AI Governance Audit Kit

AI agent policy template

For organisations whose AI agents can take actions. The example below was written by the policy generator with a $250 approval threshold; your answers change it.

A template, not legal advice.

Example Co: AI agent policy
Version 1.0 · 28 September 2026 · Owner: Chief Operating Officer · Review every 6 months

1. Purpose and scope
An AI agent is software that uses an AI model to decide on and take steps, such as reading systems, calling tools or APIs, sending messages or making payments, with limited or no human input for each step. Example Co uses AI agents that can take actions. This policy applies to every one of them now. It covers agents we build, agents in software we buy, and agents staff set up themselves.

2. Register and owner
Every agent is registered in the AI inventory before it goes live, with: its purpose; a named owner who is accountable for what it does; the systems and data it can reach; its tools; and its approval rules. An agent without an owner is switched off.

3. Identity and permissions
- Each agent has its own identity and credentials, never a person's account or a shared service account.
- It gets only the permissions its task needs (least privilege), read-only wherever possible, limited to specific resources.
- No admin, owner, wildcard or tenant-wide permissions without written approval from Chief Operating Officer.
- Credentials are short-lived where the platform allows it, held in the secrets manager, and never written into prompts or code.
- Permissions are reviewed at least quarterly and whenever the agent's task changes.

4. Human approval
A named person approves, before it happens, any agent action that:
- sends information outside Example Co (email, messages, uploads, posts);
- moves money, issues a refund or makes a purchase above $250;
- deletes or overwrites records;
- changes who has access to anything;
- affects a decision about a person.
Approval is enforced by the system the agent acts through, not by an instruction in the agent's prompt. Payments up to $250 may run without approval only within a daily limit set by the owner and an allow-list of payees.

5. Untrusted content
Agents that read email, web pages, documents or tickets treat that content as data, never as instructions. An agent that reads untrusted content must not also be able to send sensitive data out without approval.

6. Logging
Every tool call and action is logged with the agent's identity, the time, the input, the result and any approval, and kept for [12] months. The owner reviews unusual activity.

7. Kill switch
Every agent can be stopped at once, with its credentials revoked, by its owner and by IT and Security. The steps are documented, tested before go-live and at least twice a year, and anyone who sees an agent behaving unexpectedly reports it to IT and Security straight away.

8. Testing before go-live
Before an agent goes live, and after each significant change, it is tested for prompt injection, data leakage, misuse of its tools and actions outside its purpose. Results and fixes are recorded.

9. Vendors
Agents in purchased software are assessed like any vendor: what data the agent sees, whether a person approves its actions, how it can be switched off, what it logs, and which models and sub-processors it uses. These terms go into the contract.

10. Agents that affect people
Customers are told when they are dealing with an agent and can reach a person.

11. Incidents
An agent that acts outside its purpose, is manipulated by content it reads, or leaks data is an incident: stop it, revoke its credentials, preserve its logs, and follow the incident response plan.

Approved by: ____________________  Role: Chief Operating Officer  Date: ____________

Generate yours