7 min readAI Agents · Cybersecurity
No Rule Names Your AI Agents. You Still Answer for Them
By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

TL;DR: Almost no rule names AI agents yet, and that silence isn't permission. An examiner still asks whether you had control of the agent, not which rule you followed. Map every agent onto a control you already report on and name a human owner for each. Keep proof you didn't write by hand.
Last updated October 6, 2026. I rebuilt this piece from the ground up around the question regulated teams keep asking me: which box do the agents go in?
On the same day in July, two financial firms told me opposite things about the same question. One put its AI work under model risk management and treated it as a governed model. The other said its regulator had just revised model risk guidance and left generative and agentic AI outside the scope. Both calls were July 6, 2026. Both teams were smart. They read the same silence two different ways, and that's where most regulated businesses sit right now: nobody has written you a rule, and you still have to answer for what your agents do.
Which rules apply to AI agents in a regulated business right now?
Very few, and none were written with an agent in mind, so you're mostly borrowing. Model risk management, third-party risk, access control, and records retention were each built for something else, and each partly fits. An agent that reads customer records and takes an action touches all four at once, which is exactly why no single owner picks it up.
The old anchor is the Federal Reserve's SR 11-7, issued in 2011. It defines a model as something that turns inputs into estimates and tells banks to validate and govern them. An agent that calls tools and changes records isn't really that. It's closer to a worker with credentials. So the honest answer is that you're operating in the space between two rulebooks, one written for models and one written for people, and your agent is neither.
Why did one regulator scope AI out of model risk guidance?
Because model risk guidance covers models, and a generative system doesn't behave like one. A regional bank holding company told me on July 6, 2026 that its regulators had revised the guidance and left generative and agentic AI out of scope. I'm reporting what that team said on the call, not a published rule change, so check it against your own examiner. Their reasoning was practical: validating a model means testing whether output is accurate within known bounds, and that test doesn't work on a system whose output differs every time.
Here's what surprised them. Being scoped out didn't reduce their work. It moved it. Model risk had a validation team, a schedule, a named owner, and a report that already went to their examiner. Once AI sat outside that, nobody owned the reporting line. That's the real cost of being scoped out: you lose the machinery, not the duty.
Is regulatory silence the same as permission?
No. An examiner's question isn't "which rule did you follow." It's "show me you had control." That question has the same shape whether or not a rule names your agents. Can you see them? Can you stop one? Can you trace an action back to an agent and to the person who owns it? Can you show all of that after the fact, from a record you didn't write by hand?
Answer those and the missing rule is an inconvenience. Fail to answer them and the missing rule won't protect you, because nobody has ever been excused for unclear guidance. One piece of the proof chain does more work than the rest: every agent needs a named human owner, since an agent can't be held accountable and a team can't either. "The platform team" isn't a person, and we wrote out why in who owns your AI agent. The evidence stack behind the other questions is in the five questions your AI agent auditor will ask.
Why does your own environment disqualify most governance products?
Because the constraint comes before the evaluation, and buyers keep discovering it late. A defense supplier told me on August 4, 2026 that it runs in GCC High, the government community cloud for regulated US defense work, which breaks device management features that work fine everywhere else. A healthcare clearinghouse told me on May 29, 2026 that hosting had to sit at FedRAMP Moderate, and that one requirement removed most of the AI governance market before a single demo. Add CMMC for defense work and the EU AI Act for anything sold into Europe, and the pattern holds: nine of my client calls between March 30 and August 21, 2026 turned on a constraint like this. In most of them the constraint, not the threat model, decided what the team could buy.
Two things follow. Check your authorization boundary before you shortlist anything. And expect to build more yourself than a vendor roadmap suggests, because the product that fits your environment usually has the fewest AI features. The penalty side of the EU picture is in AI agent regulation is already here.
What should you do when no rule names your agents?
Attach each agent to a control you already report on. You already run systems that produce evidence on a schedule, each with an owner and a report that goes somewhere.
What the agent does | The existing control it belongs in |
Holds credentials and reads systems | Access review |
Changes code or configuration | Change management |
Runs on somebody else's model | Third-party risk |
Produces records a regulator may want | Records retention |
Do it in this order:
List the agents that touch regulated data or act on their own.
Not all of them. Start with the ones that would hurt.
Name the human who owns each one.
One name, not a team.
Add each agent to the closest existing control.
Access review is usually the right first home.
Write down what the agent may reach,
and make widening that list a reviewed change instead of a setting.
Keep an attributed record of what the agent did,
stored where you can't edit it.
None of that waits on a regulator, all of it produces the evidence an examiner asks for, and when a rule does arrive you'll be mapping it onto controls that already run. The NIST AI Risk Management Framework is a reasonable external scaffold: voluntary, not sufficient on its own, but it gives you language a risk committee recognizes when you're explaining why you acted before you were told to.
Frequently asked questions
Does the EU AI Act cover AI agents used inside a company?
It can, depending on what the agent does and where it's used. Regulation (EU) 2024/1689 sorts systems by risk and puts real obligations on high-risk uses, including internal ones. If you sell into Europe or employ people there, get a legal read on classification early, because the answer changes what you have to document.
Do we have to treat an AI agent as a model under model risk management?
That depends on your regulator and your own policy, and I've seen it settled both ways in the same week. The useful question isn't which box it goes in. It's whether the box you pick has a real owner and a report that goes somewhere. A wrong box with working machinery beats a right box with nobody in it.
What's the smallest thing we can do this quarter?
Name an owner for every agent that touches regulated data, and put those agents into your existing access review. That's a few weeks of work, and it answers the two questions an examiner opens with.
Will a vendor product solve this for us?
Not by itself. In a regulated environment, your authorization boundary cuts the candidate list before capability does. Assume you're assembling this from controls you already run, with a product filling one part.
Key takeaways
Almost no rule names AI agents yet, and the silence moves the obligation instead of removing it.
Examiners ask whether you had control, not which rule you followed. The missing rule is never the excuse.
Being scoped out of model risk costs you the machinery: the validation team, the schedule, the owner, the reporting line.
Your authorization boundary, whether FedRAMP Moderate, GCC High, CMMC, or the EU AI Act, eliminates most governance vendors before any demo.
Attach each agent to a control you already report on, starting with access review. Keep an attributed record you can't edit.
To see how your current controls map to the five framework elements, the free self assessment takes about ten minutes.
Rules for AI agents are coming, unevenly and by sector, and they'll mostly codify what careful teams already do. On July 6 two firms read the same silence in opposite ways, and only one was building the evidence either way. I'd rather be the one who guessed wrong about the box and right about the proof.