Agent-based governance is not about compliance. It is the prerequisite for your agents to create value without exposing the organisation to unacceptable risks.
Managing my agent-based strategy
Certified Responsible Agentic
By 2026, the roll-out of AI agents had accelerated across the board: official and shadow, assisted and autonomous, decision-making and operational. But governance had not kept pace.
73 per cent of organisations are deploying AI agents without a formalised register. 82 per cent of agent-related incidents could have been prevented by integrated governance from the design stage. An operational framework is lacking.
Meanwhile, the regulatory framework has become stricter. The EU AI Act has imposed its full obligations on high-risk systems since August 2026, with fines of up to €40 million or 7 per cent of global turnover. ISO/IEC 42001 is becoming a selection criterion in tenders from major clients. And the competitive window to establish oneself as a certified organisation before the standard becomes widespread across the market is estimated at 12 to 18 months.
Some figures
73 per cent of organisations deploy AI agents without a formalised framework (Gartner, 2025)
-
82% of agent-related incidents could have been prevented through governance by design (McKinsey, 2026)
-
The cost of remedying an agent-related incident in production is five times higher than the cost of preventing it at the design stage
-
12–18 months: estimated competitive window before the commoditisation of ISO 42001 certification
Agent-based transformation transfers entire processes to autonomous systems. To succeed, it is necessary to distinguish between the governance of ‘objects’ (the agents) and the governance of ‘dynamics’ (what the agents actually do). Both are necessary. Neither is sufficient on its own.
Governance of AI agents (the static approach)
This approach treats the agent as an IT asset: who owns it, who designed it, what its lifecycle is, and what access rights it has been granted. It is an area managed by the IT department, Legal and Compliance. It falls under accountability matrices and standards such as ISO 42001.
Governance of agent-based AI (the dynamic approach)
This approach focuses on what the agent actually does: its decision-making loops, its cascading delegations, its interactions with other systems, and its unforeseen side effects. It is an operational risk issue, jointly managed by the business units, Risk & Compliance, and Security.
The regulatory framework
Gabriel Greenfield is itself in the process of obtaining dual certification to ISO 27001 and ISO 42001. We apply the requirements we recommend to our clients to our own organisation.
The EU AI Act, which came into force in August 2024, is rolling out its requirements in phases. From August 2026, the full requirements will apply to high-risk systems, which, by definition, include any system involved in decisions relating to credit, insurance, recruitment or essential services.
The requirements are specific: documented risk management, data governance, comprehensive technical documentation, automatic logging of decisions for at least six months, and effective human supervision with the ability to override decisions.
ISO/IEC 42001 Published in December 2023, ISO/IEC 42001 is the first certifiable international standard for an AI Management System. Its PDCA approach makes it a natural complement to ISO 27001, and certification under this standard is becoming a selection criterion in tenders issued by major corporations and public institutions.
The EU AI Act specifies what needs to be documented. ISO 42001 specifies how to do so in a systematic and auditable manner. For organisations in regulated sectors, both are essential and complementary; they are not interchangeable.
Our Certified Responsible Agentic offering
Our support is structured around the Meridian methodology
Our agentic governance offering is rolled out in three progressive stages. Each stage produces actionable deliverables. Each stage provides a solid foundation for the next.
Step 1
Competency Assessment
Before implementing governance, it is essential to understand what actually exists, including agents deployed outside official channels.
We carry out a comprehensive inventory of your agent systems in production (both official and shadow), an EU AI Act risk analysis for each system, a mapping of the data flows consumed and produced by each agent, and an assessment of your governance maturity against the D5 dimension of the GAME framework.
Deliverables: governance maturity report with GAME score, risk matrix by agent, and identification of high-risk systems requiring immediate action.
Step 2
Governance framework
We implement the live agent register as a central asset for your governance. Each agent is catalogued with its owner (Agent Owner), its purpose, the data it consumes, the tools it has access to, its EU AI Act classification, its performance metrics, and its escalation thresholds.
We implement usage policies and the agent charter, access controls and permissions by system, train your teams and appoint Agent Owners, and deploy your monitoring dashboard with real-time observability.
An agent without a designated Agent Owner cannot be deployed in production within the Meridian framework.
Deliverables: register of deployed agents, validated policies, active dashboard, trained teams.
Step 3
Certification & Excellence
We support you throughout the entire ISO 42001 process: gap analysis, remediation plan, mock audit, certification audit. We document and maintain compliance with the EU AI Act for each system.
We lead periodic governance reviews (monthly AI committee meetings, fortnightly Agent Owner reviews, half-yearly governance audits). And we work with you to build your in-house agent-based centre of excellence, ensuring that governance becomes an organisational capability rather than an external dependency.
Deliverables: A comprehensive Technical File for each high-risk system, ISO 42001 certification, and an internal governance playbook handed over to your teams.
Case studies

Driving transformation through expertise that combines strategy, analytics and AI.
Read a case study >

Enterprise Architecture & APIs on Ardoq and Azure to streamline integration platforms and manage over 500 interfaces.
Read a case study >
Discover our blog posts :
