A chatbot replies. An agent acts. That one difference is why most AI governance programs written in the last two years now need to change, and why AI agent regulations matter more than the policy PDF sitting on your intranet.
What changes when AI starts acting
A generative assistant is single-turn. A prompt goes in, an answer comes out, and a human reads it, decides, and does something. The worst case is bad content: a hallucinated fact or an inappropriate answer. The controls built for that world are usage policies, human review, and red-teaming of outputs.
An agent plans multi-step work toward a goal. It calls tools and APIs, it calls other agents, and it holds memory across sessions. The worst case is no longer bad content. It is wrong actions at machine speed: a ticket closed, a record deleted, a payment sent, a configuration changed, a thousand times before anyone notices.
The blast radius changed, so the control set has to change with it. Agents need identity, authorization, runtime guardrails, and audit. Those are security and platform controls, not content-review controls, and most AI policies we review were written only for the first case.
AI agent regulations: the regulatory floor
You no longer choose whether to have agent governance. You choose whether to build it before or after someone asks for it. Three frameworks set the floor, and a fourth wraps them.
1. The EU AI Act: the law
The Act’s transparency obligations applied from August 2, 2026. Following the Digital Omnibus, which entered into force on July 27, 2026, the high-risk obligations for Annex III systems now apply from December 2, 2027, and Annex I systems follow on August 2, 2028. Four requirements in the high-risk obligations matter most for agents:
- Continuous risk management across the agent’s lifecycle.
- Human oversight that can stop an action before it commits. A person must be able to halt or reverse the action. Reviewing logs afterward does not meet the requirement.
- Automatic logging and traceability of every action and every system the agent touches.
- Transparency to users about when they are dealing with an AI system.
If your agent acts in banking, healthcare, HR, or critical infrastructure, assume it is high-risk. The Act reaches any provider whose system is used in the EU, so a US company with EU users is in scope. The deadline moved; the oversight and logging requirements did not.
2. The NIST AI Agent Standards Initiative: the guidance
NIST launched its AI Agent Standards Initiative on February 17, 2026, with three pillars: industry-led standards, community-led open protocols for agents, such as the Model Context Protocol (MCP), and research on agent identity and security. NIST’s adversarial machine learning taxonomy, AI 100-2, already covers indirect prompt injection and the security of AI agents. Even if you never sell to the US government, expect this language to appear in customer procurement and security questionnaires.
3. The OWASP Top 10 for Agentic Applications: the test plan
OWASP’s Top 10 for Agentic Applications, published in December 2025, is the first OWASP risk list written specifically for agents. It is what your security team should test against before an agent is promoted to production.
4. ISO/IEC 42001: the certificate
ISO/IEC 42001 is the certifiable AI management system that wraps the other three. When a customer asks whether you are “certified for AI,” this is the standard they mean.
Four frameworks, four different jobs
These AI agent regulations and frameworks are easy to treat as alternatives. They are not. The EU AI Act is law with extraterritorial reach. NIST is guidance that becomes a de facto procurement baseline. OWASP is a test plan. ISO/IEC 42001 is a certificate. You do not pick one; you map each agent to the obligations that apply and let the ISO structure hold the evidence.
What to do this quarter
- Find the agents that can write. Inventory every agent and flag the ones that can change a production system. Ask the question in your next leadership meeting; the answers usually surprise the people in the room.
- Put an approval gate on irreversible actions. Anything you cannot undo with a click, such as sending, deleting, paying, or deploying, needs a human checkpoint before it commits. Everything else can run.
- Map every agent to one row. For each agent in your registry, record which EU AI Act obligations apply, which NIST and OWASP controls you test, and where the evidence lives under ISO/IEC 42001. That one-sheet-per-agent mapping is the most reusable audit artifact you will produce, and it is the first thing auditors ask for.
- Move your policy from content controls to action controls. Add identity, scoped permissions, runtime guardrails, and audit logging to the policy you already have.
If you are deciding where to build your first governed agent, our comparison of Rovo and Copilot Studio covers the platform side. For regulated teams in financial services and healthcare, our AI adoption and governance practice builds the operating model, decision rights, and control mapping described here.
Book a 30-minute discovery call to talk through mapping your agents to the EU AI Act, NIST, and OWASP.

