This paper argues that the introduction of agentic AI requires a substantial expansion of traditional enterprise architecture principles to address new behavioral, security, and governance risks emerging from non-deterministic AI systems interacting with heterogeneous operational platforms-ERP, HCM, CLM, asset management, workflow engines, and domain-specific applications.
Abstract
As enterprises accelerate the adoption of autonomous and agentic AI, the need for robust governance has become a critical architectural priority. Large organizations operate under strict regulatory, operational, and financial constraints, where even a single incorrect payment, billing error, or missed reconciliation can lead to significant compliance violations, audit failures, and material financial losses. These environments depend on deterministic, traceable, and verifiable execution; therefore, AI-driven automation cannot operate freely but must be deployed on well‑defined “rails” that enforce consistency, accountability, and operational safety. This paper argues that the introduction of agentic AI requires a substantial expansion of traditional enterprise architecture principles to address new behavioral, security, and governance risks emerging from non-deterministic AI systems interacting with heterogeneous operational platforms-ERP, HCM, CLM, asset management, workflow engines, and domain-specific applications. We propose a governance-centered framework for safe agentic AI in enterprise settings, emphasizing lifecycle oversight (model management, testing, deployment, rollback), cross-system policy enforcement, and auditable decision lineage. Central to this framework is a security model grounded in Just‑In‑Time (JIT) and Just‑Enough‑Access (JEA) permissions, ensuring that AI agents receive only the minimal privileges required, only when needed, and never with long‑standing or system‑wide access. Additional safeguards include least‑privilege design, segmentation boundaries, continuous audit trails, agent identity isolation, controlled inter-agent communication, and human‑in‑the‑loop escalation for high-risk or sensitive tasks. These controls prevent unauthorized lateral movement, protect sensitive financial and HR data, and ensure agent actions remain aligned with organizational risk and compliance boundaries. By integrating these governance mechanisms with orchestration and policy engines, enterprises can achieve predictable execution, transparent reasoning, and resilient automation at scale. This work highlights why governance is not peripheral but foundational to the safe deployment of agentic AI
LATTICE (Layered Agentic Triad Topology for Intelligent Coordinated Execution), a governance-first architecture that reframes the authorization question from “do the authors trust this AI?” to “do they trust this architecture?”
Elias Calboreanu· Frontiers in Artificial Inte...· 1 citation
A contract-bounded runtime architecture, a source-preserving data substrate, and a falsifiable measurement protocol are contributed, which proposes a cluster-period randomized crossover experiment with a four-state verdict: supported, falsified, conditional-engineering, or inconclusive.
Ya-Xiao Liu, Peng Liu, Yi-Wen Liu et al.· 0 citations
This paper argues for a transition from AI Governance as Compliance to AI Governance Engineering , a systems-oriented discipline in which governance is embedded throughout the enterprise intelligence lifecycle, enabling enterprise intelligence systems that are secure, explainable, trustworthy, and governable by design.
Faruk Çelikkanat· International Journal of Res...· 0 citations
Enterprises are increasingly building agentic AI systems out of reusable skills — modular units that bundle prompts, reasoning strategies, tool integrations, and execution policies, and that get reused across many AI use cases. This pattern speeds up delivery, but it creates a risk that current AI governance frameworks were not designed for. A single privileged skill, reused across dozens of workflows, can quietly accumulate excess privilege, expand the operational blast radius of every workflow it touches, and drift from its original policy boundary. The NIST AI Risk Management Framework, ISO/IEC 42001, MITRE ATLAS, and OWASP's guidance for LLM and agentic applications all treat AI systems as a single object. None of them gives an organization a way to govern reusable skills as the cross-cutting assets they have become.
This paper argues that reusable agent skills should be treated as first-class governed enterprise assets, and that the enterprise agent harness — not the skill, the model, or the use case — must serve as the runtime trust boundary at which a skill's authority is granted. The paper proposes a runtime governance framework built on three constructs. Skill Risk Inheritance is a design-time model for reasoning about how risk flows through the composition of skills, tools, and use cases. Dynamic Capability Projection (DCP) is the runtime mechanism by which the harness grants, on each invocation, only the subset of a skill's declared capabilities authorized for the current use case and principal. Risk-Adaptive Capability Projection (RACP) extends DCP across time: the granted subset widens or narrows as runtime risk signals change. The framework is grounded in the object-capability tradition, modern policy engines such as OPA and Cedar, and Zero Trust architecture. It is validated through a prototype implementation on Open Policy Agent and a graph-based simulation, which together show that DCP reduces the runtime capability surface to 41% of declared scope withholding 59% of potential capabilities per invocation–at a median policy-evaluation overhead of 8.9ms, negligible against LLM inference latency. Critically, inheritance analysis revealed that 93% of simulated use cases operated at higher effective risk than their declared classification, a finding with immediate implications for enterprise AI risk programs.
Sandeep Kumar Anuguthala· International Journal for Sc...· 0 citations
Enterprise AI adoption has reached a structural inflection point: while a majority of organizations have deployed generative AI, few have established mature governance models for autonomous agents. This disparity reflects a fundamental architectural gap: Multi-Agent Systems, Enterprise Architecture, AI agent deployment, and software architecture have approached agent coordination from separate disciplinary perspectives, with no single framework integrating persistent memory, semantic interoperability, orchestration, human oversight, and normative enforcement. Following Design Science Research, this article develops the Agentic Enterprise Capability Framework (AECF), a five-layer architecture structured around Context Persistence (CPL), Semantic Interoperability (SIL), Hybrid Orchestration (HOL), Human Governance Interface (HGI), and Governance Envelope (GEL). The framework introduces the co-evolution constraint: technical capability layers cannot mature independently of governance capacity. This constraint is operationalized through Context-Enriched Pre-Execution Validation (CEPEV), which grounds compliance checks in operational memory. Five architectural propositions formalize inter-layer dependencies (P1), scalability boundaries (P2), governance effectiveness (P3), performance accumulation (P4), and a governance scaling law (P5). The study contributes an integrated architectural model, propositional formalization, and validation agenda for governed enterprise AI agent deployments.
Khammal Adil, Hamzane Ibrahim, Marzak Abdelaziz et al.· International Journal of Adv...· 0 citations
Organizations operating under compliance mandates increasingly rely on AI agents to automate workflows involving unstructured documents and dynamic decision-making. In such settings, agentic systems must reconcile autonomy with strict requirements for auditability, controlled variability, and integration with legacy infrastructures. We propose an Exemplar as a reusable evaluation artifact for analyzing agentic orchestration frameworks under Compliance Management and Documentary Uncertainty. The Exemplar captures the interaction between probabilistic extraction and deterministic constraint enforcement in workflows characterized by unstructured inputs, rigid schemas, and asynchronous processes. We empirically evaluate four frameworks (CrewAI, Embabel, LangChain, and n8n) across three dimensions: type safety, reasoning auditability, and legacy interoperability. The evaluation is grounded in a real-world instantiation within a state penitentiary agency, involving automated processing of employment contracts with incomplete data and asynchronous stakeholder interactions. Results show clear trade-offs between flexibility and control, highlighting the importance of hybrid approaches that combine agentic reasoning with deterministic validation. The exemplar generalizes to regulated domains such as public procurement, finance, and healthcare.
Renzo Zukeram, Vinícius Mergulhão, Yuri de Medeiros et al.· Anais do LIII Seminário Inte...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.