AI agent governance is rapidly becoming a serious enterprise discipline. It has to. Agents are no longer confined to answering questions in a chat window. They can navigate systems, use tools, access information, make decisions, execute multi-step tasks, and increasingly act on behalf of people inside real business workflows.
The security and governance ecosystem is responding quickly. Identity, permissions, data access, runtime behavior, observability, tool use, prompt injection, containment, and agent-to-agent interaction are all becoming legitimate control domains. In February 2026, NIST launched its AI Agent Standards Initiative to support interoperable and secure adoption, including new work around agent authentication, identity infrastructure, and secure human-agent interactions. OWASP is developing its own increasingly substantial body of agentic security work, including the new Agent Control Standard, which focuses on making agents inspectable, traceable, instrumentable, and controllable at runtime.
All of this is necessary. It is also only part of the system we are trying to govern.
Because every time an organization asks a person to supervise an agent, approve its work, interpret its recommendations, decide when to challenge it, escalate a problem, take responsibility for its output, or simply work alongside it, another control surface appears: the human-agent relationship itself.
Agentic systems make this particularly visible, because the risk increasingly sits in the human-agent system, not neatly on either side of the relationship. We explore that in more depth in our guide to AI agent governance.
That is where AI agent governance should overlap with Human Risk Management.
What solutions help organizations manage human risk when employees work with AI agents?
Organizations need a layered control model, not a single AI security product.
AI governance establishes policy, accountability, acceptable use, and risk ownership. Identity and access management determines what agents and people can access. Data-security controls protect sensitive information. Agent-security and runtime controls constrain what an agent can do and create visibility into its actions. Monitoring and observability help organizations understand and reconstruct what happened.
Human Risk Management addresses a different set of questions: whether the people working with agents have the capability, context, authority, and judgment required to use them appropriately; how much they rely on agent outputs; whether they verify, challenge, or override them when needed; whether escalation actually works; how behavior changes as familiarity grows; and whether the organizational environment quietly undermines controls that appear perfectly sensible on paper.
We have written before about why Human Risk Management increasingly acts as a control plane for AI at work. Agentic systems make that argument more consequential. Technical controls can govern what an agent can do. Human Risk Management helps organizations understand and influence what happens when people trust, direct, supervise, challenge, override, or act on what that agent does.
Enterprise agent governance needs both.
AI agents change the control relationship
Traditional software usually waits. It may automate a deterministic process, enforce a rule, or surface information, but the relationship between operator and application is relatively easy to understand.
Agentic systems blur that boundary. They can interpret a goal, plan a sequence of actions, choose between tools, retrieve information, make intermediate decisions, and continue moving a task forward with progressively less human involvement. NIST's current agent initiative explicitly recognizes the growing importance of secure interactions between agents, humans, and digital systems as this ecosystem matures.
That is why agent governance naturally begins with questions such as:
- What identity does the agent have?
- Which systems can it access?
- What tools can it invoke?
- What information can it see?
- Which actions require approval?
- What gets logged?
- How can it be stopped?
- What happens if its objective, context, memory, or instructions are compromised?
These are good questions, and work such as OWASP's Agent Control Standard is helping organizations develop a stronger technical control plane around them.
But the approval gate creates another set of questions.
Who is doing the approving? Do they understand what they are approving? Do they have enough information to recognize a problem? Have they learned where the agent is reliable and where it is not? Are they expected to inspect one consequential agent action per day or three hundred routine ones? Does rejecting an agent create ten minutes of extra work? Is the employee already under pressure to move faster? Does the culture reward questioning automated recommendations, or does “the system said so” quietly end the conversation?
The agent may be well governed while the work system around it is not.
That distinction becomes more important, not less, as autonomy increases.
Human-in-the-loop is an architecture, not evidence of control
“Human in the loop” has become reassuring language. It suggests that even if an AI system becomes uncertain, consequential, or risky, a person remains present to make the final call.
Sometimes that is an excellent control.
Sometimes it is a box on a diagram.
The mere presence of a human does not tell us whether meaningful oversight is occurring. NIST is considerably more precise about this than much of the shorthand around AI governance. Its AI Risk Management Framework Playbook specifically recommends defining and differentiating human roles and responsibilities for AI oversight, developing proficiency standards, providing risk-management training, capturing risk information about human-AI configurations, and addressing known difficulties in human-AI teaming and user interaction.
That gets us closer to the real control question.
A human approval point becomes meaningful only when the person has enough capability, authority, context, attention, and opportunity to intervene effectively.
Imagine a finance employee reviewing an agent-generated recommendation. The workflow technically requires human approval. But the agent is normally right, the employee is processing dozens of recommendations, the reasoning is difficult to inspect, rejecting the recommendation creates more work, and the team is already behind target.
