Leanpub Header

Skip to main content

Runtime AI Governance

A Practitioner’s Playbook for Governing Agentic AI Systems

Runtime AI Governance
This book is 95% completeLast updated on 2026-08-19

AI governance changes when AI stops merely producing answers and begins taking action. Runtime AI Governance provides the architecture, controls, evidence and assurance methods practitioners need to govern agentic AI while consequential actions are still observable, interruptible and accountable.

Minimum price

$7.99

$9.99

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
About

About

About the Book

Runtime AI Governance - Second Edition (August 2026)

AI governance changes when AI stops merely producing answers and begins taking action.

Most governance programmes were designed around models, assessments, approvals and periodic review. Agentic AI creates a different operating problem. An autonomous system can retrieve information, invoke tools, communicate externally, change records, delegate work and trigger downstream actions before a human has an opportunity to review the outcome.

Runtime AI Governance: A Practitioner’s Playbook for Governing Agentic AI Systems provides a practical architecture for governing that execution layer. It shows how approved governance intent can become runtime controls, observable decisions, human intervention points and reconstructable evidence across the full agent action path.

What is enhanced in the Second Edition

The Second Edition expands the book from 10 to 15 chapters and adds dedicated treatment of autonomy authorisation, responsibility and liability across the agent chain and third-party agent procurement. It deepens the runtime control architecture across tools and connectors, memory, fail-open, fail-closed and degraded modes, supervision effectiveness and shared-dependency blast radius.

The framework bridge has also been rebuilt around reusable evidence and explicit source status. A new regulated-sector chapter is led by the NovaCred financial-services case, with healthcare and public-sector applications. The control-assurance method now separates design adequacy from operating effectiveness and adds sampling, negative testing, findings, remediation and retest. The edition also introduces implementation-ready assets including the dual-view reference architecture, a 120-day build plan, a governance-function operating model and field-level evidence specifications.

Inside the book

Chapter 1 — The Object Changed
Chapter 2 — Where You Are Now
Chapter 3 — Agent Identity Is the New Perimeter
Chapter 4 — Permission Is Not Intent
Chapter 5 — Governance Runs, It Does Not Review
Chapter 6 — Humans Move Up the Stack
Chapter 7 — Accountability Does Not Survive the Handoff
Chapter 8 — Authorising Autonomy
Chapter 9 — Responsibility and Liability Across the Agent Chain
Chapter 10 — Third-Party Agents and Procurement
Chapter 11 — The Framework Bridge
Chapter 12 — Runtime Governance in Regulated Sectors
Chapter 13 — Assuring the Control Plane
Chapter 14 — Building the Runtime Governance Stack
Chapter 15 — Building the Governance Function

Using the continuing NovaCred case, the book translates governance concepts into concrete patterns, control requirements and assurance tests. Readers see how to govern agent identity, delegated authority, purpose, tools and connectors, runtime policy decisions, human supervision, handoffs, vendor boundaries, degraded operating modes and the evidence needed to prove that consequential actions were governed.

The book is written for AI governance leaders, risk and compliance professionals, security and platform architects, enterprise architects, technology executives, internal audit and assurance teams and practitioners responsible for deploying agentic AI into consequential business processes.

The central question is no longer only whether an AI system was approved. It is whether the organisation can govern the action before consequence.

Author

About the Author

Srinivas Bommena

Srinivas is a Generative AI Practitioner and Educator specializing in the architectural design and rigorous evaluation of LLM-powered applications. With deep experience in developing multi-agent frameworks and hybrid RAG architectures, he focus on bridging the gap between experimental AI and production-ready systems.

He is the creator of popular technical practice tests on Udemy, including the AWS Certified GenAI Developer - Professional series, and have developed comprehensive frameworks for AI project estimation and compliance. His work frequently involves industry-leading evaluation tools such as RAGAS, Giskard, and Guardrails.ai.

Driven by the mission to help IT professionals navigate the "mindset shift" required for the AI era, Srinivas provides systematic, data-driven methodologies for building AI that is not only innovative but reliable and compliant with emerging standards like the EU AI Act.

Contents

Table of Contents

  • A Letter Before You Read
  • How to Use This Book
  • PART I — The Shift
    • Chapter 1 — The Object Changed
    • Chapter 2 — Where You Are Now
  • PART II — Five Runtime Dimensions
    • Chapter 3 — Agent Identity Is the New Perimeter
    • Chapter 4 — Permission Is Not Intent
    • Chapter 5 — Governance Runs, It Does Not Review
    • Chapter 6 — Humans Move Up the Stack
    • Chapter 7 — Accountability Does Not Survive the Handoff
  • PART III — Decisions Governance Owns
    • Chapter 8 — Authorising Autonomy
    • Chapter 9 — Responsibility and Liability Across the Agent Chain
    • Chapter 10 — Third-Party Agents and Procurement
  • PART IV — Proving and Operating It
    • Chapter 11 — The Framework Bridge
    • Chapter 12 — Runtime Governance in Regulated Sectors
    • Chapter 13 — Assuring the Control Plane
    • Chapter 14 — Building the Runtime Governance Stack
    • Chapter 15 — Building the Governance Function
  • APPENDICES
    • Appendix A — Runtime Governance Pattern Library
    • Appendix B — Framework Crosswalk
    • Appendix C — NovaCred Case Study Summary
    • Appendix D — Glossary
    • Appendix E — Evidence Specification and Control Requirements
  • Chapter 1 — The Object Changed Why governing actions is different from governing artifacts
  • Chapter 2 — From Approval to Supervision The architectural evolution of AI governance
  • Chapter 3 — Agent Identity Is the New Perimeter Dimension 1: Knowing who is acting
  • Chapter 4 — Permission Is Not Intent Governing what the agent means, not just what it can do
  • Chapter 5 — Governance Runs, It Does Not Review Dimension 3: Runtime enforcement architecture
  • Chapter 6 — Humans Move Up the Stack Dimension 4: From human-in-the-loop to human-on-the-loop
  • Chapter 7 — Accountability Does Not Survive the Handoff Dimension 5: Preserving ownership across agents, tools, vendors, and workflows
  • Chapter 8 — The Framework Bridge Mapping runtime governance artifacts to ISO 42001, NIST AI RMF, EU AI Act, Singapore MGF, OWASP, and NIST AI Agent Standards
  • Chapter 9 — Building the Runtime Governance Stack The reference architecture for governing agentic AI in production
  • Chapter 10 — The Operating Model Turning runtime governance into repeatable enterprise practice
Appendices
  • Appendix A — Runtime Governance Pattern Library
  • Appendix B — Framework Crosswalk
  • Appendix C — NovaCred Case Study Summary
  • Appendix D — Glossary

Get the free sample chapters

Click the buttons to get the free sample in PDF or EPUB, or read the sample online here

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub