A chatbot answers. An agent acts. Once a system can send an email, query a database, or call another service, the governance question stops being about the model's output and becomes about the permissions it holds.
What the guidance recommends
- Grant the minimum access the agent needs, and no more.
- Scrutinise plugins and connected tools as third-party suppliers.
- Set retention limits on what the agent stores and logs.
- Assess continuously, not once at deployment.
- Keep a human in the loop for consequential actions.
- Assign named governance responsibility.
What this means for you
Most organisations have a generative AI policy by now. Very few have an agent register: which agents exist, what tools they can call, what data they can reach, and who approved each one. That register is what the guidance is pointing at.
Where to start
Add an agent column to the AI inventory you already keep — autonomy level, tools, data scope, owner, and last review date. It is an afternoon of work and it answers the question before it is asked.