The organization has a human in the loop.
Whether it has meaningful human oversight is a different question.
NIST itself highlights this problem in its guidance on AI risk management and human-AI interaction, noting the importance of understanding whether people are actually empowered and incentivized to challenge AI outputs, and whether organizations can learn from when and why humans overrule systems.
This is why Cybermaniacs argues that agentic governance has to look beyond the existence of approval gates and examine the actual conditions surrounding human judgment.
The unit of risk is becoming the human-agent system
For years, cybersecurity often divided controls into neat categories. Technology had vulnerabilities. People made mistakes. Security built protections around both.
Agentic work makes that separation considerably less useful.
An outcome may now emerge from a chain in which a person frames a task, an agent interprets it, several tools are invoked, an output influences the person's judgment, another system carries the decision forward, and the human eventually approves something they did not personally construct.
Whose risk was that?
The better unit of analysis is increasingly the human-agent system: the combination of people, agents, workflows, permissions, interfaces, incentives, organizational conditions, and control mechanisms producing the outcome.
This does not eliminate individual accountability or technical security. It gives both of them context.
We explored one part of this problem in our work on Human-AI Work Design. The central issue is that AI does not simply insert a new technology into an existing job. It changes how tasks move, where judgment happens, what people can see, when intervention occurs, and sometimes who or what is meaningfully responsible for the work.
Agentic systems accelerate that shift.
A mature Human Risk Management program therefore needs to understand more than whether somebody has read the AI policy or completed an AI-awareness course. It needs visibility into how human behavior and capability are changing as AI begins mediating more consequential work.
Several dimensions deserve particular attention.
Reliance: trust should be calibrated, not maximized
How much weight does an employee place on an agent's recommendation or output?
Too little reliance can defeat the purpose of the technology and send employees back toward manual or shadow processes. Too much reliance can turn assistance into deference, particularly when repeated exposure to competent outputs creates a growing assumption that the next output will also be right.
The goal is not maximum trust in AI.
It is appropriately calibrated trust.
That means understanding whether trust changes appropriately with task, consequence, expertise, system performance, and uncertainty.
Verification: “check the AI” is not much of a control
“Verify AI output” is easy policy language.
The interesting question is what verification actually means.
Verification becomes harder when the task is complex, the employee lacks deep domain expertise, the evidence is difficult to inspect, or the efficiency benefit disappears if every output has to be manually recreated before somebody can trust it.
Organizations therefore need to define proportionate verification around actual workflows. A low-consequence drafting task and an agent recommendation that changes a customer's financial position should not require the same level of human scrutiny.
Without that distinction, “verify the output” risks becoming another policy instruction that everybody technically understands and nobody can consistently perform.
Influence: the AI does not need the final say to shape the decision
An agent does not need formal decision authority to exert considerable influence.
It can determine which information appears first, frame the available choices, summarize evidence, suggest language, recommend a course of action, or establish an initial position around which subsequent human thinking gravitates.
That creates a subtler governance problem.
Organizations need to consider not only whether a human makes the final decision, but how the AI shaped the judgment that produced it.
This is part of why the human-agent relationship deserves to be treated as a real control surface rather than a footnote to model governance.
Intervention and override: can people actually stop the system?
A well-designed agentic workflow needs more than an emergency stop.
Employees have to recognize when intervention is warranted, know what action to take, understand the consequences of intervention, and have the authority to act.
Workflow design matters here. So do incentives and culture.
An override mechanism that is technically available but socially discouraged, operationally painful, or routinely ignored is weaker than the architecture suggests.
The same is true of escalation.
Escalation: governance needs somewhere for uncertainty to go
Novel systems produce novel uncertainty.
Employees need somewhere to take the case that does not fit: the output that feels wrong but is difficult to prove wrong, the behavior that may not violate policy but still seems concerning, the unexpected interaction between tools, or the workflow nobody quite seems to own.
Escalation is therefore more than incident management.
It is part of the learning system surrounding agent adoption.
We have written separately about the increasingly awkward question of who owns AI risk when AI changes how work gets done. The answer cannot simply be “Security” for technical risk and “HR” for people risk, because the most interesting agentic failures occur precisely where those categories stop being separable.
Adaptation: the risk does not stand still after launch
Human behavior around AI will not remain static.
People learn the quirks of systems. They develop shortcuts. Confidence increases. Workarounds appear. Teams establish informal norms. Tasks migrate between humans and agents. Skills can strengthen, weaken, or simply change. A workflow that behaves one way during a carefully managed pilot can behave very differently once several thousand employees have been living with it for nine months.
