Agentic AI Transformation

Executive-grade guidance for organisations that need to adopt agentic AI safely, calmly and at scale.

Governance / L2 detail

Policies

Governance8 Level 3 activities

Linked Level 3 activities

Level 3

AI usage policies

XS

Extend acceptable use into explicit autonomy tiers, defined agent red lines, permitted action classes, tool boundaries, and approval thresholds (and link these to enforcement mechanisms in architecture/policy enforcement)

Open Level 3 detail

Level 3

Policy suite uplift across risk taxonomy

M

Update the broader policy suite impacted by agents (eg responsible AI/data ethics, AI usage, privacy, cyber, resilience/operational risk, third-party risk, data quality, model risk/validation) and align definitions/requirements across them

Open Level 3 detail

Level 3

Responsible agent rules

S

Move from static principles to scenario-based rules for autonomous choices and trade-offs (eg prioritisation, customer impact, escalation)

Open Level 3 detail

Level 3

Compliance framework definitions

S

Expand compliance definitions from “AI use case” to explicit objects - agents, agent bundles, foundation models, connectors, tools, and AI platforms - and define required records, controls, and responsibilities per object

Open Level 3 detail

Level 3

Third-party agreements and procurement clauses for agents

S

Update supplier due diligence and contract clauses for agent connectors/tools (data use, logging, breach handling, residency, sub-processors, change notification, audit rights)

Open Level 3 detail

Level 3

AI risk appetite statements and autonomy bounds

S

Update risk appetite to include measurable autonomy limits (impact thresholds, decision classes, spend caps, customer harm tolerance, override requirements)

Open Level 3 detail

Level 3

Accountability policy and ownership model

S

Extend from “model owner” to defined owners for foundation models, agent service/bundle, solution design, infrastructure design, connector use, and tool ownership with clear obligations

Open Level 3 detail

Level 3

Data retention policies (agent memory and traces)

S

Extend retention to agent memory, action traces, and tool outputs, aligned to privacy, evidencing, and dispute requirements

Open Level 3 detail