AI in control
Agentic AI in control
Agentic AI raises the stakes for every control in this section. A system that acts rather than only outputs closes the gap between a decision and its real-world effect faster than a person can review. Process knowledge can live in probabilistic layers, but the controls that bound what an agent is allowed to do must live in deterministic ones, and that split is what the three articles below work through in order. First the architecture: how an agent comes to know and act on your business process. Then the risk that architecture creates, assessed through the same harm-risk-control chain as any AI risk. Then the control environment itself: where the controls belong in that architecture, and how you prove afterward that they held.
How an AI agent knows your business process: the six building blocks
A language model knows nothing about your organization on its own. Everything an agent knows about your process enters through six building blocks, and each one is a design choice with consequences.
2. RiskAgentic AI risk assessment: from architecture decisions to control objectives
Architecture decisions are not risks by themselves. They become risks when they create the possibility of harm. This article turns the recorded design of an AI agent into risk scenarios and control objectives.
3. ControlsThe control environment for agentic AI: where controls belong and how you prove they work
An agent runs your process, so your controls have to move with it. This article covers where each control belongs, why prompt rules create false assurance, and how you test design and operating effectiveness for a system that is partly probabilistic.
This page covers the control side. For the governance condition itself, cross-cutting all seven pillars, see Agentic AI: what changes when the system acts, not just decides.