Agentic AI Controls

Reviews and proposes controls for an agentic AI use case (an AI system that selects actions, calls tools, reads or writes systems of record, or operates with autonomy beyond single-turn generation) in a regulated financial-services firm. Output names the agent's scope and authority statement, the architecture and tool inventory with permissions and blast radius, the identity and authorisation posture, the human oversight points with effective oversight evidence, the prompt-injection-via-tool-output and tool-misuse threat assessment, the kill-switch and rollback procedures with drill evidence, the logging and audit posture, the incident response with regulator-notification triggers, the residual risk with accepted owners, and the recommended owner actions. Designed for second-line review of agents that book actions in real systems, not chat-only assistants. Best for: - A first-line owner has built or is building an agentic system that calls tools, reads from systems of record, or executes actions, and second-l

anotb a3ba136 15 files · 248.9 KB Updated

File contents

anotb/second-line-financial-services/tree/main/plugins/capability-plugins/ai-governance-model-risk/skills/agentic-ai-controls commit a3ba1365ca

Frequently asked questions

npx skillmds@latest add anotb/agentic-ai-controls