Quaintitative

Agentic AI

Agentic AI risk management and runtime governance

AI that acts, not just answers, has to be governed while it runs, not only when it is approved.

An AI agent does not just produce an output. It takes actions, uses tools, reads and writes to real systems, and chains several steps towards a goal, with some autonomy over how it gets there. That is what makes agents useful, and it is also what changes the risk. A model that writes a paragraph can be wrong. An agent that can move money, send a message, or change a record can be wrong and act on it, several times, before anyone looks.

So the usual model of governance, approve it once before deployment and review it now and then, does not hold for agents. The risk is not in a single output you can inspect; it is in the sequence of actions the agent takes while it runs, which you did not see in advance. Governing agentic AI means governing it at runtime: knowing what it is doing as it does it, authorising it continuously rather than once, checking its actions against policy in the moment, watching for drift in how it behaves, and being able to contain it when it steps out of bounds.

I developed the MAS AI Risk Management Guidelines (AIRG) which covers risk management for Agentic AI, co-authored a peer-reviewed paper on scalable runtime governance for agentic AI in financial services, and contributed to MAS's Safeguards for Agentic Finance at Runtime (SAFR). I now work on this independently. These pages are the short version; the ebook and the paper carry the detail.

Start here

Go deeper

I am publishing more on AI risk management in the coming weeks. Subscribe to get it, and future updates on agentic AI governance.

Subscribe for updates