Board Governance in the Agentic Era: What Risk Committees Need to Know

The SEC wants AI disclosure. DORA demands cyber accountability. Neither framework addresses autonomous AI systems.
Tim Williams — CEO and Cofounder — AstraSync AI
In December 2025, the U.S. Securities and Exchange Commission’s Investor Advisory Committee adopted recommendations urging public companies to disclose how their boards oversee AI. DORA and NIS2 have shifted cyber accountability into the boardroom across Europe.
Both developments signal that boards can no longer delegate technology risk to operational teams without oversight.
Neither framework addresses agentic AI: systems that plan and execute actions autonomously rather than responding to direct human instruction. This gap creates material risk for organisations deploying these systems.
Why Traditional Oversight Models Fail for Agentic AI
The SEC’s guidance encourages companies to define AI clearly, describe board oversight structures, and explain deployment and material impact. Barbara Cresti, writing on the SEC’s Investor Advisory Committee recommendations on LinkedIn, notes that companies are now expected to report AI use the same way as cybersecurity or compliance risks (https://www.linkedin.com/posts/barbaracresti_ai-aigovernance-boardroom-activity-7404773195205091331--oID).
DORA requires boards to own cyber resilience outcomes. As P. Raquel Bise observes in her LinkedIn article “Board-Level Cyber Accountability in the DORA Era”, cyber accountability has moved to the executive level (https://www.linkedin.com/pulse/board-level-cyber-accountability-dora-era-room-just-got-bise--a3gae/).
Both frameworks assume AI operates as a tool under human direction. Agentic AI operates differently.
When an AI agent decides which APIs to call, what information to gather, and which other agents to collaborate with, risk emerges from interactions rather than individual components. The behaviour of a multi-agent system is often unpredictable even to its developers, because it results from thousands of micro-decisions occurring faster than human oversight can track.
Enterprises are deploying AI agents for customer service, financial analysis, supply chain management, and software development. These agents can breach non-AI regulations without human intervention. An agent providing financial information might cross into solicitation territory. An agent handling customer data might make decisions that conflict with privacy obligations across jurisdictions.
The Accountability Gap
Current compliance approaches are, in the words of one CTO from our industry interviews, “largely ... log monitoring” and “100% manual and reactive rather than preventative.”
When an AI agent causes harm, regulators, customers, and board members will ask: who is responsible?
In most organisations today, there is no clear answer.
This problem predates agentic AI. The Linux Foundation’s Open Source Security Foundation (OpenSSF) maintains a working group dedicated to helping developers and users “understand and make decisions on the provenance of the code they maintain, produce and use.” Ken Thompson identified this problem in his 1984 Turing Award lecture “Reflections on Trusting Trust”: “You can’t trust code that you did not totally create yourself… Perhaps it is more important to trust the people who wrote the software.”
The XZ Utils backdoor (CVE-2024–3094) demonstrated this vulnerability. Valid signatures and HTTPS encryption functioned correctly, but software supply chain security failed when developer provenance was compromised. A compromised maintainer account allowed the backdoor to enter as an official change. No cryptographic check caught it.
If organisations struggle to verify who built their existing software, governing autonomous agents presents a greater challenge.
With agentic AI, behaviour emerges from interactions between models, tools, APIs, and other agents. Current regulatory regimes treat these components independently, leaving fundamental questions unanswered: How should composite agent behaviour be evaluated for risk classification? Who holds responsibility when harmful behaviour results from interactions across multiple vendors? How should third-party tools integrated into agent loops be audited?
The SEC’s disclosure recommendations do not address these questions. DORA’s operational resilience requirements assume organisations can map their digital dependencies. With agents that dynamically select their own toolsets and collaborators, that mapping changes continuously.
The Verification Gap
Consider workforce risk management. Employees typically undergo background verification before being granted access to systems, data, and authority to act on the company’s behalf. HR, legal, and compliance functions all participate in this process.
AI agents represent autonomous actors entering enterprise environments with significant privileges and the ability to interact with customers, partners, and critical systems.
What verification exists for these agents?
In most organisations: none. An agent gets deployed and granted API access. The developer who built it may be unknown. The training data that shaped its behaviour may be undocumented. The guardrails governing its actions may be poorly defined or absent.
If a human employee was hired without verification and subsequently committed fraud affecting the company, its partners, customers, and shareholders, accountability questions would follow immediately. Who approved the hire? What controls failed?
The same accountability questions apply to agents. Boards should be asking them before incidents occur.