Agent governance therefore cannot be a launch checklist.
It has to observe the human-agent relationship as it evolves.
That is one reason measurement becomes such an important part of the control system.
The seven layers of enterprise AI agent governance
It is useful to think of agent governance as a set of complementary control layers rather than a contest between competing categories of technology.
| Control layer | Core question | Typical capabilities |
|---|---|---|
| AI governance | Should this use exist and under what rules? | Policy, inventory, risk classification, ownership, lifecycle governance |
| Identity & privilege | Who or what can access which resources? | IAM, non-human identity, least privilege, authentication, authorization |
| Data protection | What information can enter or leave the system? | DLP, classification, access controls, data governance |
| Agent security & runtime control | What can the agent do while operating? | Tool controls, runtime policy, containment, agent monitoring, prompt-injection defenses |
| Observability & evidence | What happened, and can we reconstruct it? | Logging, telemetry, audit, SIEM integration, traceability |
| Human Risk Management | Can people work with and supervise the system safely? | Readiness, competency, reliance, verification, behavior, culture, escalation, targeted intervention |
| Change & workforce enablement | Can new ways of working become safe, useful, and sustainable? | Role redesign, communication, learning, adoption support, workflow change |
These layers are complementary.
An identity product should not be expected to solve a workforce-readiness problem. Employee training should not compensate for wildly excessive agent permissions. A DLP control cannot tell you whether an approver understands the decision they are validating. Human Risk Management cannot patch a technical containment failure.
Controls work best when they solve the problems they were designed to solve and share enough evidence to illuminate what is happening across the wider system.
That is also why developments such as OWASP's Agent Control Standard strengthen rather than compete with the Human Risk Management case. The technical control plane is becoming more sophisticated. Organizations now need comparable seriousness around the people operating inside it.
Training matters. It is not an operating model.
There is a tempting answer to every new human-risk problem: "Let's just train everybody."
Yes, certainly training matters, but let's be honest, it's not an operating model.
If an employee lacks the authority to challenge an agent, training them to challenge it does not solve the problem. If a workflow requires impossible levels of manual verification, another awareness module will not make the workflow sustainable. If incentives reward speed while policy demands deliberation, the organization has created a control conflict.
Managing human-agent risk therefore requires several forms of intervention.
Role and decision design should establish where humans lead, where agents act, where approval is required, and where accountability remains.
Competency and readiness should reflect the actual work people are being asked to perform, including the ability to recognize limitations and failure modes relevant to their role.
Policies and guardrails should be specific enough to guide real decisions without asking an employee to consult thirty pages of governance prose every time an agent behaves unexpectedly.
Learning and communications should evolve as tools, threats, workflows, and organizational norms change rather than treating AI competence as an annual compliance event.
Behavioral and cultural measurement should help organizations understand whether expected practices are actually taking hold.
Risk signals should be used proportionately to identify where additional support, intervention, or control redesign is warranted.
And feedback loops should make incidents, near misses, questions, overrides, and unexpected behaviors useful inputs into governance rather than simply evidence that somebody failed.
This is where the existing discipline of Human Risk Management becomes particularly useful. It asks a more productive question than “Did the employee know the rule?”
It asks: What is driving the behavior, and what intervention is actually likely to change it?
AI does not make that question less important. It makes the consequences of answering it badly considerably larger.
Measure the relationship, not just the deployment
Organizations are becoming very good at measuring AI systems.
They can track adoption, licenses, model performance, errors, latency, token consumption, usage volumes, and increasingly the actions taken by agents.
Workforce measurement often remains much thinner.
An organization may know that 73 percent of a business function uses its approved AI tooling every week without knowing whether those employees can identify when an output requires verification. It may know that an approval was recorded without knowing whether the approver had enough understanding to challenge the recommendation. It may know that adoption is rising without knowing whether confidence is appropriately calibrated as it rises.
That is why we think AI workforce measurement increasingly needs to examine the conditions surrounding use: capability, behavior, reliance, confidence, culture, workflow, escalation, intervention, and the organizational environment in which decisions happen.
We explore this in much more depth in How Do You Measure Human Risk in AI-Driven Work?
The objective is not employee surveillance.
It is enough visibility to recognize when the human-agent system begins drifting away from the assumptions on which the governance model depends.
So who owns the human side of agent governance?
Probably nobody alone.
Security has an obvious role in threat, identity, data, technical controls, monitoring, and incident response. AI governance leaders bring policy, lifecycle oversight, and risk classification. IT and technology teams own substantial parts of deployment. Legal, privacy, compliance, HR, and business leaders each own different parts of the environment in which AI-enabled work occurs.
The difficult risks appear between them.
