{"id":194,"date":"2026-09-29T08:00:31","date_gmt":"2026-09-29T08:00:31","guid":{"rendered":"https:\/\/www.dobryakov.net\/blog\/194\/"},"modified":"2026-09-29T08:00:31","modified_gmt":"2026-09-29T08:00:31","slug":"ai-governance-agentic-governance","status":"publish","type":"post","link":"https:\/\/www.dobryakov.net\/blog\/194\/","title":{"rendered":"Agentic AI Governance: Bounded Autonomy, Policy Gates, and the Human in the Loop"},"content":{"rendered":"<p>When an AI system stops generating text and starts taking actions, the failure mode changes entirely. A hallucination stops being a bad reply and becomes an executed money transfer. An injection from an ingested email stops being a formatting glitch and becomes a privilege escalation. The agent&#x27;s power and visibility become the attack surface. Per the 2026 Saviynt report, only 5% of security leaders are confident they could contain a compromised agent. The industry is building systems that act on the world before building the guardrails that bound those actions.<\/p>\n<p><!--more--><\/p>\n<p>This is the problem the agentic-systems engineer owns. You are not tuning a model for better answers. You are engineering an autonomy plane: letting an agent do useful work on its own while explicitly bounding the scope of that autonomy, requiring approval for irreversible actions, and intercepting dangerous behavior before it causes damage.<\/p>\n<h2>The autonomy plane<\/h2>\n<p>Autonomy is not an on\/off switch. It is graduated by the action&#x27;s risk class. The architectural pattern is a <strong>Policy-Gated Action Loop<\/strong>: every agent action passes through a deterministic policy gate that decides whether to auto-execute, require human confirmation, or deny.<\/p>\n<p>This is a direct application of out-of-band policy design. The safety of an action is decided <strong>outside the model<\/strong> \u2014 by a deterministic policy over provenance and action class that cannot be talked past with a prompt injection. The model proposes an action; a system the model cannot influence decides whether it runs.<\/p>\n<pre><code>agent plan \u2192 tool selection\n      \u2502\n      \u25bc\n[classify action risk] \u2192 read | reversible-write | irreversible | financial\n      \u2502\n      \u25bc\n[OPA policy gate] \u2500\u2500 auto \u2500\u2500\u25ba execute (least-priv, short-lived creds)\n      \u251c\u2500\u2500 HITL \u2500\u2500\u25ba approval queue \u2500\u2500\u25ba (human) \u2500\u2500\u25ba execute | reject\n      \u2514\u2500\u2500 deny \u2500\u2500\u25ba block + audit\n      \u25b2\n[kill-switch flag] \u2500\u2500 interrupts the loop immediately<\/code><\/pre>\n<h2>Engineering stack<\/h2>\n<table>\n<thead>\n<tr>\n<th>Layer<\/th>\n<th>Component<\/th>\n<th>Role<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Orchestration<\/td>\n<td>LangGraph, CrewAI, or custom state-machine runner<\/td>\n<td>Explicit states for agent execution<\/td>\n<\/tr>\n<tr>\n<td>Tool protocol<\/td>\n<td>MCP (Model Context Protocol)<\/td>\n<td>Governed server access, scoped tools<\/td>\n<\/tr>\n<tr>\n<td>Policy<\/td>\n<td>OPA (Rego)<\/td>\n<td>Deterministic action gate<\/td>\n<\/tr>\n<tr>\n<td>Kill-switch<\/td>\n<td>Feature flags<\/td>\n<td>Immediate loop interruption<\/td>\n<\/tr>\n<tr>\n<td>HITL<\/td>\n<td>Approval queue + audit trail<\/td>\n<td>Human confirmation for irreversible actions<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Explicit orchestration states are an architectural requirement, not a preference. If the agent&#x27;s execution graph is implicit, you cannot insert a deterministic gate into the flow.<\/p>\n<h2>Step 1. An action catalog with risk classes<\/h2>\n<p>Every tool action gets a risk class and a required execution mode. This catalog is the foundation; the policy gate enforces it.<\/p>\n<pre><code class=\"language-yaml\">actions:\n  search_customer:   {risk: read,             mode: auto}\n  create_ticket:     {risk: reversible-write, mode: auto}\n  update_limit:      {risk: irreversible,     mode: hitl}\n  transfer_funds:    {risk: financial,        mode: hitl, second_approver: true}<\/code><\/pre>\n<p>The agent does on its own whatever is cheap to undo. Anything irreversible or expensive goes through a human. For financial actions, dual confirmation is mandatory.<\/p>\n<h2>Step 2. The policy-gated loop<\/h2>\n<p>Before calling a tool, the agent asks OPA: is this allowed, for whom, under what conditions? The policy evaluates the action class, the amount, the customer, the time of day, and the data provenance. The verdict is logged to the audit trail.