Know Your Agent: A Framework for Oversight
For financial services organisations, this framing should be familiar. Oversight of Know Your Customer (KYC) and Anti-Money Laundering (AML) programs are board-level responsibilities. Regulators expect directors to understand the frameworks, ensure adequate resourcing, and bear accountability for failures.
Know Your Agent (KYA) requirements follow the same logic. If an AI agent executes transactions, handles customer data, or makes decisions with material impact, the board needs visibility into three areas:
- Know Your Developer (KYD): Who built this agent? What is their track record? What verification exists?
- Know Your Owner (KYO): Which entity owns this agent and bears liability for its actions?
- Know Your Agent (KYA): What is this agent authorised to do? What are its operational boundaries?
For financial services companies, adopting KYA programs extends existing compliance infrastructure. For retailers, manufacturers, healthcare providers, and professional services firms that have never operated KYC-style programs, implementation presents different challenges.
How will those organisations implement KYA? What capabilities do they need? Who will own the function?
These questions require answers before regulatory mandates arrive.
The Compliance Tooling Gap
The board’s primary operational resource for managing regulatory risk is typically the compliance team. They interpret requirements, implement controls, monitor adherence, and report upward.
Most compliance teams lack the tools required for agentic oversight.
Current compliance systems were designed for human behaviour and traditional software. They assume static policies applied to predictable actions. Agent behaviour is neither static nor predictable. An agent might operate within policy parameters for months, then encounter a situation where its response creates unexpected liability.
Compliance teams need: real-time monitoring of agent activity, automated detection of policy violations, and immutable audit trails demonstrating what happened and why. They need visibility into decisions made, not just data moved.
Without these capabilities, compliance teams cannot provide effective oversight. If compliance lacks visibility, the board lacks visibility.
A Framework for Board Oversight
Building on Bise’s one-page cyber briefing model, agent governance oversight should include the following elements. Monthly board reporting is necessary but not sufficient. Continuous monitoring between board meetings requires operational teams to have appropriate tools.
Monthly Agent Risk Briefing (One Page)
- Agent Inventory: How many AI agents operate in our environment? Which are internal versus third-party? What changed since last month?
- Top 3 Agent-Related Exposures: What are the greatest risks from agent behaviour? Customer harm? Data leakage? Regulatory breach? Reputational damage?
- Provenance Status: For highest-risk agents, can we demonstrate who built them (developer verification), who owns them (organisational accountability), and what they are authorised to do (operational boundaries)?
- Counterparty Access: Which counterparties did our agents request access to? How often was access granted? Where access was denied, what were the reasons?
- Behavioural Alerts: How many alerts were triggered by agents behaving in ways that created risk? This includes attempts to breach guardrails or access counterparties outside of established cadences and norms.
- Remediation Performance: What was the median time to repair or retire agents that were causing risk?
- Compliance Readiness: Does the compliance team have real-time visibility into agent activity? What gaps exist in monitoring capabilities?
- Unaddressed Risk: What agent-related risk is the organisation currently accepting without explicit board acknowledgment?
Note: AstraSync has deployed, or is actively building, solutions for these observability requirements.
Regulatory Direction
The regulatory trajectory is clear.
The EU AI Act establishes requirements for AI system transparency, risk assessment, and documentation applicable to many agentic applications. While enforcement timelines have shifted, the fundamental obligation remains: organisations deploying AI in high-stakes domains will need verifiable identity and compliance infrastructure.
Proxy advisors are evaluating AI governance alongside ESG and cyber. CalSTRS, Norges Bank Investment Management, and Allianz Global are treating AI governance as a core pillar of fiduciary risk.
In one year, the share of U.S. large-cap companies citing AI as a risk in their filings increased from 14% to 36%.
Existing disclosure frameworks assume visibility that most organisations do not have over their AI agents. Disclosure requires visibility.
Required Shift
If agent accountability is moving to the boardroom, leadership teams must abandon the assumption that technology risks can be fully delegated to technology teams.
Cybersecurity required this shift over the past decade. AI governance requires it now, on a compressed timeline.
Organisations that manage this transition effectively will treat agent governance as they treat financial health: a continuous, cross-functional responsibility requiring visibility, accountability, and appropriate tooling.
A board that cannot explain how it governs systems making decisions on the company’s behalf has a governance gap that regulators, auditors, and shareholders will eventually identify.
Further reading on AstraSync
- What is Know Your Agent (KYA)?
- PDLSS Permission Boundaries
- Verify before transact: the trust pattern for agent commerce
This essay first appeared on Medium on 30 December 2025.

