Category definition · For boards, CIOs and risk officers
What is agentic AI, governed for production?
Agentic AI plans multi-step actions and executes across systems with reduced human intervention per step. In a regulated enterprise, every action carries an identity, a policy and an audit record, or it stays a demo, never production.
The definition
Autonomy is not the product. Governed autonomy is.
Agentic AI is autonomy scoped to task risk: an agent acts without approval on low-risk, reversible steps and stops for human sign-off on actions with financial, legal or safety consequence. The threshold is fixed before deployment, not discovered after an incident.
-
Not an agent framework
Frameworks orchestrate calls between tools and models. They do not carry accountability for the action taken. An orchestration library is a component, not an answer to who signs for the outcome.
-
Not a copilot
A copilot waits for a human at every step. An agent acts across steps without that pause, and the risk profile changes the moment it does. Governance has to move with it.
-
Not an automation script
Scripts execute a fixed path. Agents plan and adapt, so the audit trail has to capture a decision, not just an output. Logging the result is not enough once the path is not fixed.
Agentic AI is a workload. The governance, audit and runtime that make it defensible are the operating layer we already run. See the full category definition When to choose Hikari Blue, and when not to
Why now, why regulated enterprises first
Obligations attach to the action, not the model.
An agent that acts across systems with reduced human intervention crosses into Annex III high-risk territory faster than the model that serves it. The deployer, not the model vendor, carries the compliance obligation. Read more on what AI governance requires in production.
-
Article 9 · Risk management
Continuous risk management across the agent's lifecycle, not a one-time assessment before launch. Each new tool or permission an agent gains reopens the assessment.
-
Article 12 / 19 · Traceability
Which agent acted, under whose authorisation, on which data. A model API does not log this for a multi-step task. The containment layer around the agent does.
-
Article 14 · Human oversight
Oversight scoped by task risk, not blanket approval on every step. A named person can review, override or stop the agent before a consequential action ships.
Our newsroom tracks the enforcement timeline and the shift it forces. Govern the action, not the model The agent no one owns
The three properties
What qualifies a governed agent.
The same three properties that qualify our operating layer are the test we apply to every agent before it reaches production. Each one is architectural: it cannot be added later as a feature.
-
Identity by architecture
Every agent carries a verifiable identity and least-privilege permissions, assigned before production, not discovered in an incident review. No agent acts under a shared credential.
-
Containment by architecture
A kill switch at the infrastructure layer, under thirty seconds, without needing the agent's cooperation or a developer on call. Containment does not depend on the agent behaving.
-
Audit by architecture
Every action recorded immutably at the moment it happens. The evidence a regulator accepts, not documentation reconstructed after the fact once an incident forces the question.
The reference architecture behind identity, containment and audit is published. See the Engineering page See the operating layer these properties come from
Where it sits
The workload, and the layer that makes it defensible.
Agentic AI is the workload: autonomous action across systems. The AI operating layer is what makes that workload defensible, policy per task, audit trail per action, kill switch as architecture. One runs on top of the other, never instead of it.
-
The workload
An agent that plans, calls tools and acts across systems. It is judged on what it does, not on how well it demos.
-
The layer underneath
Governance, audit and runtime engineered between the model and the workflow. It decides which agent may act, and records that it did.
See how the practices behind this work engage. How we operate What is an AI operating layer
Direct answers
The questions senior buyers actually ask.
What is agentic AI, in practice?
Software that plans multi-step tasks, calls tools and acts across systems with reduced human intervention per step, not a chatbot answering one question. In a regulated enterprise, every action needs an identity, a policy and an audit record, or it is a demo, not a production agent.
How is agentic AI different from an AI operating layer?
Agentic AI is a class of workload: autonomous action across systems. The AI operating layer is the governance, audit and runtime that makes that workload defensible: policy per task, audit trail per action, kill switch as architecture. Agentic AI runs on the layer, not instead of it. What is an AI operating layer
Does agentic AI trigger the EU AI Act?
Often, yes. Agents taking consequential actions, credit, hiring, clinical, critical infrastructure, meet the Article 6 high-risk conditions under Annex III. The deployer carries the compliance obligation, not the model provider. We map your agents to risk tier before anything reaches production. See what AI governance requires
What happens when an agent fails or acts wrong?
It stops. Containment operates at the infrastructure layer, under thirty seconds, without needing the agent's cooperation. Every action up to that point sits in the immutable audit trail, so the incident review starts from evidence, not reconstruction.
For boards, CIOs and risk officers
See agentic AI against your own workflows.
Thirty minutes with a named partner. We map one agentic workflow you already run to the audit trail a regulator would ask for. You leave with the diagram, whether or not we ever work together.