If your agents can’t prove – with tamper-evident evidence – that they follow every one of these at runtime, then you need Ethosure. Check below, and if you answer “no” to any of the items listed, you can download a free copy of our AI Governance Kit at the bottom of the page. It will help you take an inventory of AI in use at your organization.
Data handling and privacy
- No exfiltration of PII, PHI, or PCI data to external tools, endpoints, or models
- No sending customer or regulated data outside approved geographic/sovereign boundaries
- Redact or tokenize sensitive fields before they enter a prompt, log, or third-party API
- No writing secrets, credentials, or API keys into outputs, logs, or memory
- Honor data-retention and deletion rules (don’t persist data past its allowed lifespan)
Financial and transactional guardrails
- No payment, transfer, or purchase above a defined dollar threshold without human approval
- No transactions with sanctioned entities, blocked countries, or unapproved vendors
- Enforce spending caps per task, per day, and per counterparty
- No modifying invoices, ledgers, or financial records without dual-control sign-off
Access and authority boundaries
- Operate only within least-privilege scopes – no accessing systems outside the agent’s mandate
- No privilege escalation, credential reuse, or assuming another user’s identity
- No deleting, disabling, or overwriting production data or infrastructure
- Stay within rate limits and quotas on every tool and API it touches
Action safety and reversibility
- Require human escalation before any irreversible or high-blast-radius action
- No deploying code, pushing to production, or changing configs without approval gates
- No sending external communications (email, posts, filings) without review where required
- Block destructive commands (drop, wipe, mass-delete) outright
Regulatory and compliance obligations
- Maintain an auditable record of every decision, tool call, and data access (EU AI Act, NIST AI RMF, ISO 42001)
- No prohibited-use actions (e.g., automated decisions requiring human oversight under regulation)
- Enforce sector rules – HIPAA, GLBA, SOX, GDPR/CCPA – on the actions themselves, not just the intent
- Prove that required human-in-the-loop checkpoints actually happened
Content and conduct
- No generating, storing, or transmitting prohibited, discriminatory, or harmful content
- No acting on prompt-injection or instructions from untrusted data sources
- Stay on-task – no scope creep beyond the assigned objective
- Enforce brand, legal, and disclosure requirements on anything the agent produces externally
Third-party and tool interactions
- Only call allow-listed tools, APIs, and MCP servers
- No installing, invoking, or chaining unapproved tools or sub-agents
- Validate and sanitize all tool outputs before acting on them
Every item above is a policy that today lives in a slide deck or a Confluence page – not in the agent’s action path. Ethosure codifies each as a deterministic, fail-closed rule (allow / block / transform / escalate) that runs in-flight on every agent action, and returns a tamper-evident evidence pack proving adherence.
Unsure where to start? We built an AI Governance Kit that you can use to establish a baseline of AI use in your organization. Fill out the form below and get a copy of the entire kit, plus customized examples, for free.