<\/p>\n<p>The gate evaluates provenance because the source of the request matters as much as the action itself. An action provoked by an untrusted source \u2014 an ingested email, a scraped webpage \u2014 gets denied regardless of whether the action class would normally auto-execute.<\/p>\n<h2>Step 3. Least-privilege tools via MCP<\/h2>\n<p>MCP servers receive minimal scopes, short-lived revocable credentials, and an allow-list of tools per agent role. MCP servers are supply-chain components: they go into the AI Bill of Materials. An unmanaged MCP server with broad credentials is the same class of risk as an unmanaged SaaS integration \u2014 except the agent can call it at machine speed.<\/p>\n<h2>Step 4. Human-in-the-loop for the irreversible<\/h2>\n<p>Irreversible and expensive actions go to an approval queue. Without explicit confirmation \u2014 two confirmations for financial actions \u2014 they do not execute. This is an explicit state transition in the orchestration graph, not &quot;the model decided it was fine.&quot; The model proposes. The human disposes.<\/p>\n<h2>Step 5. Memory governance<\/h2>\n<p>Agent memory requires isolation and validation. Poisoned memory is a mechanism for smuggling an injection across sessions: an attacker corrupts the agent&#x27;s stored context in one interaction, and the agent acts on that corruption in the next, bypassing the real-time input filters. Memory entries need TTLs, write permissions, and validation on read. The OWASP Agentic Top 10 names memory poisoning explicitly because it is one of the few attack vectors that compounds over time.<\/p>\n<h2>Step 6. Limits and the kill-switch<\/h2>\n<p>A per-task limit on steps and cost prevents runaway loops. Exceeding the limit triggers a stop and escalation. The kill-switch \u2014 implemented via feature flags \u2014 interrupts the loop immediately and freezes unfinished actions. Any agentic task must be stoppable, and its in-flight actions must be freezable. If you cannot freeze the queue, the kill-switch only stops the next action, not the one already in flight.<\/p>\n<h2>Where it breaks<\/h2>\n<p><strong>HITL fatigue.<\/strong> Too many confirmations and the human rubber-stamps &quot;OK&quot; without reading the context. Oversight becomes a formality. The fix is structural: HITL only for genuinely irreversible actions, batching low-stakes confirmations, and providing clear, concise context in each approval request. If the human has to read three paragraphs to approve a ticket creation, they will stop reading.<\/p>\n<p><strong>Injection bypasses the gate through task logic.<\/strong> The agent is convinced the action is legitimate because an indirect injection in ingested data told it so. What saves you is not a guard model arguing with the agent. What saves you is a provenance policy: the action was provoked by an untrusted source, so the gate denies it regardless of the agent&#x27;s conviction.<\/p>\n<p><strong>Composition of safe actions produces a dangerous result.<\/strong> Each individual step is permitted by the gate. The chain is harmful. A single step&#x27;s gate cannot see this \u2014 it needs task-level and session-level invariants that evaluate the cumulative effect of the action sequence, not just each action in isolation.<\/p>\n<p><strong>Gate latency kills agent liveness.<\/strong> Every policy check adds latency. Synchronous checks slow the agent; reserve them for irreversible and financial actions: a gate that checks everything synchronously makes the agent too slow to be useful. The resolution is asynchronous pre-evaluation for read and reversible-write classes, reserving synchronous gates for irreversible and financial actions.<\/p>\n<p><strong>Multi-agent accountability diffusion.<\/strong> In a swarm, accountability diffuses across agents. Tracing causality \u2014 which agent triggered which action, and why \u2014 becomes significantly harder. Stopping the swarm requires a kill-switch that propagates to all agents in the graph, not just the one exhibiting the anomaly.<\/p>\n<h2>Standards mapping<\/h2>\n<table>\n<thead>\n<tr>\n<th>Framework<\/th>\n<th>Provisions<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>OWASP Top 10 for Agentic Applications<\/td>\n<td>Excessive agency, tool misuse, memory poisoning, hijacking via injection<\/td>\n<\/tr>\n<tr>\n<td>OWASP LLM<\/td>\n<td>LLM06 (Excessive Agency), LLM01 (Prompt Injection)<\/td>\n<\/tr>\n<tr>\n<td>EU AI Act<\/td>\n<td>Art. 14 (human oversight), Art. 15 (robustness)<\/td>\n<\/tr>\n<tr>\n<td>ISO\/IEC 42001<\/td>\n<td>Operations and incident management for AI<\/td>\n<\/tr>\n<tr>\n<td>NIST AI RMF<\/td>\n<td>Manage (oversight, intervention)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The EU AI Act Article 14 requirement is direct: a human must be able to intervene. The policy-gated loop is the engineering implementation of that legal requirement. Without the gate, the approval queue, and the kill-switch, &quot;human oversight&quot; is a policy document with no mechanism behind it.