Towards Agentic AI Governance: A Preliminary Assessment
Source: arXiv:2607.07612 · Published 2026-07-08 · By Mubarak Raji, Masooda Bashir
TL;DR
This paper addresses the emerging challenge of governing agentic AI systems—autonomous AI entities capable of independently planning and executing complex tasks with minimal human intervention. It situates agentic AI as the next evolutionary stage beyond generative AI and traditional AI, characterized by features such as adaptability, autonomy, multi-agent coordination, and temporal coherence. The authors present a comprehensive systematic review of the scholarly literature on governance approaches specific to agentic AI, filling a critical gap since no dedicated frameworks existed except the recent Singapore Model AI Governance Framework (MGF) for agentic AI. The review synthesizes definitional ambiguities, ethical and legal accountability issues under the principal-agent model, privacy concerns due to the agent’s persistent data usage, and stakeholder roles. It culminates in preliminary governance priorities emphasizing risk assessment, human accountability, technical safeguards, and user responsibility. This foundational assessment aims to guide future policy, research, and responsible deployment of agentic AI.
Key findings
- Agentic AI adoption surged from ~11% in Q1 2025 to ~42% by Q3 2025 among organizations (KPMG 2025).
- Agentic AI market valuation expected to grow from approximately USD 4.81 billion in 2024 to USD 7.06 billion in 2025, with a forecast of USD 93.2 billion by 2032 (MarketsandMarkets).
- Identified key unique features of agentic AI include adaptability, autonomy, goal complexity, environmental interaction, learning capability, workflow optimization, multi-agent systems, and temporal coherence (Table 2).
- Governance literature shows confusion and lack of consensus on agentic AI definition and classification, leading to governance ambiguity.
- Legal scholarship suggests current principal-agent law insufficient for AI agents due to information asymmetry, unclear authority scope, and loyalty issues, recommending amendments.
- The Singapore Model AI Governance Framework released Jan 2026 is the only formal governance framework explicitly targeting agentic AI, emphasizing human oversight and accountability.
- Privacy challenges arise from agentic AI’s data retention, reuse, and learning capacities, highlighting regulatory gaps as traditional data privacy laws focus mainly on data collection.
- The EU AI Act, while foundational, is inadequate to address agentic AI risks due to definitional and oversight ambiguities and the autonomous, evolving nature of these systems.
Threat model
Not applicable; this is a governance and policy-focused literature review rather than a security threat modeling paper.
Methodology — deep read
The authors conducted a systematic literature review focusing on peer-reviewed scholarly work published between 2020 and 2025. They searched major digital repositories—Google Scholar, ACM DL, SSRN, JSTOR, and AAAI—to capture relevant papers using keywords like "agentic AI governance" and "autonomous agentic AI governance." An initial corpus of over 3,000 papers was filtered down by excluding duplicates, works focused on non-software autonomous devices (e.g., autonomous vehicles, military drones), and those primarily on generative or traditional AI rather than agentic AI, resulting in 54 core publications. Further restricting to peer-reviewed articles led to a final set of 21 papers. The authors performed thematic analysis on these to identify governance-relevant patterns and recurring issues related to agentic AI. They categorized agentic AI governance discourse broadly along two dimensions: (1) autonomous goal-pursuit capability, including attributes like adaptability, autonomy, learning, and temporal coherence; and (2) moral agency, focusing on legal responsibility and accountability frameworks under common principal-agent law analogies. They also reviewed the first formal governance framework for agentic AI—the Singapore Agentic AI Model Governance Framework released in early 2026—and contrasted it with broader AI governance laws such as the EU AI Act. Privacy considerations were analyzed in light of existing data protection laws and their applicability or gaps with regard to agentic AI’s persistent learning and data activities. Overall, their method combines rigorous literature filtering with thematic synthesis reflecting interdisciplinary perspectives (engineering, law, policy, ethics). However, data on concrete governance efficacy or adversarial robustness is not evaluated, as this is a conceptual legal/policy literature review.
Technical innovations
- Systematic literature review specifically focused on the emerging field of agentic AI governance, distinct from broader AI governance.
- Identification and synthesis of unique agentic AI features like temporal coherence and multi-agent coordination relevant to governance design.
- First comprehensive analysis of the principal-agent legal framework’s applicability and limitations in governing AI agents.
- Assessment and critique of the nascent Singapore Agentic AI Model Governance Framework as the only agentic AI-specific governance model to date.
Limitations
- The review only includes peer-reviewed literature, potentially excluding cutting-edge reports or industry whitepapers relevant to agentic AI governance.
- Lacks empirical validation of governance models or metrics evaluating governance effectiveness in deployed agentic AI systems.
- Focuses on conceptual, legal, and policy literature without technical analysis of agentic AI system architectures or adversarial robustness.
- Excludes physical autonomous systems such as autonomous vehicles and drones, limiting scope to software-based agentic AI.
- Jurisdictional focus is skewed towards common law and Western frameworks, with limited discussion on civil law or other legal traditions.
Open questions / follow-ons
- How can existing legal frameworks for agency be amended or augmented to adequately address the complexity and autonomy of agentic AI?
- What empirical governance metrics and audit processes can validate the effectiveness of agentic AI frameworks like Singapore’s MGF?
- How to integrate technical safeguards, such as transparency and interpretability, with legal accountability to enable enforceable agentic AI governance?
- What roles should international organizations play in harmonizing agentic AI governance across jurisdictions given varying legal systems?
Why it matters for bot defense
For bot-defense and CAPTCHA practitioners, this paper underscores the increasing prominence of autonomous AI agents that can perform actions with minimal human oversight — a factor that dramatically shifts threat surfaces. Traditional bot detection assumes relatively simple scripted or model-limited automated behaviors, whereas agentic AI can autonomously adapt, learn, and execute complex adversarial workflows. Understanding the governance challenges—such as transparency, legal accountability, and oversight—is critical since these agents may exploit gaps in regulation or ethical safeguards to bypass security mechanisms, including CAPTCHAs. Agentic AI’s multi-agent coordination capabilities and temporal coherence also mean attacks could persist and evolve over longer time horizons. Practitioners should anticipate governance and policy developments like Singapore’s MGF that may mandate specific transparency or human-in-the-loop controls influencing how agentic AI systems can be deployed. This calls for research into bot defense systems that are resilient not only to reactive AI but proactive agentic AI capable of sophisticated, goal-driven fraud or abuse. Incorporating detection of agentic behavior patterns, assessing decision autonomy, and collaboration with legal/policy teams on compliance frameworks will be increasingly important.
Cite
@article{arxiv2607_07612,
title={ Towards Agentic AI Governance: A Preliminary Assessment },
author={ Mubarak Raji and Masooda Bashir },
journal={arXiv preprint arXiv:2607.07612},
year={ 2026 },
url={https://arxiv.org/abs/2607.07612}
}