Runtime AI Governance - Second Edition (August 2026)
AI governance changes when AI stops merely producing answers and begins taking action.
Most governance programmes were designed around models, assessments, approvals and periodic review. Agentic AI creates a different operating problem. An autonomous system can retrieve information, invoke tools, communicate externally, change records, delegate work and trigger downstream actions before a human has an opportunity to review the outcome.
Runtime AI Governance: A Practitioner’s Playbook for Governing Agentic AI Systems provides a practical architecture for governing that execution layer. It shows how approved governance intent can become runtime controls, observable decisions, human intervention points and reconstructable evidence across the full agent action path.
What is enhanced in the Second Edition
The Second Edition expands the book from 10 to 15 chapters and adds dedicated treatment of autonomy authorisation, responsibility and liability across the agent chain and third-party agent procurement. It deepens the runtime control architecture across tools and connectors, memory, fail-open, fail-closed and degraded modes, supervision effectiveness and shared-dependency blast radius.
The framework bridge has also been rebuilt around reusable evidence and explicit source status. A new regulated-sector chapter is led by the NovaCred financial-services case, with healthcare and public-sector applications. The control-assurance method now separates design adequacy from operating effectiveness and adds sampling, negative testing, findings, remediation and retest. The edition also introduces implementation-ready assets including the dual-view reference architecture, a 120-day build plan, a governance-function operating model and field-level evidence specifications.
Inside the book
Chapter 1 — The Object Changed
Chapter 2 — Where You Are Now
Chapter 3 — Agent Identity Is the New Perimeter
Chapter 4 — Permission Is Not Intent
Chapter 5 — Governance Runs, It Does Not Review
Chapter 6 — Humans Move Up the Stack
Chapter 7 — Accountability Does Not Survive the Handoff
Chapter 8 — Authorising Autonomy
Chapter 9 — Responsibility and Liability Across the Agent Chain
Chapter 10 — Third-Party Agents and Procurement
Chapter 11 — The Framework Bridge
Chapter 12 — Runtime Governance in Regulated Sectors
Chapter 13 — Assuring the Control Plane
Chapter 14 — Building the Runtime Governance Stack
Chapter 15 — Building the Governance Function
Using the continuing NovaCred case, the book translates governance concepts into concrete patterns, control requirements and assurance tests. Readers see how to govern agent identity, delegated authority, purpose, tools and connectors, runtime policy decisions, human supervision, handoffs, vendor boundaries, degraded operating modes and the evidence needed to prove that consequential actions were governed.
The book is written for AI governance leaders, risk and compliance professionals, security and platform architects, enterprise architects, technology executives, internal audit and assurance teams and practitioners responsible for deploying agentic AI into consequential business processes.
The central question is no longer only whether an AI system was approved. It is whether the organisation can govern the action before consequence.