<\/p>\n<h2>Maturity checklist<\/h2>\n<ul>\n<li><strong>L1<\/strong>: An agent with an allow-list of tools and action logging.<\/li>\n<li><strong>L2<\/strong>: A risk-class policy gate, HITL for the irreversible, step and budget limits, MCP with least privilege.<\/li>\n<li><strong>L3<\/strong>: Memory governance, a kill-switch with drills, an out-of-band provenance policy, protection against compositional attacks, anti-rubber-stamp measures in oversight.<\/li>\n<\/ul>\n<p>Most organizations deploying agents today are at L0 \u2014 an agent with tool access, no policy gate, and logging that runs only if someone remembers to turn it on. The gap between L0 and L2 is where the real engineering work lives.<\/p>\n<h2>Lab and artifact<\/h2>\n<p>Give the agent four tools of different risk classes via MCP. Set up the OPA gate, an approval queue with dual confirmation for financial actions, step and budget limits, memory isolation, and the kill-switch. Run a red-team exercise: an indirect injection from an ingested email attempting to trigger <code>update_limit<\/code> or <code>transfer_funds<\/code>. The artifact is an action catalog with risk classes, Rego policy gates, a HITL log, and a red-team report mapped against the OWASP Agentic Top 10.<\/p>\n<p>If the injection succeeds in triggering the financial action, the provenance policy is not working. If the human rubber-stamps the approval, the HITL context is not clear enough. Both failures are fixable. The one failure that is not fixable is discovering you needed these guardrails after the agent already executed the action.<\/p>\n<hr \/>\n<p>An agent without bounded autonomy is a tool that acts on your infrastructure with your credentials at a speed you cannot match. The question is not whether the agent will attempt something destructive. The question is whether the policy gate stops it before the action leaves the queue \u2014 and whether you built the gate before giving the agent the keys.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When an AI agent stops answering and starts acting, a wrong answer becomes an executed money transfer. Here is the engineering pattern for bounding agent autonomy.<\/p>\n","protected":false},"author":0,"featured_media":193,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[199,147],"tags":[200,201,202,27,204,203],"class_list":["post-194","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-agentic-ai","category-ai-governance","tag-agentic-ai","tag-bounded-autonomy","tag-human-in-the-loop","tag-mcp","tag-opa","tag-policy-engine"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"How to engineer bounded autonomy for AI agents: policy-gated action loops, MCP least-privilege tools, human-in-the-loop for irreversible actions, and kill-switches.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.dobryakov.net\/blog\/194\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Grigoriy Dobryakov - IT+AI Blog - Grigoriy Dobryakov&#039;s blog: management, development and testing\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Agentic AI Governance: Bounded Autonomy &amp; Policy Gates\" \/>\n\t\t<meta property=\"og:description\" content=\"How to engineer bounded autonomy for AI agents: policy-gated action loops, MCP least-privilege tools, human-in-the-loop for irreversible actions, and kill-switches.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.dobryakov.net\/blog\/194\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-29T08:00:31+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-29T08:00:31+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Agentic AI Governance: Bounded Autonomy &amp; Policy Gates\" \/>\n\t\t<meta name=\"twitter:description\" content=\"How to engineer bounded autonomy for AI agents: policy-gated action loops, MCP least-privilege tools, human-in-the-loop for irreversible actions, and kill-switches.