20 questions, answered in full.
- Questions, each answered on its own merits
- 20
- Sections of argument beneath them
- 114
- Numbered steps you can act on today
- 142
- Follow-on questions answered in full
- 100
Which of these did you come here with?
- THE FIELD, DEFINED
What is AI agent governance, and what does it actually require?
AI agent governanceWhat governance cannot reachAny agent that never routes through it — that is a discovery problem first
- INDIRECT INJECTION
How do you defend an AI agent against prompt injection?
Prompt injection defenceThe honest limitA phrasing nobody wrote a pattern for scores zero, and the rule never fires
- DEPLOYER OBLIGATIONS
What does the EU AI Act require of an organisation deploying AI agents?
The EU AI Act for agent deployersWhat no tool can do for youClassify your risk tier, run the assessment, or notify the authority
- HARD BUDGETS
How do you stop AI agent spend running away?
LLM cost controlThe cost of a hard ceilingOne potentially billable egress: no retry, no failover on that call
- LEAST PRIVILEGE
How should you model what an AI agent is allowed to do?
The agent permissions modelWhat this layer cannot seeArgument values. Refunds over £200 is a policy, not a permission
- TAMPER EVIDENCE
What counts as audit evidence for an AI agent’s actions?
Audit evidence for agent actionsThe default, stated plainlyUnkeyed, a rewrite that recomputes every hash verifies clean
- TOOL SURFACE
How do you secure Model Context Protocol tool servers?
MCP tool server securityWhat is withheld rather than inspectedImage, audio, blob and resource content, after the tool has already run
- COVERAGE FIRST
How do you find AI use that is not going through your controls?
Shadow AI discoveryHow current a finding isExactly as current as the export it was computed from
- THE WHOLE SURFACE
How do you secure an AI agent?
AI agent securityWhat none of it reachesAn agent that calls a provider directly, and any media it sends
- THE REQUEST PATH
How should an LLM gateway be architected?
LLM gateway architectureThe topology this assumesOne process and one write path; no multi-replica or high-availability claim
- TWO DISCIPLINES
Do I need agent observability or governance, or both?
Observability and governanceWhat neither reachesAn agent that routes through neither, and the model’s hidden reasoning
- WHERE IT RUNS
Should AI governance run in my own network?
Self-hosted or hosted governanceWhat self-hosting does not settleSupport access, incident handling and evaluation terms are still a legal question
- WHEN IT GOES WRONG
What do you do when an agent does something it should not have?
AI agent incident responseThe limit of erasureIt reaches the live database; snapshots and some tables are outside it
- INTERSECTION
How should one agent be allowed to ask another for something?
Agent-to-agent delegationWhat intersection does not boundWhy the upstream agent asked — a legitimate grant, exercised for an injected reason
- RESIDENCY
How do you keep agent traffic inside a jurisdiction?
LLM data residencyThe assertion nobody can verifyNo control can prove where a vendor actually served a request
- PROCUREMENT
What should you ask an AI vendor?
The AI vendor questionnaireWhat this exercise is notA questionnaire is a filter; it does not replace testing the product yourself
- RISK, MEASURED
How do you decide which agents are risky?
Measuring AI agent riskWhat the tier does not doIt is not a policy-scope dimension; rules bind on agent id, team and tag
- TESTABLE RULES
How do you express an AI policy so it can be tested?
Policy as code for AIWhat a compiled artefact is notA policy exported to another engine covers matching, not the enforcement around it
- PROTOTYPE TO PRODUCTION
How do you take an agent from prototype to governed production?
Agent onboardingWhat a readiness check cannot tell youRelease provenance, independent testing, legal approval or your integration matrix
- THE GAP
Why don’t existing API controls work for agents?
Why agents need different controlsWhat reusing the stack cannot fixAn agent that never routes through any of it
100 narrower questions, and where each is answered.
AI agent governance
- How is AI agent governance different from AI governance?
- Do we need agent governance if we already have an LLM gateway?
- Where should a programme start if the estate is already running?
- What does a governance layer genuinely evidence for an auditor?
- Is a governance product a substitute for certification?
Prompt injection defence
The EU AI Act for agent deployers
LLM cost control
The agent permissions model
- Why should delegation intersect instead of taking the union?
- What happens when one role allows an action and another denies it?
- Can a permission depend on an argument value, like a refund over £200?
- Should an agent inherit the permissions of the person it acts for?
- How do you stop granted permissions accumulating over time?
Audit evidence for agent actions
MCP tool server security
- Is filtering the MCP tool list enough to control what an agent can call?
- How do you defend against a tool server changing its own descriptions?
- What happens to a tool result that cannot be fully inspected?
- Why is registering an MCP server a privileged action?
- Does governing MCP cover a developer’s coding assistant?
Shadow AI discovery
AI agent security
LLM gateway architecture
Observability and governance
Self-hosted or hosted governance
AI agent incident response
- Does a kill switch stop a request that has already been sent to the provider?
- How do you tell whether a policy was actually enforcing at the time?
- What should be preserved before restoring from a backup?
- Can you erase one person’s data from the record after an incident?
- What happens if the audit chain itself is found to be broken?
Agent-to-agent delegation
LLM data residency
- Why three separate flags instead of one residency setting?
- What happens when no provider satisfies an agent’s data policy?
- Can the gateway prove that a provider actually served from the declared region?
- Does an anchor published outside our network create a data transfer?
- What does a retention period actually cover?
The AI vendor questionnaire
Measuring AI agent risk
Policy as code for AI
Agent onboarding
Why agents need different controls
If the question that would decide it for you is not on that list, that is the more interesting question and it is the one worth sending.
Ask it directlyNone of the 20 is your question?
Write to hello@tenhaw.com with what your agents do, which providers they call and what would have to be true for you to put something in front of them. James Rooney replies. You will get a straight answer about whether Token Observe fits, including when it does not.
no form · no qualification step · no sales desk · the other three ways in