The Agentic AI Risk Register: What to Track Before You Deploy
Use an agentic AI risk register to set ownership, autonomy limits, approval thresholds, and evidence before deployment creates business exposure.
Tyson Martin
8/17/202610 min read


Agentic AI Risk Register: What to Track Before Deployment
An executive framework for approving autonomous AI with clear ownership, limits, and evidence.
An audit committee asks a simple question: who approved this AI agent to act without a person reviewing every step? If your answer is a policy, a vendor presentation, or a list of approved tools, you don't have enough.
Agentic AI combines large language models with permissions, tools, and the ability to act. An agentic AI risk register is a decision record, not a simple inventory.
It tracks what an agent can do, what could go wrong, who owns each risk, and what evidence shows the controls work. That record protects trust, valuation, regulatory standing, and enterprise customer confidence before deployment creates a problem.
TL;DR
Start with agentic AI systems that can affect money, customers, regulated decisions, sensitive data, or critical systems.
Record purpose, autonomy, permissions, data access, connected tools, business ownership, approval status, and evidence.
Set clear stop conditions. An agent shouldn’t create commitments, change critical records, or communicate externally without defined limits.
Treat vendor claims as inputs, not proof. Verify controls through contracts, testing, monitoring, and documented recovery.
Report business exposure, open exceptions, trends, owners, and decisions needed. Activity counts alone don’t show control.
Approve each use case, approve it with limits, delay it until gaps are fixed, or reject it.
Why an Agentic AI Risk Register Matters Before You Deploy
A chatbot usually responds to a prompt. Large language models can support planning, while an agent adds multi step execution. It can retrieve information, call tools, update records, and continue through several steps.
Conversational software is different from autonomous systems that act with limited intervention. You aren't only asking whether the model gives a reliable answer. With agentic AI, you're asking what happens when it takes an unsafe action with valid access.
An agent could approve a transaction, alter customer data, provision access, expose confidential information, or send an incorrect instruction to a customer. The risk grows when the agent has external reach, sensitive data, broad permissions, or no reliable human stop point.
This creates unresolved compliance risk for public companies and IPO-track businesses. The SEC's cybersecurity disclosure rules require timely disclosure of material cybersecurity incidents, while directors and executives face sharper questions about technology risk oversight. S-1 diligence teams, enterprise buyers, auditors, privacy regulators, and financial-services examiners also want evidence that management understands its exposure.
The register is not an inventory of AI tools. It isn't a technical bug log or a policy that sits unsigned in a folder. It is part of the company's governance structure, connecting each use case to a decision, an accountable owner, a risk tolerance, and proof.
Many organizations report agents created, tests completed, or policies issued. That shows activity. Decision-useful reporting answers a different question: what business exposure remains, who owns it, and what decision is required?


The nist ai rmf and ISO/IEC 42001 provide useful structures for managing AI risk. Each is a risk management framework, but your register should also reflect applicable SEC, privacy, financial-services, employment, and contractual obligations. The framework matters less than whether you can show how decisions were made.
What to Track in an AI Risk Register
Each record should be short enough for executives to understand and complete enough for outside scrutiny. For each agentic ai system, capture at minimum:
Agent name, business purpose, and accountable business owner
Model, provider, version, and connected vendors
Technical capabilities, multi step execution, and business authority
Data used, stored, transmitted, and retained
Tools, systems, APIs, and permissions
Affected customers, employees, partners, and other stakeholders
Risk rating, approval status, review date, and exception status
Controls, testing results, monitoring plan, and evidence location
The record should describe business impact, not only technical behavior. For agentic ai, "Can call the CRM API" is incomplete. "Can change customer payment details and trigger account communications" gives the board something it can govern.
Track the Agent's Purpose, Autonomy, and Decision Boundaries
Start with the task. What is the agent supposed to accomplish? What decisions may it make? What actions may it take without approval?
Ask whether it can create a financial commitment, change customer information, approve access, make a regulated decision, or send an external message. Record the systems it can reach and the point where a person must approve, pause, or stop the action. This is the human in the loop.
Your register should name prohibited actions, transaction or spending limits, escalation rules, and the person who owns the outcome. A business owner cannot accept a risk they don't understand, but someone must have the authority to accept, reduce, or reject it. Clarify who may approve or commit the company to reduce authorization risk.
A useful record distinguishes between assistance and authority. An agent that drafts a response is different from one that sends it. An agent that recommends an access change is different from one that approves it.
The board doesn't need every prompt. It needs to know where the agent's authority begins, where it ends, and who can stop it.
Track Identity, Access, Data, and Privacy Exposure
Record the agent's non human identity, credentials, privilege level, authentication method, and access review date. Note whether it uses customer data, employee information, financial records, health information, source code, or confidential business plans.
