Free resource, agent governance
Who controls your agents?
Forty yes-or-no checks across eight areas to find out whether your AI agents have someone deciding what they may do, something watching them while they operate, and a record proving what they did. It takes an afternoon and needs no new tooling.
Preview
What you will receive
A ten-page PDF, ready to print or hand out by area: a cover with the scoring, eight areas of five checks each, and what to do with the result.

Forty yes-or-no checks
No partial credit: if you have to explain it, it is a no. Tick, count and read the score.
How to check each one
Every check comes with the concrete test that answers it in minutes, without new tooling.
Anchored in real frameworks
OWASP LLM Security and Governance Checklist, Agent Control Standard, OWASP Agentic Top 10 and Articles 9, 12 and 14 of the EU AI Act.
A score that says where to start
Three bands, each with its next action, from inventory to continuous validation.
Sample
This is what the checks look like
The full area 1 before we ask for your email. It is the exact format of the other seven.
Area 1
Inventory and ownership
Do you know how many AI systems run in your company and who answers for each one?
0 / 5
OWASP Governance Checklist, inventory and governance areas. ISO/IEC 42001, context and roles. EU AI Act, Article 9.
What is inside
Eight areas, forty checks
It walks the three layers of operational governance: decide, watch and prove. Each area answers a question a CTO or a CISO asks in the first week with an agent in production.
1. Inventory and ownership
Do you know how many AI systems run in your company and who answers for each one?
2. Policy and autonomy limits
Is it written down what an agent may decide on its own and what it may not?
3. Tool permissions
Do your agents act with their own credentials, and only the ones they need?
4. Human oversight
Is there a person before every action that cannot be undone?
5. Guardian and runtime controls
Is there something outside the agent deciding on each action before it happens?
6. Data and sources
Do you control what the agent may read and who may write to what it reads?
7. Evidence and traceability
Could you reconstruct tomorrow what an agent did today, and why?
8. Continuous validation and regulation
Is the coverage of your controls measured, or only declared?
FAQ
Frequently asked questions
Who is this checklist for?
Whoever answers for an AI agent in production or is about to put one there: CTO, CISO, platform or data lead. You do not need to be a security expert; you need to be able to look at the agent's configuration and ask whoever operates it.
How is it different from the OWASP LLM Top 10 checklist?
The Top 10 is a list of technical risks for whoever builds or audits the system. This one is about control: who decides what the agent may do, how it is watched and what evidence it leaves. They complement each other; if you run an agent, you need both.
How long does it take?
An afternoon. Every check comes with the test that answers it in minutes. What takes longest is not the checklist but finding the person who has the answer, and that is already a result.
Which frameworks is it based on?
The OWASP LLM Security and Governance Checklist, the Agent Control Standard from the OWASP GenAI Security Project, the OWASP Top 10 for Agentic Applications and Articles 9, 12 and 14 of Regulation (EU) 2024/1689. It also cites ISO/IEC 42001, NIS2 and OCSF where they apply.
Does it work if a vendor built my agent?
Yes, and that is where it is needed most. Half the checks are about what surrounds the agent: inventory, permissions, approvals and logs. That is yours even if the agent is not.
What do I do with the result?
Start with the area with the most noes. Turn every no into a task with an owner and a date. If you want us to walk it with you, the KAIX LABS control assessment applies this checklist to your system, with a fixed scope and price.