Agent governance covers several layers: an explicit agent constitution (scope and rules), a runtime policy engine that enforces those rules, retrieval grounding to keep responses accurate, tool-call permission controls, audit logging on every interaction, and a change-control process for the constitution itself.
In regulated industries — financial services, healthcare, legal — governance is not optional. Compliance teams must be able to audit what the agent said, what sources it cited, which policies were evaluated, and which humans reviewed the output.
Effective governance is designed into the deployment from day one, not retrofitted after launch. Retrofitting policy onto an agent that has been running "by vibes" is expensive and rarely complete.