Framework
Governing AI Agents in Regulated Operations
How to keep intelligence roles accountable in environments where a decision has to be explained after the fact.
- Type
- Framework
- Topic
- Governance
- Author
- AEGIS OS™
- Published
- Updated
Key takeaways
- Governance is designed with the workflow, not applied to it afterwards.
- Attribution answers three questions: what was used, which role acted, and who approved.
- Some work is deliberately kept out of scope — that decision is documented, not implied.
- A review trigger is as important as a review schedule: certain events demand immediate examination.
Four controls that carry the weight
- Approval gate
- A named person decides before an output leaves the organisation or changes a committed record.
- Attribution
- Every material output records its inputs, the role that produced it and the person who approved it.
- Boundary
- The data and tools a role may touch, enforced by permission rather than by instruction.
- Review trigger
- A defined event — an escalation, a boundary breach, a disputed output — that forces examination before the next scheduled review.
Deciding what stays out of scope
In regulated and professional contexts, some judgement is not delegated at all. AEGIS deployments in healthcare settings are non-clinical by design: administrative and operational work is in scope, and clinical judgement is not.
- Decisions a licensed professional must personally make
- Commitments that bind the organisation contractually or financially without review
- Communications that represent a person as having said something they did not
- Anything the organisation could not defend by showing how it was produced
Building the evidence trail before you need it
| Question asked later | What must already be recorded | |
|---|---|---|
| Why was this decided? | Inputs and criteria captured at the step | |
| Who decided it? | Named approver on the gate, with timestamp | |
| What produced the draft? | Role identity and version at the write | |
| Was anything overridden? | Exception path and reason recorded, not discarded |
Retrofitting evidence is not possible
An audit trail can only record what the system was designed to capture. Governance added after go-live explains the future, never the past.
Sources and references
- AEGIS AI use policy — Published position on how intelligence is scoped and governed.
- Architecture Assessment — Where gates, attribution and review triggers are documented for one organisation.
Reviewed and published. No client example, vendor comparison, pricing claim, certification or performance figure is described.
Start with an Architecture Assessment
An Architecture Assessment turns these questions into a documented blueprint, readiness analysis, implementation roadmap and quote for your organization.
Related resources
Framework
Human Approval Architecture
Designing approval boundaries so intelligence can draft, prepare and route work while people stay accountable for decisions.
Framework
Operating Boundaries for AI Agents
The six-part specification every intelligence role carries before it is allowed to touch live work.
Framework
What Should Never Be Fully Automated
Decision classes that require a named human owner, and how to encode those boundaries in an operating system.