How organizations secure AI systems and govern autonomous AI agents, including the AI Agent Governance Hub.
TC260's third edition adds a dedicated agentic AI risk class built around identity, tools, memory and planning. It is not binding law — but it is the third major jurisdiction this year to describe the agent in the same four terms.
California signed two laws creating a state registry for AI auditors and a certification framework for independent verification organisations, then issued an executive order nine days later to accelerate both. The assurance layer is becoming regulated infrastructure.
Europe's first quality management standard for the AI Act finished its approval process this summer, and EN ISO/IEC 42001:2026 arrived in March. Neither one currently gives a provider legal cover — and understanding why changes what you should be building.
Cyber insurers have moved faster than regulators on AI governance: generative-AI exclusions, conditional AI riders, and control questionnaires that put a price on your documentation. The four artefacts underwriters now ask for are the same four ISO/IEC 42001 and the EU AI Act already require.
On 19 August NIST released the initial public draft of SP 1353, a quick-start guide of AI prompts for producing CSF 2.0 governance reviews and state profiles. The caveat NIST attaches to it is the whole governance question.
The Digital Omnibus pushed the AI Act high-risk deadlines back by more than a year, but Article 50 transparency duties and Commission enforcement over general-purpose models became live on 2 August 2026. Knowing which is which is now a governance problem.
An AI agent that can act on its own, call tools, and make decisions is not just software. Governing it like a regular application misses the risk that actually matters.
Traditional software executes instructions. Chatbots mostly respond. AI agents act, on real systems, under someone's authority. That shift is a governance problem before it is a technical one.