Continuous GRC for Agentic AI
Abstract
This article examines Continuous Governance, Risk, and Compliance (Continuous GRC) as a foundational requirement for autonomous and agentic AI systems. It argues that periodic assessments and retrospective audits are insufficient for systems that continuously interpret goals, delegate authority, invoke tools, access resources, and modify operational state. The article develops a runtime governance model that connects machine-executable policies, continuous risk evaluation, control validation, Evidence-as-Code, provenance, drift detection, bounded exceptions, human oversight, and governed risk response. It explains how governance decisions must adapt to changes in identity, authority, context, system behavior, environmental conditions, and evidence quality while preserving accountability and auditability. The analysis expresses these requirements as technology-independent architectural invariants within SGAEIA — Secure Governed Autonomous Edge Intelligence Architecture. It demonstrates how continuous assurance can connect policy intent, runtime decisions, autonomous actions, control effectiveness, and verifiable evidence across distributed multi-agent and edge environments. This deposit preserves the author-manuscript archival edition of the article originally published on Medium on 12 September 2026. Original publication:https://medium.com/@aridiosilva/continuous-grc-for-agentic-ai-ada11c2974d0 Archival edition DOI:https://doi.org/10.5281/zenodo.22728227