Why Agentic AI Governance Must Be Built In From the Start
Summary
Kimchi argues that governance for agentic AI cannot be added after agents have entered production. Drawing on historical examples such as boiler inspections, seatbelts, motorcycle helmets, and cloud security, the article says safety systems typically follow technological adoption, and proposes building governance into agents from the beginning. It treats an agent as a workplace coworker: an agent needs an identity, scoped permissions, a defined operating context, activity records, and an offboarding process. The article contrasts a basic run of reasoning, decisions, execution, and output with a governed run that adds agent identity, inference controls, authority, secure execution, and evidence. Identity should establish who is acting, for whom, and in what session; inference controls should determine which models process data and where that data goes; and an authority layer should govern tools, MCP servers, repositories, credentials, network destinations, budgets, and approvals. Kimchi says policy enforcement must occur when actions happen, rather than relying on instructions not to perform a risky action. It recommends isolated cloud workspaces with task-scoped access, restricted networking, no inherited developer credentials, and kernel-level isolation, with environments periodically replaced to prevent hidden state from accumulating. Tamper-evident audit records should show who initiated a run, which agent and models acted, what tools and policies were involved, and why an action was allowed, denied, or escalated. The article also describes Kimchi’s SPIFFE/SPIRE-based workload identity, OpenAI-compatible hosted or self-hosted inference, governance perimeter, Remote Workspaces, and audit trail. It cites OWASP’s agentic application risks and phased EU AI Act obligations as reasons these foundations will become increasingly important, while presenting the piece as a case for building operational control before agents become embedded in critical work.