NIST's AI Risk Management Framework is explicitly socio-technical in orientation, emphasizing a broad set of actors and perspectives across AI governance rather than treating AI risk as a purely technical discipline.
Someone still needs accountability, but the operating model needs shared evidence and coordinated intervention. Our earlier piece on CISO and HR AI governance explores what that shared ownership starts to look like when AI changes roles, judgment, accountability, and the design of work itself.
Where Cybermaniacs fits
Cybermaniacs does not replace AI governance, IAM, DLP, runtime agent security, or technical observability.
We work on the part of the system those controls cannot solve by themselves: the people, behaviors, capabilities, culture, and changing work surrounding AI.
Our AI Enablement & Change work helps organizations understand workforce readiness, adoption barriers, capability, confidence, behavioral risk, and where targeted intervention can help AI adoption become safe and productive rather than simply widespread.
Our Agentic Readiness & Change capability goes further into the operating model created by agents: helping organizations clarify human and agent roles, identify where workflows and controls need to change, prepare people to work with and supervise increasingly capable agents, and build targeted enablement as agentic AI scales.
And this sits within a broader Human Risk Management approach because agentic AI is not creating a completely separate species of workforce risk. It is amplifying questions organizations already need to answer about judgment, trust, competency, behavior, accountability, intervention, and resilience — while fundamentally changing the environment in which those questions have to be answered.
As AI systems become more autonomous, that distinction gets harder to ignore. In our guide to AI agent governance and the missing human-risk layer, we look at what happens when governance has to account not only for what an agent can do, but for how people supervise, trust, challenge, override, and work alongside it.
The next generation of agent governance will govern relationships as well as systems
Agent security is going to improve quickly. Identities will become better defined. Permissions will become more granular. Runtime controls will mature. Observability will improve. Standards will settle. NIST's new AI Agent Standards Initiative and OWASP's Agent Control Standard are both evidence of how quickly the technical and governance architecture is developing.
That progress should make agents safer. It will not make the human side automatic.
The more capable agents become, the more consequential the handoffs between human judgment and machine action become too. Organizations will need to know when people should trust, when they should verify, when they should intervene, whether they are equipped to do so, and what happens when the relationship between person and agent changes over time.
That is why the next phase of AI agent governance needs a broader unit of analysis.
Not simply: Is the agent controlled?
But: Is the human-agent system working safely, effectively, and as intended?
That is the human-risk layer.
The broader workforce problem extends well beyond agents. Our guide to AI workforce risk management looks at how AI changes capability, behavior, judgment, work design, culture, and organizational risk across the workforce.
Frequently Asked Questions
What is AI agent governance?
AI agent governance is the set of policies, accountabilities, technical controls, lifecycle processes, and oversight mechanisms used to determine how AI agents may be developed, deployed, accessed, monitored, and used within an organization. It can include agent inventory, risk classification, identity and permissions, data governance, runtime controls, logging, human oversight, and incident response.
For organizations building their governance model, the NIST AI Risk Management Framework provides a broader framework for governing, mapping, measuring, and managing AI risk, while NIST's newer agent initiative addresses issues specific to increasingly autonomous systems.
What is human risk when employees work with AI agents?
Human risk arises from the way people understand, direct, trust, verify, supervise, challenge, override, and act on AI agents. It can also arise from workflow design, unclear accountability, insufficient competency, excessive or insufficient reliance, weak escalation, conflicting incentives, and cultural norms surrounding AI use.
Is human-in-the-loop enough to manage AI agent risk?
No. Human-in-the-loop describes the presence of a human decision or approval point; it does not establish that meaningful oversight is occurring. Effective human oversight depends on whether the person has sufficient capability, context, authority, attention, and opportunity to recognize problems and intervene.
What solutions are needed to manage AI agent risk?
Most enterprises will need a combination of AI governance, identity and access management, data protection, agent-security and runtime controls, observability, Human Risk Management, and workforce change or enablement. These capabilities solve different parts of the same human-agent system and should be designed to work together rather than treated as substitutes for one another.
How does Human Risk Management fit into AI governance?
Human Risk Management provides a workforce-risk layer within the broader AI governance system. It helps organizations understand and influence the capabilities, behaviors, culture, and organizational conditions shaping how people use and supervise AI, while producing evidence that can inform governance decisions and targeted interventions.
What should organizations measure when employees use AI agents?
Relevant measures can include workforce readiness, role-specific competency, reliance and verification behavior, confidence, escalation, intervention and override behavior, workflow conditions, cultural norms, adoption patterns, and appropriate enterprise risk signals.
Measurement should be proportionate, transparent, and focused on making the system safer and more effective rather than turning AI governance into employee surveillance.