The Question
Enterprise organizations have invested heavily in AI agent security controls: access management, prompt injection defenses, output filtering, and network segmentation. These controls address the external threat model — preventing unauthorized actors from manipulating agents or exfiltrating data through them. But security controls do not answer a different and equally important set of questions: What is this agent authorized to do? Who is accountable when it makes a consequential decision? How does the organization verify that agents are operating within their intended scope over time? What is the audit record that satisfies regulatory review?
These are governance questions, and most enterprise agent programs cannot answer them. Security and governance are related but distinct disciplines. Security protects the agent from external threats. Governance ensures the agent operates within the organization's intended boundaries, with accountability for the outcomes it produces, and with the audit record that enables oversight. An agent that has passed a full security review but has no authority scope policy, no accountability assignment, and no audit log is secure against external attack but ungoverned — and ungoverned AI agents are a compliance and operational risk.
The organizations learning this lesson in 2025 and 2026 are the ones that deployed agents quickly, discovered a compliance gap or an incident that could not be reconstructed from available logs, and are now building the governance framework retrospectively. Building it prospectively — before the agents go to production — is substantially easier.
Agent governance is not agent security — security controls protect agents from external threats, while governance controls ensure agents operate within the organization's intended scope, with accountability for the outcomes they produce.
Why This Matters Now
The EU AI Act entered its compliance enforcement phase in August 2025 for high-risk AI system categories. Several enterprise agent use cases fall into the high-risk classification: agents used in employment decisions (workflow routing, performance monitoring), agents used in credit or financial decisions, and agents used in critical infrastructure operations. Organizations in these categories are required to demonstrate human oversight mechanisms, complete audit logs, and documented accountability assignments — all governance requirements, not security requirements.
In the United States, the NIST AI Risk Management Framework (AI RMF 1.0) has been adopted as the baseline for federal contractor AI governance requirements, and several state-level AI governance bills — including Colorado's AI Act and Illinois's AI Video Interview Act — have established requirements that effectively mandate governance frameworks for AI systems making consequential decisions.
On the operational side, the scale of enterprise agent deployment in 2025 created governance problems that were not anticipated at the pilot stage. Microsoft's 2025 Work Trend Index found that 82% of enterprise leaders reported concern about their ability to audit AI agent decisions and actions — a figure that reflects the gap between deployment volume and governance maturity. Gartner's 2025 AI governance survey found that only 22% of organizations had a formal AI agent governance policy in place, despite 68% having deployed production agents.
The Zenity platform's 2026 State of AI Security report documented specific governance failures in enterprise environments: 41% of surveyed organizations had deployed agents whose authority scope was not formally documented, and 55% could not produce a complete audit log of agent actions for a specified 30-day period. These are not security failures — the agents passed security review. They are governance failures.
What the CURVE™ Data Shows
The 2026 Stackcurve AI Enterprise Agent Platform CURVE™ Report evaluated governance support — policy tooling, audit capabilities, and accountability mechanisms — across the enterprise agent platform market. The assessment covered IBM watsonx Orchestrate, ServiceNow Now Assist, Microsoft Copilot Studio, Salesforce Agentforce, Zenity, Workato, Google Agentspace, AWS Bedrock Agents, and UiPath Autopilot.
IBM watsonx Orchestrate leads on governance tooling, with integrated policy management, audit logging to SIEM systems, and a documented accountability framework in the enterprise deployment guide. ServiceNow provides strong audit logging within the Now Platform, with governance workflow integration through its GRC module. Salesforce Agentforce's Data Cloud integration enables detailed action logging, but the governance policy layer requires custom configuration.
Zenity is the purpose-built governance platform for enterprise agents — specifically designed for the low-code and no-code agent sprawl problem, where business users deploy Power Automate, Copilot Studio, and similar agents without IT oversight. Zenity provides automated agent discovery, risk scoring, policy enforcement, and audit logging across heterogeneous agent environments. It is the only platform in the evaluation that directly addresses the governance gap for agents deployed outside IT-controlled channels.
Microsoft Copilot Studio added a governance policy layer in its Q4 2025 update, including sensitivity label enforcement and an admin center with agent activity reporting. AWS Bedrock Agents and Google Agentspace remain governance-sparse, with audit log access through CloudTrail and Cloud Audit Logs respectively but no native policy framework.
The full vendor rankings are in the 2026 Stackcurve AI Enterprise Agent Platform CURVE™ Report — free to download.
The Gap Most Buyers Miss
Most enterprise agent programs implement security controls and assume governance is covered. It is not. Governance adds four capabilities that security controls do not provide.
Authority Scope Policy
Every deployed agent should have a documented authority scope: a formal statement of what actions the agent is permitted to take autonomously, what actions require human approval before execution, and what actions are never permitted regardless of instruction. Authority scope is distinct from technical permissions — an agent may have the technical permission to send email but an authority scope that restricts autonomous email sending to internal recipients only.
Authority scope should be defined for each deployed agent, reviewed and signed off before production, and reviewed again before any capability expansion. Without it, the answer to "what is this agent authorized to do?" is "whatever it can technically do," which is not a governance answer — it is an absence of governance.
