Do you need an AI governance framework?

Home       Blog       Do you need an AI governance framework?

Do you need an AI governance framework?

Somewhere in your firm there’s a document that says who can commit the firm to what.

It might be called a delegation of authority schedule, or a signing matrix, or just “the approvals policy”. It’s been through the board. It says a senior associate can authorise up to a figure, that above another figure it needs two partners, and that certain things need you personally regardless of the amount.

It’s one of the oldest and best ideas in professional practice. Every action the firm takes has a name attached to it, decided in advance, written down.

Now find the row for the software.

There isn’t one, and somebody will shortly offer to sell you an AI governance framework to fix that. Hold off. The document you already have is closer to the answer than anything you’d buy.

The question I get asked most

More partners are asking me a version of the same question, and it’s the right question: if one of these things does something wrong, who’s answerable?

For the last two years the answer was comfortable, because the tools only answered. Someone asked Copilot to summarise a thread, read the summary, decided what to do, and their name went on the decision. The human was the control.

That’s changed, quietly, in about eighteen months. The tools act now. They watch a mailbox and respond to a trigger. They move information between systems. They fill in a form, update a record, draft and send. Microsoft’s own admin dashboard for this reports a metric called agent run-time, meaning total hours worked by agents, which tells you how the vendors are thinking about it.

The Australian Institute of Company Directors, in the second version of its director’s guide to AI governance published in June with the University of Technology Sydney, found that nearly a third of organisations, 32.5%, reported at least one use of agentic AI, with a further 12.9% planning adoption. The research covered 419 directors and senior executives, surveyed in late 2025.

So this isn’t a frontier question.

It’s a “roughly one in three of your peers, already” question.

Beware: An agent inherits a person’s access, but not their judgement, their conscience, or their name on the file.

What the regulator has already said

ASIC got here before most firms did. In October 2024 it published REP 798, Beware the gap: Governance arrangements in the face of AI innovation, a review of 624 AI use cases across 23 banking, credit, insurance and financial advice licensees.

Two findings worth carrying into your next risk committee.

Nearly half the licensees reviewed had no policy referencing fairness or the risk of bias, and fewer still had anything about disclosing AI use to consumers.

And around 60% intended to increase their AI use, which is what produced the title.

Joe Longo’s line is the one I’d put on the agenda paper: “This can only happen if adequate governance arrangements are in place before AI is deployed.”

Notice what that sentence assumes. Not adequate technology. Adequate governance. The regulator’s describing a paperwork problem, which is convenient, because paperwork is something your firm is extremely good at.

One thing REP 798 doesn’t do is use the word agent, because in December 2023, when the data was collected, this wasn’t yet a category.

The evidence base predates the thing you’re now buying. That’s worth saying out loud, because it means nobody’s going to hand you a rulebook for this in time…

I sell automation for a living, and my own side of the industry has been much quicker to switch these things on for firms than to write down who owns them. That one’s ours to wear. It also isn’t a framework problem, which is the good news: it’s four answers, and you can write the first set this month.

Do you need an AI governance framework? Not the kind you’re being sold

You don’t need one. You need four answers, in writing, for each agent your firm runs. They make up the missing row.

Who owns it? A person, by name, not a team. Microsoft’s own agent dashboard has an administrative task called “manage agents without owners”, which tells you how common the problem already is. An ownerless agent is an action nobody’s agreed to be answerable for.

What can it reach? An agent runs on permissions, and permissions in most firms have drifted for years. Nobody who switched one of these on was cutting a corner. They were doing the thing your firm has rewarded for thirty years, finding the faster way to get the work out the door, with a tool you bought them and asked them to use. The access review is work you’d be doing anyway, and it has to happen before the agent runs, not after somebody notices what it found.

What can it do without a human? This is the delegation schedule question, and it’s the one that actually matters. Read only, or read and draft? Draft and send? Draft and send externally? Anything that touches client money, client instructions or outbound client communication needs a person in the loop, and that should be a written rule rather than a current setting.

How would you know? If an agent did something today that it shouldn’t have, what would tell you, and when? There’s now a SharePoint agent access insights report showing how agents are reaching content across your sites, which is the closest thing to a supervision log that currently exists. It needs SharePoint Advanced Management or a Copilot licence.

Tip: Write those four answers for one agent this month. Not all of them. The exercise is the point, and the first one takes an hour.

The part I wouldn’t build on

There’s a lesson in something that happened in the last fortnight, and it’s the reason an AI governance framework built around today’s feature list ages badly. Keep yours made of questions instead.

In July, Microsoft released a control that let administrators exclude up to 1,000 domains from Copilot’s web grounding, so it wouldn’t draw on sources you’d ruled out. Sensible, and exactly the kind of thing a compliance manager writes into a control register.

On 7 August, Microsoft published a post titled “Update: Domain Exclusion for Microsoft 365 Copilot”, and trade coverage reported the feature had been pulled. As I write this, more than a week later, Microsoft’s own documentation still describes it as available and carries no notice at all.

I’m not making a point about Microsoft, who ship more useful governance tooling than anyone else in this space. The point’s narrower and it applies to every vendor: a control that exists in a product roadmap isn’t the same as a control you can rely on, and the documentation isn’t always the truth. Check your own tenant. Then write your rules so they survive the tooling changing underneath them.

The rest of what’s available is worth knowing about, with the same caveat. Microsoft Agent 365 became generally available in May and gives you a single registry of every agent running in your tenant. The admin centre dashboard that sits on top of it? Still in preview. Purview data loss prevention can stop external email being used as grounding data in Copilot responses, which is a direct answer to prompt injection, and it’s in preview too, with general availability not expected until early 2027.

Useful, all of it. None of it finished…

And there’s a cost dimension nobody mentions in the sales conversation. Agent usage is increasingly billed by consumption rather than per seat, so somebody in your firm needs a spending limit and an alert against it, the same way you wouldn’t let a contractor bill unlimited hours without a purchase order.

The question to take to your next risk committee

Not “should we use AI”. That one’s settled, and the broader security picture around it is a separate conversation we’ve had before.

The question is this: for every automated process now running in this firm, whose name is against it, and what’s it allowed to do without asking a person first?

If you can answer that for everything, you’re ahead of most of the licensees ASIC reviewed. If you can’t, the gap between what your software does and what your governance documents describe is the actual risk, and it isn’t a technology problem.

It’s a row missing from a schedule you already have.

If you’d rather not answer that question from memory, our automation team can go through your tenant, list every agent running in it, and put a named owner and a permitted-action line against each one. You’d get it back as a one-page schedule, in writing, in the shape your risk committee already reads.

IntuitiveIT_ITPortraits2671-YA-Headshot-noBG 100px margin top 2

About the author

Yener is the founder and Managing Director of Intuitive IT. Prior to running his own business Yener worked for a number of corporate organisations where he gained invaluable experience and skills, as well as an understanding of how IT can complement and improve business outcomes.