\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/194\\\/#blogposting\",\"name\":\"Agentic AI Governance: Bounded Autonomy & Policy Gates\",\"headline\":\"Agentic AI Governance: Bounded Autonomy, Policy Gates, and the Human in the Loop\",\"author\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/author\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ai-governance-agentic-governance.jpg\",\"width\":1200,\"height\":630,\"caption\":\"Agentic AI Governance: Bounded Autonomy, Policy Gates, and the Human in the Loop\"},\"datePublished\":\"2026-09-29T08:00:31+00:00\",\"dateModified\":\"2026-09-29T08:00:31+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/194\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/194\\\/#webpage\"},\"articleSection\":\"Agentic AI, AI Governance, agentic AI, bounded autonomy, human-in-the-loop, MCP, OPA, policy engine\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/194\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/category\\\/ai-governance\\\/#listItem\",\"name\":\"AI Governance\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/category\\\/ai-governance\\\/#listItem\",\"position\":2,\"name\":\"AI Governance\",\"item\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/category\\\/ai-governance\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/194\\\/#listItem\",\"name\":\"Agentic AI Governance: Bounded Autonomy, Policy Gates, and the Human in the Loop\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/194\\\/#listItem\",\"position\":3,\"name\":\"Agentic AI Governance: Bounded Autonomy, Policy Gates, and the Human in the Loop\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/category\\\/ai-governance\\\/#listItem\",\"name\":\"AI Governance\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#organization\",\"name\":\"Grigoriy Dobryakov - IT+AI Blog\",\"description\":\"Grigoriy Dobryakov's blog: management, development and testing\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/194\\\/#webpage\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/194\\\/\",\"name\":\"Agentic AI Governance: Bounded Autonomy & Policy Gates\",\"description\":\"How to engineer bounded autonomy for AI agents: policy-gated action loops, MCP least-privilege tools, human-in-the-loop for irreversible actions, and kill-switches.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/194\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/author\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/author\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ai-governance-agentic-governance.jpg\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/194\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"Agentic AI Governance: Bounded Autonomy, Policy Gates, and the Human in the Loop\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/194\\\/#mainImage\"},\"datePublished\":\"2026-09-29T08:00:31+00:00\",\"dateModified\":\"2026-09-29T08:00:31+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/\",\"name\":\"Grigoriy Dobryakov - IT+AI Blog\",\"description\":\"Grigoriy Dobryakov's blog: management, development and testing\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Agentic AI Governance: Bounded Autonomy & Policy Gates","description":"How to engineer bounded autonomy for AI agents: policy-gated action loops, MCP least-privilege tools, human-in-the-loop for irreversible actions, and kill-switches.","canonical_url":"https:\/\/www.dobryakov.net\/blog\/194\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.dobryakov.net\/blog\/194\/#blogposting","name":"Agentic AI Governance: Bounded Autonomy & Policy Gates","headline":"Agentic AI Governance: Bounded Autonomy, Policy Gates, and the Human in the Loop","author":{"@id":"https:\/\/www.dobryakov.net\/blog\/author\/#author"},"publisher":{"@id":"https:\/\/www.dobryakov.net\/blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.dobryakov.net\/blog\/wp-content\/uploads\/2026\/09\/ai-governance-agentic-governance.jpg","width":1200,"height":630,"caption":"Agentic AI Governance: Bounded Autonomy, Policy Gates, and the Human in the Loop"},"datePublished":"2026-09-29T08:00:31+00:00","dateModified":"2026-09-29T08:00:31+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.dobryakov.net\/blog\/194\/#webpage"},"isPartOf":{"@id":"https:\/\/www.dobryakov.net\/blog\/194\/#webpage"},"articleSection":"Agentic AI, AI Governance, agentic AI, bounded autonomy, human-in-the-loop, MCP, OPA, policy engine"},{"@type":"BreadcrumbList","@id":"https:\/\/www.dobryakov.net\/blog\/194\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog#listItem","position":1,"name":"Home","item":"https:\/\/www.dobryakov.net\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/#listItem","name":"AI Governance"}},{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/#listItem","position":2,"name":"AI Governance","item":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/194\/#listItem","name":"Agentic AI Governance: Bounded Autonomy, Policy Gates, and the Human in the Loop"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/194\/#listItem","position":3,"name":"Agentic AI Governance: Bounded Autonomy, Policy Gates, and the Human in the Loop","previousItem":{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/#listItem","name":"AI Governance"}}]},{"@type":"Organization","@id":"https:\/\/www.dobryakov.net\/blog\/#organization","name":"Grigoriy Dobryakov - IT+AI Blog","description":"Grigoriy Dobryakov's blog: management, development and testing","url":"https:\/\/www.dobryakov.net\/blog\/"},{"@type":"WebPage","@id":"https:\/\/www.dobryakov.net\/blog\/194\/#webpage","url":"https:\/\/www.dobryakov.net\/blog\/194\/","name":"Agentic AI Governance: Bounded Autonomy & Policy Gates","description":"How to engineer bounded autonomy for AI agents: policy-gated action loops, MCP least-privilege tools, human-in-the-loop for irreversible actions, and kill-switches.