforces identity, policy, region, cost and health per tool.
  • Identity mapping through OIDC, Entra ID, Okta, SAML and SPIFFE, with credential brokerage.
  • Trace and SIEM export (W3C trace context, OTLP) for the security team and the regulator.

Free tier: 1,000 calls a monthPaid plans from $10 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Barzel FinOps Atlas

Intelligent financial operations for AI agents and automation.

  • Cost per action, workflow and business outcome, allocated as it happens.
  • Spend limits and anomaly detection before the bill, not after.
  • Financial evidence tracing and close-readiness for SOX, SOC 2 and external audit.

Free tier: 500 calls a monthPaid plans from $29 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.

Markets in English

In local languages

Cross-market topics