Ghost in the Stack: The CISO Handbook for AI Agent Identity, Accountability, and Governance

Enterprise AI agents now act autonomously on behalf of the organisations that deploy them, at a scale that has outpaced the governance frameworks meant to control them. Machine identities already outnumber human identities in most enterprises, and the ratio is widening. When one of those agents takes an action that causes harm, a question follows immediately: who is accountable, and can the organisation prove it? Regulators in three jurisdictions have converged on the same answer. Spain's data protection authority (February 2026) established that an AI agent is a technical means of processing, not an autonomous legal actor. A United States executive order (June 2026) and California statute foreclosed the defence that AI acted independently. Singapore's Model AI Governance Framework for Agentic AI (January 2026) made accountability explicitly non-delegable. Technical autonomy does not reduce legal responsibility. It transfers that responsibility back to the humans who deployed the system. Most enterprises cannot currently meet the burden of proof this creates. This handbook is a practitioner's guide to closing that gap. It is written for CISOs, boards, and general counsel rather than for researchers, and its contribution is analytical and organisational rather than experimental. It introduces the Accountability Chain — a five-link diagnostic framework spanning Identity, Authority, Action, Attribution, and Accountability — which serves as the analytical spine of the handbook and is applied throughout. Around that framework it provides: a vendor-neutral six-layer reference architecture for agent governance; a five-question checklist boards can use to assess readiness with data rather than belief; a five-level maturity model for self-assessment; a six-metric board reporting framework with quarterly and event-driven cadences; and a ninety-day implementation plan. The handbook examines the accountability vacuum through five specific governance gaps, including the contractual agent and the orphaned agent. It treats insider risk as a first-class concern, with particular attention to the sponsor-abuse pattern — cases where the accountable human is the source of the misuse rather than its safeguard, which most agent governance frameworks fail to address. It extends the governance model to model supply chain integrity, cross-border data flow at inference time, and Zero Trust architecture. It compares the current vendor landscape across CyberArk, Okta, SailPoint, and Microsoft without advocating for any of them. Federated agent identity — agents transacting across organisational boundaries — is treated as an explicitly open problem rather than a solved one, with interim practices offered and the research gap named honestly. The handbook closes with ten dated predictions for 2030, offered as calibration points rather than forecasts. Approximately 65 pages, with glossary, acronym list, vendor comparison table, small-and-medium-enterprise appendix, and a companion architecture diagram. Twenty citations to primary regulatory, industry, and academic sources. The third paper in a planned four-paper series on enterprise AI security. Companion papers: Calibrated to Act (DOI 10.5281/zenodo.21157411) on agentic SOC calibration, and Proven Exploitable (DOI 10.5281/zenodo.21159028) on AI-augmented vulnerability discovery. Vendor and product agnostic. Views are the author's own and do not represent any employer or institution. Research and drafting assistance provided by Claude (Anthropic); all analysis, framework design, and conclusions are the author's own.

Paper

The full text of this publication is not hosted on 44B due to licensing.

Read it at OpenAlex

Similar papers

© 2026 NYSGPT2525 LLC