The control question is access control. The agent should have only the access required for its approved purpose. Separation of duties matters when one agent can request and approve the same action.
Capture retention periods, data location, cross-border transfers, model training use, and deletion terms as part of data risk management. Include prompt and output logging where appropriate, while respecting privacy and confidentiality requirements.
Runtime defense should restrict or block unsafe actions after deployment. Use it to limit sensitive operations, detect unusual behavior, and interrupt activity before it causes data leakage.
The executive question is direct: which critical systems and sensitive data could this agent affect if its access were misused? That answer should drive the risk rating, approval level, and review frequency.
Track Model, Prompt, Tool, and Third-Party Failure Modes
Your record should address hallucinations, unsafe recommendations, prompt injection, memory poisoning, jailbreaks, model drift, agentic drift, insecure tool calls, and excessive agency. Large language models can fail at the model level, while connected tools can create tool use risks. You don't need a technical essay. You need to know which failures could cause financial loss, customer harm, disclosure pressure, or operational disruption.
These concerns belong within ai security, which connects model, identity, data, and tool protections. Third party risks need equal attention. Record subcontractors, underlying model providers, hosting locations, service limits, change-notice terms, audit rights, data deletion, incident reporting, and exit support.
A vendor's assurance statement is not evidence by itself. Verify the claim through documentation, contract language, testing, monitoring, or compensating controls. Runtime defense can add live restrictions and monitoring when vendor assurances are incomplete.
Ask what happens when the provider changes the model, limits service, suffers an incident, or ends the product. Failures can propagate through connected tools and systems, creating cascading failures. Vendor dependence can create trust debt when the business adopts a capability before it understands how to exit.
Track Resilience, Human Oversight, and Incident Readiness
Record availability targets, fallback procedures, rate limits, rollback steps, kill-switch authority, incident contacts, and recovery needs. Together, these support operational resilience. Then test them.
Consider an agent sending incorrect instructions to customers, exposing confidential data, taking an unsafe action, or becoming unavailable during a critical process. Runtime defense should support rate limits, kill switches, and containment during live operation. Who notices first? Who stops the agent? Who decides whether to notify customers, regulators, investors, or the board?
Run a tabletop exercise with the CEO, legal, communications, security, compliance, technology leadership, and the business owner. The exercise should test security controls and produce:
A decision tree for containment and disclosure
A current contact list with named decision rights
An evidence checklist covering logs, approvals, actions, and audit trails
A communication plan for customers, employees, regulators, and investors
If nobody has tested the shutdown process, you don't know whether human oversight exists in practice.
Turn Agentic AI Risks Into Board Decisions and Approval Thresholds
A risk register becomes useful when it changes decisions. Apply four approval criteria to every high-impact agent:
Define what the agent can do, including its tools and limits.
Estimate the worst credible business impact.
Assign someone who can stop the agent or accept the risk.
Identify proof that the controls work before approval.
Score the use case in plain language. Use a consistent risk management framework for likelihood, business impact, autonomy, data sensitivity, external reach, and recovery difficulty. Low, medium, and high ratings work when definitions are clear and consistent.
Set escalation thresholds before a difficult case arrives. An agent should receive executive or board-level review when it can affect a critical system, make a regulated decision, access sensitive data, communicate externally, create material customer impact, or depend on a high-risk vendor. Review authorization risk closely when an agent can approve access, make commitments, or act without a clearly assigned decision-maker.
For high-impact agents, control effectiveness includes tested runtime defense, clear intervention points, and reliable recovery procedures. Reassess approval after a major incident, material system change, new vendor dependency, or evidence of agentic drift.
The board or audit committee should receive material risks, trends, open exceptions, owners, due dates, control effectiveness, and decisions needed. It doesn't need a dashboard full of green indicators.
Ask management:
Who owns AI risk across the company?
What happens when this agent is wrong?
Which human can stop it, and has that action been tested?
What evidence supports approval?
What risk are we accepting, and when will we review it?
Show What Good Evidence Looks Like
Evidence should survive review by an auditor, regulator, investor, or diligence team. Useful records include approved use cases, access reviews, large language models test results, red-team findings, human override tests, vendor terms, security controls, incident drill outputs, monitoring records, audit trails, exception approvals, and dated remediation proof.
For high-impact agents, evidence should also show that runtime defense works in production. Test live restrictions, monitoring, and intervention mechanisms rather than relying on design claims alone.
A completed training course doesn't prove an agent is controlled. A green dashboard doesn't prove risk is falling. An unsigned policy proves almost nothing.
The standard isn't perfect prediction. It is defensible oversight. You should be able to show the decision, the owner, the control, the exception, and the follow-up. That is actionable governance.
How to Use the Agentic AI Risk Register Before You Deploy
Use the register as a deployment gate, not a documentation exercise. Start with agents that have the greatest business reach. You don't need a perfect enterprise-wide inventory before making a sound first decision.
