// Board governance · Agentic AI

How can a board govern agentic AI?

By governing the consequential decisions an agent is permitted to make—not merely approving the model, platform or use case.

A board should require every material agentic decision to have an explicit mandate, a bounded authority, a replayable evidence chain and an intervention point. Governance is real only when the institution can establish what the agent was authorised to do, what it actually did, and whether the difference was detected while action remained possible.

// 01

The shift the board must see

Traditional AI governance often begins with the system: its risk classification, testing, controls and responsible owner. Agentic AI changes the question because the system can plan, use tools and execute. The board therefore has to govern the decision as it travels from purpose to outcome.
The practical risk: every component can be approved while the joins between mandate, prompt, data, tools, permissions and execution remain unowned. The eventual action may be technically valid but institutionally unauthorised.

// 02

Four board requirements

01 · Mandate

State the purpose, obligations and prohibited outcomes the agent must preserve.

02 · Authority

Define which decisions it may make, which require escalation and which it may never execute.

03 · Evidence

Preserve the data, rules, tools, judgement and authority behind each consequential action.

04 · Intervention

Identify who can detect divergence, stop execution and correct what follows.

05 · Feedback

Return outcomes to someone with authority to alter the chain.

06 · Replay

Test whether a contested decision can be reconstructed end to end.

// 03

The board test

  1. Name one decision an agent can execute without prior human approval.
  2. Produce the written boundary of that authority.
  3. Replay one decision from mandate through execution and feedback.
  4. Identify the point at which a human could still intervene.

If the institution cannot complete all four, the board has approved a capability without demonstrating control over the decisions it produces.

// Questions people ask

Common questions

Does human-in-the-loop solve agentic AI governance?

Not by itself. A human who lacks time, evidence or practical authority to intervene is an approval step, not an effective control.

What should the board receive?

A decision-level view of mandate, authority, replayability, material drift and intervention—not another inventory of AI systems.

Who remains accountable?

The institution remains accountable for decisions made under authority it delegated, even when execution is automated.

// The practical test

Test one institutional decision

The ten-day Decision Drift Audit™ maps one material decision across all eight layers, assesses replayability and authority boundaries, and delivers one prioritised board finding.

Test one decision →Canonical definitions →Decision Integrity Chain™ →

Related questions

Further reading: The Irrecoverable Institution and The Fiduciary Gap in AI-Driven Financial Institutions.