Perspective · External & Agentic AI Governance · RuleBridge Advisory · July 2026

Governing the AI You Did Not Build

Most organisational AI now arrives through vendors, platforms and product updates — and increasingly it acts rather than answers. Accountability does not arrive with it. It was yours already.

The centre of gravity of organisational AI has moved outside the organisation. AI arrives embedded in enterprise software, through platform features switched on in a release note, through general-purpose models consumed over an API — and, increasingly, as agents: systems that plan, invoke tools and carry out multi-step tasks under delegated authority. Gartner expects task-specific agents in some 40% of enterprise applications by the end of 2026, up from under 5% a year earlier; the same analysts expect a large share of agentic initiatives to be cancelled by 2027, mostly for want of governance and demonstrable value. Both projections can be true at once. Together they describe the period ahead: rapid delegation of work to systems the organisation did not build, governed — or not — by structures designed for a different kind of software.

Why the classic model breaks.

Third-party risk management, as most organisations run it, was built for software that sits still. It reviews artefacts at a point in time — a questionnaire, a certification, a data-processing agreement — on an annual cadence, through a security-centric lens. Three of its founding assumptions no longer hold.

Behaviour is no longer fixed at contract signature. A model update changes what the system does without any procurement event taking place. The product that was assessed and the product that is running diverge quietly, on the vendor's schedule.

The unit of risk is no longer the artefact but the action. An agent with credentials, tool access and a goal is an operational actor inside the organisation's processes, not a document to be reviewed. What matters is what it may read, initiate, commit and spend — and under whose authority.

The chain no longer ends with the vendor. Beneath the vendor's product there is usually a general-purpose model with its own provider, its own release cadence and its own terms. Dependency runs deeper than the contract that names it.

What accountability law already says.

The legal architecture around external AI is settling into a consistent shape, and none of it accepts distance as a defence. Under the EU AI Act, deployer obligations sit with the organisation using the system; and an organisation that rebrands or substantially modifies a third-party system can find that it has become the provider, with everything that follows. Supervision of general-purpose AI is consolidating at EU level — and the 2026 Digital Omnibus widened the AI Office's scope rather than narrowing it. From December 2026, the new Product Liability Directive treats software, bought or built, as a product under strict liability. And buyers are moving faster than any of this: the European Commission's model contractual clauses for AI procurement are spreading from public buyers into private contracting practice, which means governance questions now arrive inside tenders and vendor reviews first. The direction is uniform. The organisation answers for the AI through which it acts — whoever built it.

Five planes of control.

Governing external and agentic AI is not a longer questionnaire. It is an operating model with five planes.

Scope what is delegated. Define, per agent and per process, what the system may read, write, initiate, commit and spend — and towards whom. The default beyond that envelope is denial. Delegated authority that has never been written down cannot be reviewed, limited or defended.

Gate the consequential. Place human checkpoints where actions are irreversible, external-facing or above defined thresholds — and design those checkpoints as real oversight, with the authority, information, capacity and record-keeping that make intervention genuine rather than nominal. A gate that cannot hold is a diagram, not a control.

Govern change. Treat a vendor's model or platform update as a change event in the organisation's own terms: notification rights, re-evaluation triggers, version records in the AI inventory. The characteristic failure mode of embedded AI is the silent upgrade — a material change in behaviour that no internal process ever registered.

Contract for evidence. Access to relevant logs, incident notification and cooperation duties, information about evaluations and material changes, assistance on exit. The contract will not carry what it does not contain, and it is negotiated once — usually before anyone has thought hard about what an incident review would need.

Keep an exit. Containment first — the ability to suspend an agent's permissions or a system's role in a process without stopping the business — and a transition path that preserves continuity, data and records. A dependency without an exit is a decision made once and lived with indefinitely.

The horizon.

Over the next five to ten years the boundary keeps moving: agents transacting with other organisations' agents, standing delegations that outlive the people who granted them, incidents that propagate at machine speed across organisational lines. None of that changes the discipline; it raises the price of not having it. Organisations that can scope, watch, gate and stop delegated authority will experience the agentic period as routine operations. The rest will experience it as a series of surprises, each investigated after the fact.

The discipline is available now, and it is cheapest before the portfolio grows. An organisation can outsource the system. The accountability was never on offer.

Scope. Governance of AI the organisation does not fully control: vendor and platform AI, general-purpose models consumed through products or APIs, and agents acting across the organisational boundary under delegated authority. Model-level technical evaluation and cybersecurity engineering are inputs to this work, not part of it.

Assumptions. Figures on agent adoption and initiative cancellation are Gartner projections (2025–2026) and describe direction, not precision. Legal references reflect the EU AI Act as amended by the Digital Omnibus on AI (June 2026) and the Product Liability Directive as adopted; obligations vary by role and use case.

Sources. Regulation (EU) 2024/1689 (EU AI Act), in particular Articles 25 and 26 — EUR-Lex; Freshfields, The final Digital Omnibus on AI (July 2026), on the AI Office's expanded supervisory scope; Directive (EU) 2024/2853 on liability for defective products — EUR-Lex; European Commission Public Buyers Community, Updated EU AI model contractual clauses (2025) — public-buyers-community.ec.europa.eu; Gartner, agentic AI forecasts and 2026 CIO and Technology Executive Survey, as published in analyst and trade coverage (2025–2026).

Intended use. For executives, procurement, risk and operations owners establishing or reviewing governance of third-party and agentic AI. A governance perspective, not legal advice; contractual drafting belongs with counsel.

← All perspectives & tools