🤖 AI Summary
This study addresses the challenge of translating high-level governance standards into enforceable runtime safeguards for agentic AI systems, whose multi-step external actions complicate direct application of conventional norms. To bridge this gap, the authors propose a hierarchical translation framework that systematically maps governance objectives from standards such as ISO/IEC and NIST across four levels: governance goals, design-time constraints, runtime mediators, and assurance feedback. The framework explicitly distinguishes governance intent, technical controls, runtime protections, and evidentiary assurance, introducing control tuples and runtime executability criteria to guide the appropriate architectural placement of safeguards. Validation through a procurement agent case study demonstrates that only observable, deterministic, and time-sensitive controls are suitable for runtime enforcement, effectively reconciling normative requirements with practical system implementation.
📝 Abstract
Agentic AI systems plan, use tools, maintain state, and produce multi-step trajectories with external effects. Those properties create a governance problem that differs materially from single-turn generative AI: important risks emerge dur- ing execution, not only at model development or deployment time. Governance standards such as ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 42005, ISO/IEC 5338, ISO/IEC 38507, and the NIST AI Risk Management Framework are therefore highly relevant to agentic AI, but they do not by themselves yield implementable runtime guardrails. This paper proposes a layered translation method that connects standards-derived governance objectives to four control layers: governance objectives, design- time constraints, runtime mediation, and assurance feedback. It distinguishes governance objectives, technical controls, runtime guardrails, and assurance evidence; introduces a control tuple and runtime-enforceability rubric for layer assignment; and demonstrates the method in a procurement-agent case study. The central claim is modest: standards should guide control placement across architecture, runtime policy, human escalation, and audit, while runtime guardrails are reserved for controls that are observable, determinate, and time-sensitive enough to justify execution-time intervention.