A practical sequence is:
Identify agents that can affect critical systems, sensitive data, customers, money, or external communications. Look for unapproved tools that may indicate shadow AI.
Map permissions, connected tools, data flows, retention, sensitive information, vendors, and human approval points. Apply data risk management throughout the process.
Test the most serious failure paths, including prompt injection, unsafe actions, incorrect outputs, data exposure, and shutdown. Confirm runtime defense is active before deployment, with restrictions on high-impact actions.
Assign named owners and close urgent control gaps.
Review the evidence with the right decision-makers.
Approve, approve with limits, delay, or reject the use case.
Monitor the approved agent against defined thresholds.
Run a Pre-Deployment Review With Named Decision Rights
The business owner defines the value and accepts operational risk within approved limits. Legal and compliance assess obligations. Security and privacy lead the ai security review of models, tools, identities, and data. Technology leadership confirms reliability and recovery. Executive leadership approves high-impact exceptions.
Write these roles down in a simple RACI or decision-rights model. This governance structure doesn't need to be elaborate. It needs to prevent the familiar failure where everyone participates, but nobody owns the decision.
For a public or pre-IPO company, unresolved exceptions should have an executive owner, a due date, a compensating control, and a clear escalation path. Unresolved regulatory or contractual gaps can create compliance risk. That record matters when the use case appears in an audit, diligence request, or board discussion.
Set Monitoring, Review, and Escalation After Approval
Approval is not the end of governance. Track failed actions, policy violations, unusual tool use, access changes, human overrides, customer complaints, incidents, and model or vendor changes. Use runtime defense for live detection and intervention. This supports operational resilience after deployment.
Set the review cycle according to risk and business change. Review sooner after a major model update, new data source, new tool connection, acquisition, material incident, or regulatory shift. Changes involving large language models or agentic drift also warrant renewed review.
After each material review, send a short recap:
Decisions made
Top risks and owners
Actions, dates, and proof of completion
Prioritize the First 90 Days Without Creating Compliance Theater
In the first 90 days, focus on the few agents with the greatest authority and business reach. Map their access, test their failure paths, assign owners, and bring unresolved exceptions to the right executive or board committee.
Track signals that show control, not busyness. Use runtime defense metrics for tested shutdown, privileged-access restriction, and recovery. Also track timely incident escalation and closure of high-risk vendor findings.
Don't create dozens of low-value metrics. Your board needs a small set of indicators tied to decisions. For practical questions to take into your next meeting, Download the AI Boardroom Question Pack.
Frequently Asked Questions
What is an agentic AI risk register?
An agentic AI risk register is a decision record for systems that can use tools, access data, and take actions with limited human intervention. It documents the agent's authority, risks, accountable owner, controls, approval status, and evidence.
What should an agentic AI risk register track?
Track the agent's purpose, autonomy, permissions, identity, data access, connected tools, vendors, affected stakeholders, failure modes, recovery procedures, and human approval points. Each record should also include a risk rating, named owner, review date, exceptions, and evidence that controls work.
When should an agent receive executive or board-level review?
Escalate an agent when it can affect critical systems, sensitive data, money, regulated decisions, customers, external communications, or material business commitments. Review is also appropriate when the agent depends on a high-risk vendor or lacks a clearly tested human stop point.
What evidence is needed before deployment?
Useful evidence includes approved use cases, access reviews, model and red-team testing, human override tests, vendor terms, monitoring records, audit trails, incident drills, and documented remediation. Vendor claims and completed training do not prove that the agent is controlled.
How often should an approved agent be reassessed?
Reassess according to the agent's risk and after a major model update, new data source, tool connection, vendor change, material incident, or regulatory shift. Review failed actions, unusual tool use, human overrides, customer complaints, and evidence of agentic drift during ongoing monitoring.
Conclusion
The register gives you more than a compliance record. It clarifies ownership, limits autonomy, surfaces trust debt early, and shows directors that management oversees AI with care.
Choose the highest-impact use case first. Document what it can do, name the accountable owner, set stop conditions, and require evidence before approval. If your board, audit committee, or leadership team has an oversight gap, Get Board-Ready on AI and Cyber Risk.
Tyson Martin is the executive public and pre-IPO companies in financial services, AI/data, SaaS, and cloud hire to make trust a measurable asset, one accountable answer to Is it secure? Is it resilient? Is the AI governed?
© 2026. All rights reserved.
Navigation
Free Resources
Contact


Stay ahead of your next board agenda
Sign up for Reports & Learnings From the Boardroom. Plain-English AI and cyber governance insights, biweekly. No pitch.
No spam. Unsubscribe anytime. · Or download the Director's AI Question Pack — 25 questions free