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.dobryakov.net\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.dobryakov.net\/blog\/194\/#breadcrumblist"},"author":{"@id":"https:\/\/www.dobryakov.net\/blog\/author\/#author"},"creator":{"@id":"https:\/\/www.dobryakov.net\/blog\/author\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.dobryakov.net\/blog\/wp-content\/uploads\/2026\/09\/ai-governance-agentic-governance.jpg","@id":"https:\/\/www.dobryakov.net\/blog\/194\/#mainImage","width":1200,"height":630,"caption":"Agentic AI Governance: Bounded Autonomy, Policy Gates, and the Human in the Loop"},"primaryImageOfPage":{"@id":"https:\/\/www.dobryakov.net\/blog\/194\/#mainImage"},"datePublished":"2026-09-29T08:00:31+00:00","dateModified":"2026-09-29T08:00:31+00:00"},{"@type":"WebSite","@id":"https:\/\/www.dobryakov.net\/blog\/#website","url":"https:\/\/www.dobryakov.net\/blog\/","name":"Grigoriy Dobryakov - IT+AI Blog","description":"Grigoriy Dobryakov's blog: management, development and testing","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.dobryakov.net\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"Grigoriy Dobryakov - IT+AI Blog - Grigoriy Dobryakov's blog: management, development and testing","og:type":"article","og:title":"Agentic AI Governance: Bounded Autonomy &amp; Policy Gates","og:description":"How to engineer bounded autonomy for AI agents: policy-gated action loops, MCP least-privilege tools, human-in-the-loop for irreversible actions, and kill-switches.","og:url":"https:\/\/www.dobryakov.net\/blog\/194\/","article:published_time":"2026-09-29T08:00:31+00:00","article:modified_time":"2026-09-29T08:00:31+00:00","twitter:card":"summary_large_image","twitter:title":"Agentic AI Governance: Bounded Autonomy &amp; Policy Gates","twitter:description":"How to engineer bounded autonomy for AI agents: policy-gated action loops, MCP least-privilege tools, human-in-the-loop for irreversible actions, and kill-switches."},"aioseo_meta_data":{"post_id":"194","title":"Agentic AI Governance: Bounded Autonomy & Policy Gates","description":"How to engineer bounded autonomy for AI agents: policy-gated action loops, MCP least-privilege tools, human-in-the-loop for irreversible actions, and kill-switches.","keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":"Agentic AI Governance: Bounded Autonomy & Policy Gates","og_description":"How to engineer bounded autonomy for AI agents: policy-gated action loops, MCP least-privilege tools, human-in-the-loop for irreversible actions, and kill-switches.","og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":"Agentic AI Governance: Bounded Autonomy & Policy Gates","twitter_description":"How to engineer bounded autonomy for AI agents: policy-gated action loops, MCP least-privilege tools, human-in-the-loop for irreversible actions, and kill-switches.","schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":null,"created":"2026-09-29 08:00:50","updated":"2026-09-29 08:00:50"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.dobryakov.net\/blog\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/\" title=\"AI Governance\">AI Governance<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAgentic AI Governance: Bounded Autonomy, Policy Gates, and the Human in the Loop\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.dobryakov.net\/blog"},{"label":"AI Governance","link":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/"},{"label":"Agentic AI Governance: Bounded Autonomy, Policy Gates, and the Human in the Loop","link":"https:\/\/www.dobryakov.net\/blog\/194\/"}],"_links":{"self":[{"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/posts\/194","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/comments?post=194"}],"version-history":[{"count":0,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/posts\/194\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/media\/193"}],"wp:attachment":[{"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/media?parent=194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/categories?post=194"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/tags?post=194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}