Whitepaper · Spekir · July 2026
Governance for AI agents: from invisible workforce to governed system
You already have more AI agents than you think, some you started, some embedded in your SaaS, some wired up by employees. Governance is not a brake on them. It is the infrastructure that lets you say yes to more of them, faster, with an owner, a purpose, a kill-switch and an audit log for each.
00Summary
Summary for busy readers
Your company already runs AI agents. Some you started yourself. Some arrived with the last update of your SaaS tools. And some employees wired up on their own, with access to real data and nobody writing it down.
Gartner expects 40 percent of enterprise applications to carry task-specific agents by the end of 2026, up from under 5 percent in 2025. The shift is not on the way. It has happened. The new part is not that software acts, but that it acts with write access, across systems, at a pace no one can follow by hand.
Most organisations today cannot answer five simple questions. Which agents are running. Who owns them. What do they have access to. How do we switch one of them off, now. And can we prove all of it to an auditor. This whitepaper gives a practical governance model in five pillars, a concrete tool (the agent passport), an architecture principle (context with review, not access without accountability) and a checklist to start on this month. Not to slow the agents down, but to be able to say yes to more of them, faster, without losing sleep.
PDFRead here or take the PDF
The full text on this page and the designed PDF are both free. No email is required to read or download. The button works whether or not you fill in anything below.
Download the PDF01Risk class
The new risk class has hands
Shadow IT was a manageable problem for years: a department bought a tool around IT, and the worst consequence was usually wasted license money and a dataset in the wrong place. Shadow agents are a different category. An agent with write access can create, change and delete. It can act across systems through APIs and MCP connections. It can be prompted into something dumb by a well-meaning colleague. And it leaves traces only if someone arranged logging.
The industry's own literature is remarkably united on the diagnosis: a large share of organisations now monitor their AI use, but far fewer can bound what an agent may touch, and fewer still can switch a specific agent off immediately. The gap between 'we can see it' and 'we can control it' is 2026's most underrated operational risk.
The problem is not the agents. It is that most organisations gave a new kind of employee access to production systems with no contract, no manager and no personnel file.
02Five pillars
The five pillars of agent governance
Across AgentOps thinking, five pillars crystallise. They are not exotic. They are classic good IT operations, applied to a new workforce. Inventory: you cannot govern what you cannot see. All agents, internal, embedded in SaaS, and third-party, are registered in one place, with purpose and owner. Not in a spreadsheet, but in a model that knows what the agent is connected to. Identity: every agent has its own identity and its own keys. Shared service accounts are governance-dark: when everyone writes as 'system', no one has written anything.
Least access: an agent gets access to what its purpose requires, and no more. The purpose is binding: an agent that enriches the system map has no business in the payroll system. Observability: everything an agent reads, proposes and executes is logged, because the log is the evidence every later question is answered with. Continuous compliance: classifications, access and ownership are reviewed on a cadence, not at annual audit. Agents change with every model update; supervision must too.
The pillars are not five projects. In a living model they are five properties of the same system.
03The passport
The agent passport
The concrete tool that makes the pillars operational is the passport: a structured profile per agent, a first-class citizen in the architecture model on a par with systems and data. An agent passport in Atlas holds the purpose (purpose binding, written so an auditor can read it), the owner (a named human with responsibility, no owner no agent), the allowed systems and data (relationships in the graph to the applications, integrations and datasets the agent may touch), the kill-switch status (how the agent is stopped, and when it was last verified), the review cadence, and the provenance (where the agent comes from and which model it runs on).
Because the passport lives in the graph and not in a document, it can answer the question no spreadsheet can: what is the blast radius. Pick an agent and see the whole chain: which systems it reaches, which data those systems hold, which processes those data drive. 'What can this agent touch' becomes a lookup with a picture, not a workshop. And because the model is alive, it finds candidates itself: new AI features in existing systems, usage signals that look like an unregistered assistant, connections nobody reported. Shadow agents move from anecdote to inbox.
04Context with review
Turn the architecture around: context with review
Here is the architecture choice most people miss, and it decides whether agent governance becomes control or suffocation. The market's default pattern is to make all systems readable to agents: every vendor exposes an MCP server, every agent connects, and context flows freely. That solves the productivity problem and creates the governance problem: a hundred connections, no shared knowledge of who asked about what.
