How can agents be governed? I see a possible answer in a portion of past and present architectures such as Spring, SOA, CORBA and WS-*. Cross-cutting services. Require agents to invoke the security service to authenticate or the corporate logging service to log, etc. This doesn't inhibit autonomy, these are operations the agent would be invoking anyway. For the security service I can't imagine a corporation that won't require this anyway. Agents and RAGs may require different treatment by the security service but keeping things centralized seems to make the most sense. These services can be mature, well testing and well known. They also exist for the most part in most companies anyway. Usually elevating many to the higher levels where the same service implementation is used throughout the corporation is advisable as well. It also contributes to transparency as agent interactions with the common services are tracked.
------------------------------
John Harby
CEO
Autonomic AI, LLC
https://functormodel.ai
------------------------------