Skip to main content
Intelligence | May 12, 2026 | Microsoft Publishes Five-Level DDoS Resilience Maturity Framework for Consume...

WHITE PAPER · FRAMEWORK RESEARCH

Who Owns the Agent?

The Organizational Accountability Architecture That Existing Governance Frameworks Require But Do Not Implement at the Agent Level

Who it is for

Built for the people who must answer before deployment

CISO AND CTO

You need to answer the board's accountability question before the next agentic AI deployment. This paper gives you the three-layer governance architecture that makes that answer possible, built before the incident, not assembled under pressure during it.

SECURITY ARCHITECT

You need an organizational design framework to work against, not a policy checklist. This paper gives you a diagnostic, a risk proportionality model, and a pre-deployment gate you can enforce.

BOARD MEMBER

You need to understand what governance evidence you should be asking for. This paper shows you the three documents any board should be able to request for any deployed AI agent, and what it means when they cannot be produced.

The governance question

The audit trail is not the authorization record

The meeting had been going for forty minutes when the board chair held up a printout and asked a simple question. Three weeks earlier, the organization's AI agent had sent a draft contract amendment to an external counterparty. The agent had been configured to draft, not to send. The version it sent was not the current version.

The compliance team had logs. The security team had the audit record. The IT team had the agent configuration file. What none of them had was a document written before the incident that answered the chair's question: who in this organization authorized that agent to act, and how is that authorization documented?

Logging tells you what happened. It does not tell you who was responsible. Those are two different questions, and only one of them survives a board meeting.

Board question

Before any AI agent is deployed in your environment, does your organization have a formal record of what it was authorized to do, who made that authorization, and under what conditions that authorization must be reviewed?

White paper structure

Ten sections, one accountability test

01

The Question Nobody Has a Good Answer For

Eight named incidents. The gap between auditability and accountability.

02

Five Frameworks, Five Different Versions of the Same Gap

NIST AI RMF, EU AI Act, ISO 42001, CSA Agentic Profile, Microsoft. What each requires. What none of them specify.

03

The Intent Architecture Stack

Three layers. Context, Intent, and Governance. Each layer produces a document. Together they answer the board question.

04

The Diagnostic

Fifteen quick-scan questions. A full practitioner diagnostic for each layer. Designed for a 90-minute working session with the business unit that owns the agent.

05

Risk Proportionality

Not every agent needs the same documentation depth. Three risk tiers. A complete Tier 2 Intent Document template.

06

What Regulators Now Require

OCC, FINRA, Federal Reserve, FINMA. The shift from governance language to evidence language.

07

Where Most Organizations Are Right Now

Three stages. Accumulation, Recognition, Resolution. IBM's $670K shadow AI breach cost figure. The Agent Sprawl three-tier structure.

08

Applying the Framework in the Microsoft Environment

Microsoft Entra Agent ID, Purview, Agent 365, Copilot Studio. EchoLeak (CVE-2025-32711) and RoguePilot mapped to the Intent Architecture Stack.

09

Answering the Board Question

The three-layer documentation set. What each document must contain. The governance test each must pass.

10

What Good Looks Like

A Stage 3 organization in operational terms. The one test a mature governance program passes without preparation.

GET THE PAPER

Download the full white paper

Free to read and cite with attribution to Sougata Roy and sougataroy.com. No gate. No form.

Who Owns the Agent?

The Intent Architecture Stack · Framework White Paper v1.0 · May 2026

Ten sections. A complete diagnostic for all three governance layers. A Tier 2 Intent Document template. Named incident analysis across Air Canada, Meta, Upstart Holdings, Microsoft, AWS, and six others. Every statistic cited to a named primary source with a publication date.

PDF · Framework white paper · 10 sections · Full diagnostic · Intent Document template

Not legal advice. Views are my own.