Back to Blog

    Nine Controls Every AI Rollout Needs

    Research 4 min readBy Drew Rutter · October 3, 2026
    Share

    There is one test we apply to every control in an AI rollout: could you show an auditor the evidence without having to ask the AI vendor for it?

    That one question rules out controls that exist only as policy documents, and assurances that live in a vendor's console you cannot export. It also reflects where buyers already are: in Deloitte's survey of 3,235 leaders, 74% expect at least moderate use of AI agents by 2027, while only 21% report a mature governance model for them. The gap between those two numbers is where incidents and audit findings come from.

    These nine controls apply regardless of which deployment pattern an organization chooses: desktop assistants, embedded SaaS agents, custom builds or a governed platform.

    The nine

    Each control below comes with a minimum bar, the level we score against in client reviews. The bar asks for evidence that the control works, rather than a policy document saying it should.

    1. Inventory. One registry of agents, plugins, connectors and recurring tasks. Every entry has an owner, a purpose, a lifecycle state and an expiry. If you cannot count your agents, none of the other controls can be scoped.

    2. Identity. People reach AI tools through SSO and are deprovisioned automatically. Agents run under their own scoped, revocable credentials rather than a borrowed login or a shared API key, and no secrets live in config files.

    3. Least privilege on tools. Access is granted per tool or capability rather than per server, read-only by default, with write and delete actions granted by role. A connector that can refund a customer needs a higher bar than one that can look up a balance.

    4. Enforcement outside the model. Policy is checked by deterministic code before an action runs, and risky actions fail closed when the check cannot run. Prompt injection cannot be fully patched, so the gate has to hold even when the model is talked into something.

    5. Human approval gates. Defined classes of action always require a person: payments, external sends, deletions and production changes at minimum. The approval is enforced by the system and recorded, including who approved.

    6. Audit trail. A tamper-evident record of what each agent saw, decided and did, exportable into your own retention and eDiscovery tooling. Records that exist only in a vendor console fail the auditor test by definition.

    7. Supply chain review. Skills, plugins, hooks and MCP servers are reviewed by someone accountable before staff can install them, distributed from a private source, with signed or pinned versions. A marketplace that auto-pushes updates is part of your attack surface.

    8. Kill switch and cost ceiling. You can stop a specific agent, connector or scheduled task across the organization within the hour, and budgets are capped by group or workflow with alerts before the limit. Both need to be tested in practice rather than assumed.

    9. Permission-aware retrieval. When AI tools search company knowledge, they respect the access rights of the person asking. Access metadata is captured when content is indexed, the permission filter runs inside the query, and permission changes take effect without re-indexing.

    Where to start

    Most organizations score lowest on inventory and identity, and that ordering is convenient, because every other control depends on those two. You cannot apply least privilege to connectors you have not found, and you cannot write an audit trail for an agent that has no identity of its own.

    Regulation adds a deadline without removing the work. The EU Digital Omnibus, in force since 27 July 2026, defers high-risk obligations for stand-alone systems to December 2027 and for AI embedded in regulated products to August 2028, while transparency obligations have applied since August 2026. For US firms with EU exposure, we would use the extra time to build controls 1, 5 and 6 properly.

    If you want to know where you stand today, we published a nine-control self-assessment: eighteen questions, about five minutes, scored instantly with no email required. It will show you your two weakest controls and the first step for each.

    The full framework, including what each control looks like in practice and the evidence bar we score against, is in our white paper, Deploying AI at Scale.