Foundations
What is AI agent governance documentation?
The one honest, evidence-backed record that answers why you trusted an AI agent — built before it acts, not reconstructed afterwards.
The record you build before your compliance review — what it is, and what it is not.
Why it matters
A working agent on a good day shows you very little. The moment it can read data, take actions, and affect people, someone has to be able to answer why you trusted it. Governance documentation is the one honest, evidence-backed record that answers that question: who owns the agent, what it can reach, what was tested, what the model review found, who decided it could act, and how it is watched afterwards. It is coverage and evidence you can open and read — not a single readiness percentage that hides the four questions a number cannot answer.
What good looks like
One record per agent that a technical, business, security, or legal stakeholder can read in minutes: identity and ownership; purpose and scope; the data and actions the agent can reach; a quick-triage depth; governance-lens coverage; an evidence register; a control checklist; a test pack; a vendor and model review; an approval and decision record; and monitoring. Every part is traceable to its source, unknowns stay visible rather than being read as no, and on the decision to trust the agent the whole thing is frozen as a versioned compliance-readiness record.
What can go wrong
Trust rests on a screenshot and someone's memory. A readiness number stands in for the record and quietly papers over bad-day behaviour, data reach, wrong-answer handling, and accountability. Weeks later, when a stakeholder asks a direct question, the intent has to be reconstructed from a chat thread and only the original builder knows the details.
What AgentProof checks
AgentProof structures each module into one linkable record. Received is never quietly counted as accepted; an implemented control with no accepted evidence surfaces as needs-evidence; an unknown is never read as no. It maps documentation and evidence coverage against jurisdiction-aware lenses with no graded verdict. It provides compliance-readiness and documentation support — not legal advice, certification, audit assurance, or regulatory approval, and not a guarantee that any agent is safe or ready for production.
Key terms
The exact vocabulary this part of the record uses — grounded in the shipped product model.
- Estate view
- One inventory of every agent across every environment — the front door to the record.
- Quick triage
- A fast depth read (light / standard / enhanced / strict) that decides how much scrutiny an agent needs.
- Readiness score and status
- One labelled section of the record — never the headline that replaces it.
- Evidence register
- The one evidence store per agent where received is never quietly counted as accepted.
- Control checklist
- The guardrails an agent should have, mapped to the evidence that proves them.
- Test pack
- The seven agent-relevant checks, where a check never run is a visible gap.
- Vendor and model review
- The model, provider, and terms behind the agent, with what is known and still to verify.
- Approval and decision record
- Who decided the agent could act, on what basis, with what limits.
- Monitoring and reassessment
- How the record is kept alive after go-live and revisited when things change.
- Frozen compliance-readiness record
- The versioned, review-ready record captured on decision; a later reassessment mints a new version and leaves the old one untouched.
Keep reading
Build this record for your own agents
AgentProof turns each part of this into one documented, evidence-backed record — before your compliance review.
Frameworks referenced
The public frameworks AgentProof points you at
When your agent touches a high-impact area, AgentProof names the public framework you document against — you decide whether it applies to your use and arrange your own legal review where you judge it’s needed. This is documentation support, not legal advice, certification, or an audit.
| High-impact area | Public framework reference | In AgentProof |
|---|---|---|
| Prohibited practice | EU AI Act, Article 5 (prohibited AI practices) | Framework reference |
| High-impact use case | EU AI Act, Article 6 + Annex III (high-risk use cases) | Structured obligation |
| Biometric processing | EU AI Act, Annex III(1) + Article 5(1) (biometric ID / categorisation) | Framework reference |
| Health / medical | EU AI Act (safety component / medical devices) + GDPR Article 9 (health data) | Framework reference |
| Employment / worker management | EU AI Act, Annex III(4) (employment) + US EEOC guidance | Structured obligation |
| Education | EU AI Act, Annex III(3) (education / vocational training) | Framework reference |
| Access to essential services | EU AI Act, Annex III(5) (access to essential private/public services) | Framework reference |
| Credit / insurance / financial decisions | EU AI Act, Annex III(5)(b) (creditworthiness) + US CFPB guidance | Structured obligation |
| Law enforcement / migration / justice | EU AI Act, Annex III(6)-(8) (law enforcement, migration, justice) | Framework reference |
| Safety-critical / critical infrastructure | EU AI Act, Annex III(2) (critical infrastructure) + product-safety rules | Framework reference |
| Vulnerable persons | EU AI Act, Article 5(1)(b) (exploiting vulnerabilities) | Framework reference |
| Personal / special-category data | GDPR, Article 9 (special categories of personal data) | Framework reference |
| Transparency / human interaction | EU AI Act, Article 50 (transparency) | Structured obligation |
| Automated decisions / profiling | GDPR, Article 22 (automated individual decision-making / profiling) | Framework reference |
| Action-taking / connected-system permissions | OWASP GenAI/LLM (excessive agency) + least-privilege | Structured obligation |
| Sector / contractual / buyer-policy | Your organisation's own policy / contractual requirements | Structured obligation |
“Structured obligation” means AgentProof ships a documentation obligation you complete in the assessment; “framework reference” means AgentProof names the public framework for you to document against and self-assess. Neither is a legal determination.
Ready to build a compliance-readiness record for your own agent?
Request a compliance readiness pilot to apply this guidance to a real agent.
AgentProof builds a compliance-readiness record, not an official audit, and it does not speak on behalf of any vendor.