AI All-in-One series · Governance, risk & compliance

Agentic AI Governance, Risk & Compliance All-in-One by Kai London

When a system acts on its own, accountability does not disappear — it moves. This handbook sets out how to govern autonomous AI so that every consequential action has an owner, a control, a record and an answer for the auditor who arrives eighteen months later.

Available on Amazon.

What is inside

A governance operating model

Ownership, approval gates and escalation for agents, from use-case intake through to decommissioning.

The AI and agent register

What to record, who maintains it, and how it stays current when teams ship faster than governance meets.

Control design for autonomy

Preventive, detective and corrective controls mapped to the specific ways agents fail.

Risk assessment and classification

Assessing impact and autonomy level together, so oversight is proportionate rather than uniform.

Regulation in practice

The EU AI Act, ISO/IEC 42001 and the NIST AI RMF read as overlapping obligations, with the duplication removed.

Audit evidence and assurance

Logs, decision records and attestations that stand up to internal audit, a regulator or a customer's due diligence.

Who it is for: heads of AI governance, risk and compliance leaders, internal audit, CISOs, data protection officers, and the executives who sign the attestation.

EU AI ActISO/IEC 42001NIST AI RMFISO/IEC 27001DORA

When the machine acts, someone still answers. Governance decides who, before the incident does.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.