Info-Tech Sets Out AI Agent Governance Plan
Info-Tech AI agent governance plan sets out three phases for managing agent access, autonomy, oversight, and accountability.

Info-Tech Research Group has published a three-phase framework for organizations governing AI agents that can access systems, trigger workflows, and make decisions autonomously. Its Govern Enterprise AI Agents While Preserving Innovation blueprint focuses on agent identity, access, autonomy limits, and ongoing oversight. The guidance is aimed at CIOs, CISOs, and AI governance leaders. The framework is intended for organizations using agentic AI across enterprise systems while seeking clearer controls around risk and accountability.
Why Agents Need Different Controls
Info-Tech distinguishes AI agents from earlier AI models and traditional IT assets because agents can act across enterprise systems rather than only generate outputs. The firm’s model begins with identifying existing agents, their owners, their access, and their level of autonomy, then classifying risk and setting intervention points while agents operate.
“AI agents cannot be governed like traditional IT assets or earlier AI models because they do more than generate outputs; they act across systems. Many people will have multiple agents working for them, but AI agents cannot be governed the way we govern humans because they move quicker and lack emotions, conscience, and consequences.”
Five Governance Gaps
The research identifies five areas organizations need to address as agentic AI use expands: shadow AI created outside sanctioned tools, capability mismatch between autonomy and monitoring, runtime drift caused by changes to tools, prompts, and permissions, unmanaged access through overextended permissions or service accounts, and ambiguous ownership when an agent causes harm.
The framework is designed to move organizations from a one-time approval method to ongoing governance as agents operate, while enabling safe experimentation and giving leaders a view of exposure.
Three Phases For Oversight
Phase one calls for governance leaders to establish an agentic AI mandate, decision rights, and a small set of enforceable guardrails. Phase two maps the agent lifecycle, finds agents wherever they are created, classifies them by risk, and sets monitoring and intervention expectations.
In phase three, business owners, technical owners, AI governance teams, and enterprise risk leaders set an accountability model, define metrics, establish executive dashboard reporting, and carry out a phased rollout.
Tools For Governance Teams
The blueprint includes case studies, practical tools, and templates: an Agentic AI Governance Playbook, an Agentic AI Governance Charter Example, a State-of-AI-Agents Executive Dashboard, and an Agentic AI Governance Glossary. It is suited to organizations that want to manage agent identity, access, autonomy, and oversight as AI agents operate across their systems.
From an announcement by Info-Tech Research Group.


