The distinction that matters
Three terms get used interchangeably and mean different things. Getting them apart is the first step, because they call for different engineering.
| Concern | Question | Operates |
|---|---|---|
| AI safety | Does the model behave as intended? | During training and evaluation |
| Observability | What did the system do? | After execution |
| Governance | Is this action permitted, and who says so? | Before execution |
The reason this matters is irreversibility. An invoice accepted into a national e-invoicing system receives an identifier and stays there — it can be corrected, never deleted. A payment that has cleared is a recovery exercise. A rejected application that reached the applicant is a complaint. Where the action cannot be undone, observability tells you what it will cost you. Only control before execution changes the outcome.
The five-layer model
A useful way to structure the work. Each layer answers a different question and fails differently.
- Identity — who or what is acting? Not the service account, but the specific process, agent instance or human behind it.
- Permission — what is this identity allowed to do? Scoped by action type, value, counterparty and data classification, not inherited wholesale from the account the integration was set up under.
- Policy — given this action, these arguments and this context, is it permitted, permitted-with-approval, or refused?
- Approval — where a human decision is required, who makes it, on what information, and within what time.
- Evidence — a tamper-evident record of all of the above, retained on the compliance clock and reconstructable years later.
Most deployed systems have layer 1 partially and layer 5 in the form of application logs. Layers 2 to 4 are where the actual governance lives, and they are usually the ones nobody built.
Why do AI agents break existing controls?
Three properties of agentic systems defeat controls designed for deterministic automation.
The action was never scoped as a decision
A model that outputs a credit score was built to make a decision and was governed as one. An agent asked to "resolve outstanding queries" may close accounts, issue refunds or decline applications as steps toward that goal. Nobody classified those as decisions, so nobody attached controls to them — but the law does not care what the workflow was called.
Permissions are inherited, not designed
An integration granted write access to a finance system holds it for a €200 transaction and a €200,000 one, for a five-year customer and one created this morning. The boundary was set by whatever account the integration was configured under. That is a boundary nobody chose, and therefore one nobody approved.
Behaviour is not reproducible
A deterministic process can be audited by re-running the same code on the same inputs. An agent cannot: the same prompt on the same model can produce a different result, and the model may have been replaced since. Unless you captured the model and policy version at the time, you cannot even establish whether the behaviour was correct then.
Which regulations apply to AI agents?
No regulation anywhere names AI agents. The obligations arrive through regimes that already governed whatever the agent touches — which means they apply now, not when an AI act lands.
| Regime | What it demands | Since |
|---|---|---|
| UK — UK GDPR Arts 22A–22D | "Meaningful human involvement" decides whether the regime engages; access to logic and a right to contest | 5 Feb 2026 |
| Switzerland — DSG Art. 21 | Information duty and a right to human review of automated individual decisions | 1 Sep 2023 |
| Denmark — NIS 2-loven § 7 | Management body must approve security measures personally and undergo training | 1 Jul 2025 |
| Germany — BSIG § 38 | Management must implement and supervise risk-management measures; liability under company law | 6 Dec 2025 |
| California — CPPA ADMT rules | Pre-use notice, opt-out, access to the logic, right to appeal | ADMT duties 1 Jan 2027 |
| EU — AI Act, as amended by Reg. (EU) 2026/1744 | High-risk obligations deferred to 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I); transparency from 2 Aug 2026 | In force 27 Jul 2026 |
Two observations worth carrying. First, the deferral of the EU high-risk deadlines removed a compliance driver many roadmaps were built on — sixteen months, in the Annex III case. Second, none of the others moved. The obligations that bite soonest for most enterprises are data protection and cyber, not AI law.
The cluster
How to scope AI agent permissions
Why inherited permissions are the default failure, and how to bound an agent by action type, value, counterparty and data class.
Approving AI agent actions before execution
Setting thresholds that catch real risk without creating a queue people rubber-stamp. Three response levels and what to record.
How to build an audit trail for AI agents
What to capture, why application logs do not qualify, and the two fields agents need that deterministic processes do not.
Preventing unauthorised AI agent actions
Scope creep, prompt injection reaching a tool call, and the controls that stop an action rather than reporting it.
Human-in-the-loop vs autonomous agents
When human involvement is meaningful in law, when it is decorative, and how to tell the difference from the outside.
MCP governance: managing MCP servers in an organisation
Inventory, trust boundaries, tool permissions and what the protocol leaves to you.
MCP security after the 2026-07-28 specification
What the release changed, why MRTR does not close the governance gap, and why CVE feeds are an unreliable instrument here.
FinOps for AI agents: cost per workflow and per action
Why agent cost distributions are wildly uneven, and what to measure so the outliers are visible.
Where should you start with AI agent governance?
If you have agents in production and no governance layer, the fastest diagnostic is not an audit. It is one question, asked of one real action:
Pick an action an agent took three months ago. Establish what triggered it, what data it acted on, which model and policy version were in force, whether anyone approved it, and what they were shown.
If that takes more than a few minutes, or needs a developer, you have observability and not evidence. That gap is the work — and it is the same gap whether the regulator asking is the ICO, the EDÖB, Styrelsen for Samfundssikkerhed or FINRA.
In practice
BarzelVault implements layers 2 to 5 as a layer agents pass through and cannot bypass: pre-execution authorization with immutable action hashing, deterministic risk scoring, policy-as-code, approval with expiry and escalation, credential isolation, atomic spend and action limits, and signed audit receipts. Barzel Central Gateway federates and routes the tool calls themselves; Barzel FinOps Atlas attributes cost to outcomes; BarzelOps runs governed cross-system workflows on top.
By market
- United Kingdom — automated decision-making after the DUAA
- Switzerland — Art. 21 DSG and FINMA expectations
- Denmark — NIS 2-loven and management liability
- United States — the state ADMT patchwork
- Poland — governing automated KSeF invoicing
This guide is for information and does not constitute legal advice.
In practice
Permission before the action. Evidence after it.
The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.
430 days leftEU AI Act high-risk obligations (Annex III) apply from 2 December 2027
BarzelVault
The AI action firewall: decide what an agent may do before it does it.
- Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
- Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
- Credential isolation, spend and action limits, and an emergency kill switch.
Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize
Barzel Central Gateway
The AI governance control plane: one inventory and one policy layer across every MCP server and agent.
- Registers and synchronises every tool; enforces identity, policy, region, cost and health per tool.
- Identity mapping through OIDC, Entra ID, Okta, SAML and SPIFFE, with credential brokerage.
- Trace and SIEM export (W3C trace context, OTLP) for the security team and the regulator.
Free tier: 1,000 calls a monthPaid plans from $10 a monthLive on MCPize
Barzel FinOps Atlas
Intelligent financial operations for AI agents and automation.
- Cost per action, workflow and business outcome, allocated as it happens.
- Spend limits and anomaly detection before the bill, not after.
- Financial evidence tracing and close-readiness for SOX, SOC 2 and external audit.
Free tier: 500 calls a monthPaid plans from $29 a monthLive on MCPize
Enterprise: written quote by email within two business days. No sales call.
Markets in English
In local languages
- Polska
- Deutschland
- France
- Schweiz / Suisse
- United Kingdom
- United States
- Danmark
- Belgique / België
- Norge
- Slovensko
- Eesti
- Kenya