7 min readAI Agents · Zero Trust
The Three Layers of AI Agent Governance, Explained
By Michelle Savage, Experience Design Director, PayPal

TL;DR: Governing AI agents takes three layers that work together. A framework defines what to govern. A runtime enforces it before every action, and protocols let agents prove who they are to each other. No single layer solves it alone, and the enforcement cost is a rounding error next to the model call.
Last updated October 5, 2026. This piece was rebuilt from the ground up as a plain-language walkthrough of the architecture, for leaders who need to know what to buy and what to ask for.
When people say "AI agent governance," they usually mean three different things at once, and the confusion costs real money. One team buys a policy document and calls it governance. Another builds enforcement code with no standard behind it. A third assumes the communication protocols handle it. Each bought one layer and assumed it covered the other two. It doesn't. Here's what each layer does, in plain words, and how to tell whether you have all three.
What are the three layers of AI agent governance?
Layer | The question it answers | What lives there |
Framework | What gets governed, who owns the decision, and what does good look like? | The Agentic Trust Framework |
Runtime | Is this specific action allowed, right now, before it runs? | Enforcement tools like the Agent Governance Toolkit |
Protocol | How do agents communicate and prove identity to each other? | Open standards like MCP and A2A |
The framework is the operating model. It says what has to be controlled and what maturity looks like at each stage. The runtime is the enforcement plane: every agent action gets checked against written policy before it executes, so the agent never touches a tool or hands off work without a verdict. The protocols are the interoperability surface, the shared language agents use to talk to each other and to their tools.
The healthy split, and the one actually emerging: standards bodies write the framework and foundations host the protocols, while runtimes implement against both. MCP is a founding project of the Agentic AI Foundation under the Linux Foundation, and A2A is hosted by the Linux Foundation directly.
What does the framework layer actually define?
The Agentic Trust Framework, published by the Cloud Security Alliance in February 2026, asks one question per element, and the five elements carry their full names for a reason: each one is a workstream somebody has to own. Identity Management asks who are you. Behavioral Monitoring asks what are you doing. Data Governance asks what are you consuming and producing. Segmentation asks where can you go. Incident Response asks what happens if you go rogue.
Behind those questions sit 25 formal requirements, each leveled across a four-stage maturity model that runs from Intern to Principal. That's the part leaders should care about most, because it means the framework doesn't just tell you what to govern. It tells you what good looks like at your current stage, so a company with three agents and a company with three hundred aren't held to the same bar on day one. The full spec is open at agentictrustframework.ai under CC BY 4.0. We walk through the five elements in what is the Agentic Trust Framework.
How do you know a runtime actually conforms to a framework?
It publishes an assessment anyone can check. That just happened for the first time. The Agent Governance Toolkit, originally developed at Microsoft and now led by Imran Siddique at Opaque Systems, published a formal conformance assessment against the Agentic Trust Framework: all 25 requirements addressed, 18 fully met, 7 partially met with the shortfalls documented, assessed at the Senior maturity level.
The detail that counts isn't the score. It's that the assessment uses the framework's own requirement IDs, cites the spec as its source, and sits in a public directory where anyone can verify the claim. That's the difference between conformance and a logo on a slide. A framework without a runtime is a document. A runtime without a framework enforces whatever someone happened to write down. The conformance document is the handshake between them.
Doesn't a governance layer slow the agents down?
No, and this is the objection that dies fastest when you see the numbers. A single policy check in the Agent Governance Toolkit runs in 0.011 milliseconds at the median. A typical LLM call takes 500 milliseconds. The governance check is about 0.006 percent of the time budget, and even with 100 rules it stays near 0.030 milliseconds. The enforcement layer is more than a thousand times faster than the model call it protects.
So the cost argument flips. The cost of governing is a rounding error. The cost of not governing is an incident, and agent incidents compound at machine speed. If your architecture question is "can we afford the overhead," the published numbers settle it.
One more piece of convergence worth knowing: the framework and the runtime teams arrived at the same delegation rule independently. Authority can only decrease as it flows down a chain of agents. A parent agent can't grant a child more than it holds. When two groups working at different layers reach the same principle without coordinating, that's usually the sign the principle is right.
What should your company do with this in the next year?
Start with a wrapper, not a platform program.
The fastest path to governed agents is wrapping your existing tools with policy enforcement and audit logging. In the Agent Governance Toolkit that's two lines of code around a tool call. Add identity and trust scoring as you mature.
Pick a framework and assess against it.
You can't enforce what you haven't defined. Run a maturity assessment and find out where you stand before an auditor does it for you.
Put enforcement in the action path.
Detection after the fact gives you an incident report. Enforcement inline gives you a blocked action. For agents moving at machine speed, that difference is the whole game.
Treat governance as infrastructure, not paperwork.
Give it a budget and a benchmark, and hold it to uptime standards, the way you treat logging or authentication today.
If you're building the enforcement side yourself, the five additions in Zero Trust architecture for AI agents are the blueprint for what the runtime layer has to do.
Frequently asked questions
Do I need both a governance framework and a runtime?
Yes, because they do different jobs. The framework defines the 25 requirements across Identity Management, Behavioral Monitoring, Data Governance, Segmentation, and Incident Response. The runtime enforces policy in the agent's action path. Either one alone leaves the other half undone.
What does it mean that a runtime is "conformant" with the Agentic Trust Framework?
It published a formal self-assessment against the framework's conformance spec, using the framework's requirement IDs, in a public place where anyone can check it. The Agent Governance Toolkit was the first: 25 of 25 requirements addressed, 18 fully met, at the Senior maturity level.
How is this different from MAESTRO or the OWASP Agentic Top 10?
They answer different questions. MAESTRO is threat modeling: what could go wrong. The OWASP Top 10 for Agentic Applications catalogs the most common threats. The Agentic Trust Framework answers what comes after both: how you maintain control. They're complements, not competitors.
Where do the protocols fit in?
MCP and A2A are the open standards agents use to talk to tools and to each other. They're the interoperability layer, hosted by foundations rather than vendors, which keeps the communication surface neutral while frameworks and runtimes compete above it.
Key takeaways
AI agent governance is three composable layers: a framework that defines, a runtime that enforces, and protocols that connect.
The Agentic Trust Framework's five elements each carry 25 requirements leveled from Intern to Principal maturity.
The first formal conformance assessment against the framework exists, public and checkable, which is what separates real conformance from marketing.
Inline policy enforcement costs about 0.006 percent of a typical LLM call's latency, so performance is no longer an argument against governing.
Authority can only decrease as it flows down an agent chain. Both layers arrived at that rule independently.
To see which layer you're missing, the free self assessment takes about ten minutes and scores you across all five elements.
The debate about whether agent governance is necessary is over. What's left is the build, and the companies that treat it as infrastructure this year will spend next year shipping while everyone else writes incident reports.