The reverse pattern is stronger: give the agents one place to ask, and let that place have rules. In Atlas it is the MCP Context Hub. The organisation's agents, whether built, bought or embedded, ask Atlas for the organisation's truth. Reads are answered from the typed graph, with citations; the agent quotes the model, it does not make things up. Writes are never executed directly; they become change proposals that land in the Verify inbox and wait for a human. Write-with-review is the default, not an opt-in feature. And all traffic is logged per agent identity and becomes evidence in the agent's passport, so the inventory partly maintains itself.
Governance is not a fee the agents pay. It is the infrastructure that makes them usable.
05Real-time policy
Policies that work in real time
Annual-cycle governance is designed for a pace where humans make the changes. Agents make more, smaller changes, all the time. Supervision has to move from the calendar to the event stream. In Atlas, architecture policies evaluate the proposals as they arise. Harmless proposals, a metadata enrichment or an obvious duplicate flag, can be auto-approved with a log. Sensitive proposals, new access, changes to critical systems, anything touching personal data, are flagged and require human approval.
And the most important part, which surprisingly few systems have: a place where the no lives. An agent whose proposals are consistently rejected is a signal. An agent with no activity for three months is a signal. An agent whose access grows quietly is a signal. The policy layer gathers the signals so the human with the responsibility can actually exercise it. The result is continuous review instead of annual archaeology: the week's delta per domain, generated by the system, handled by people in half an hour.
06Evidence
Evidence: from trust us to see for yourself
Governance without evidence is a mood. Three audiences must be served straight from the system. Supervision and audit: the EU AI Act has become more manageable for the mid-market. The Digital Omnibus (approved by the European Parliament on 16 June 2026) deferred the high-risk obligations to 2 December 2027 and widened the relief regime to companies up to 750 employees or 150 million euro in revenue. But manageable is not the same as optional: inventory, classification and documentation still have to exist. In Atlas the AI Act documentation is generated from the register and the passports, with provenance-stamped rationale per classification.
The board increasingly asks for one connected narrative: what AI do we have, what does it cost, what does it do to risk, and what do we get out of it. Boardroom views and the board pack pull the story straight from the model, and the ROI ledger ties each use-case to a value hypothesis and realised value over time. A verified figure worth keeping in view: only about a third of CIOs can consistently prove financial AI outcomes today, while AI spend grows roughly 35 percent a year. And the organisation itself is the underrated audience: when employees can see which agents exist, what they may do, and who owns them, both the fear and the temptation to build around it fall. Visibility is the cheapest behaviour regulation there is.
07The checklist
Get started: the checklist
Governance programmes die of scope. Start with what can be done this month. Make the inventory, scrappy: write down the agents you know, bought, built, embedded, and accept that the list is incomplete, because it is for everyone. Give each agent an owner: one name per agent, and the agents nobody will own have just told you something important. Write down the purpose: one sentence per agent, because if the purpose cannot be stated, the access cannot be justified.
Find the kill-switch: do you know how each agent is stopped. Try it on one of them. Seriously, try it. Channel the context: decide that agents from now on pull organisational knowledge from one place, and that writes go through review. That is the day governance stops being a document. Set the cadence: a quarterly passport review per agent, half an hour, because the calendar is half of all governance. Tick those six and you are ahead of most, with the foundation the rest of the journey builds on: more agents, more autonomy, the same calm.
08Sources
Sources
Gartner (26 Aug 2025): 40 percent of enterprise apps carry task-specific agents by the end of 2026, from under 5 percent in 2025. European Parliament approval of the Digital Omnibus (16 Jun 2026): Annex III deferral to 2 Dec 2027, relief regime widened to 750 or fewer employees or 150 million euro (Travers Smith, Latham and Watkins, Morgan Lewis, Stibbe, DLA Piper). Gartner CIO Agenda 2026: about a third of CIOs consistently prove financial AI outcomes, AI spend up roughly 35 percent year over year. MCP adoption: 97 million installations, 78 percent of enterprise AI teams in production. Qualitative statements about the monitoring and containment gap draw on AgentOps industry analyses (ITECS, CSA, Microsoft Security and others) and are deliberately given without precise percentages.
Get started
See the whole flow in Atlas
Atlas' demo workspace holds a realistic AI portfolio, including an Annex III high-risk example and a shadow agent, so you can see the whole flow: discovery, passport, blast radius, review and evidence.