Acceptable Use Policy for Agent-Generated Outputs
Not all agent outputs should be treated equally. Some outputs are appropriate for direct use in business processes without human review: ticket routing decisions, data classification labels, scheduling suggestions. Others require human review before use: customer-facing communications, financial decisions, contract modifications, compliance determinations. An acceptable use policy for agent outputs defines these categories explicitly, with the review requirement mapped to the output type and the business process it feeds.
This policy prevents the common failure mode where an agent output that was designed to inform a human decision gets treated as a final decision because no one specified the review requirement at deployment time.
Data Access Policy
The enterprise data classification framework — typically defining confidential, restricted, internal, and public data categories — must be extended to govern agent data access. Which classification levels can each agent access? Under what conditions? With what logging requirements? For RAG-based agents, which document collections can be retrieved for which user populations? The data access policy for agents should be reviewed by the data governance team, not just the security team, because it involves questions of data appropriateness — not just data security.
Incident and Escalation Policy
What constitutes an AI agent incident? The definition matters because it determines when the incident response process is triggered and what the response requirements are. An agent that routes 5% of customer contacts incorrectly is operating within its normal error rate. An agent that sends unauthorized external emails has had an incident. An agent whose task completion rate drops 30% in 24 hours may be experiencing a systematic failure. The incident and escalation policy defines these thresholds, the escalation path for each incident category, and the response requirements including notification timelines and remediation documentation.
The Audit Trail Requirements
Every agent action that affects enterprise data or communicates with external parties should produce an immutable audit record. The minimum audit record for a consequential agent action: agent identity and version, action type, inputs provided to the agent, outputs produced, timestamp, data sources accessed, tools invoked, and — where human-in-loop was triggered — the identity of the approving human and the approval timestamp.
The audit trail must be immutable (not modifiable by the agent or by the agent platform administrators), retained for a period that satisfies regulatory requirements for the relevant industry (typically 3–7 years for financial services, healthcare, and government), and accessible for export to legal hold or regulatory review on demand. An audit log that exists but cannot be exported for regulatory review in a usable format has limited compliance value.
Questions Your Buying Team Should Be Asking
1. Does the platform provide a native policy framework for defining agent authority scope, or does authority scope governance need to be implemented externally?
A native policy framework means the platform enforces the authority scope at runtime — the agent cannot exceed its documented permissions regardless of instruction. An external governance framework means the policy is documented but not enforced at the platform level, relying on agent design to stay within scope. Native enforcement is significantly more robust. Ask the vendor to demonstrate how an authority scope policy is configured and how it is enforced at runtime.
2. What does the platform's audit log capture, what is its retention period, and is it exportable for regulatory review?
A governance-ready audit log captures agent identity, action type, data sources accessed, tool calls made, inputs, outputs, and timestamps — for every consequential action. Ask for the specific list of fields captured, the default retention period, and the export format. Ask whether the audit log is stored separately from the platform's operational logs and whether it is write-protected after creation.
3. How does the platform support discovery and governance of agents deployed by business users outside IT channels?
Low-code and no-code platforms — Power Automate, Copilot Studio, Zapier — enable business users to deploy agents without IT involvement. These agents are typically outside the organization's governance framework. Ask how the vendor's platform provides visibility into and governance enforcement for agents deployed through these channels. If the answer is "our platform" and your environment includes Microsoft Power Platform, you likely have ungoverned agents already deployed.
4. Does the platform integrate with your existing GRC or IRM platform for agent risk management?
Governance is most effective when agent risk management is integrated into the organization's existing governance, risk, and compliance workflow — not maintained as a separate AI-specific process. Ask whether the platform integrates with ServiceNow GRC, Archer, or equivalent platforms to surface agent risk items in the existing risk management workflow.
5. How does the platform handle accountability assignment — specifically, who is the accountable owner for each deployed agent, and how is that ownership tracked and enforced?
Accountability requires a named human who is responsible for each deployed agent's performance and compliance. Ask the platform vendor how ownership is assigned and tracked at the agent level, and how the platform notifies the accountable owner when the agent has an incident or when its governance policy is modified.
The Stackcurve Take
The enterprise organizations that build agent governance frameworks proactively — before their first production agent, or in the early stages of their deployment program — have a structural advantage over those that build it retrospectively. Governance built proactively is clean: every agent has a policy, every policy has an owner, every consequential action has an audit record. Governance built retrospectively requires auditing every deployed agent to reconstruct what it was doing, what access it had, and who was accountable for it. That reconstruction is expensive and frequently incomplete.
The four-component governance framework — authority scope policy, acceptable use policy for outputs, data access policy, and incident and escalation policy — is not complex. It does not require a large governance team to implement. It requires that someone owns the framework, that each agent deployment includes policy creation and sign-off, and that the audit trail is configured before the agent goes to production. Those are process requirements, not resource requirements.
Zenity has built the most purpose-built governance tooling for enterprise agent environments, particularly for the low-code sprawl problem. IBM watsonx Orchestrate provides the strongest governance integration in an enterprise agent platform. Both are worth evaluating for organizations with governance requirements that their current platform does not address.
The 2026 Stackcurve AI Enterprise Agent Platform CURVE™ Report covers agent governance tooling, audit capabilities, and policy enforcement across the enterprise agent platform market. Download it free →
Stackcurve Advisory Briefs are independent research. No vendor pays for placement, tier assignment, or editorial influence. The CURVE™ methodology is disclosed in full at stackcurve.net/research/methodology.