Skip to content
97.5% of teams see value from GC AI before month oneSee how

AI Agent Governance: An Approval Checklist for In-House Counsel


Caitlin Price

AI agent governance means deciding what an agent may access, what it may do, and who remains accountable when it acts. For in-house counsel reviewing a proposed deployment, the useful output is a written approval for a defined workflow, with evidence that its permissions and controls match the work.

Start with the requested action. Reading a negotiation thread, preparing a reply, and sending that reply require different permissions. An approval should make those differences visible to the lawyer, the business owner, and the person configuring the system.

GC AI is our enterprise legal AI platform, trusted by 2,200+ legal teams. Our co-founder and CEO, Cecilia Ziniti, served as general counsel at Anki, Bloomtech, and Replit after working in-house at Amazon and Cruise. That experience shaped a product for lawyers who need to turn company context into practical advice while retaining responsibility for the decision.

In GC AI, counsel can work from agreements, company positions, and connected-app context, inspect the source material, and prepare a response for review. Governance determines who can supply those inputs and which next steps the agent may take.

OpenAI’s September 16, 2026 model misalignment reporting framework accompanied six reports of behavior observed during model training or evaluation. Examples included unauthorized uploads and attempts to work around missing access. OpenAI expressly cautions that the individual incidents do not establish how frequently misalignment occurs. They provide failure scenarios to test; they do not provide production failure rates.

The Australian Cyber Security Centre’s September 24 advisory on AI misalignment describes agents taking unexpected actions against public-facing websites or services. It reports no indication of broader or malicious targeting against Australia and recommends access controls, monitoring, patching, and incident-response testing. The advisory creates no new U.S. legal obligation.

For an approval review, these sources support a concrete question: what happens when the agent encounters an obstacle? Test whether it stops, asks for help, or attempts an action beyond its approved scope.

Turn the reported failure modes into three questions for the operator:

  • Can a blocked task become an unauthorized disclosure? A failed retrieval should not lead the agent to upload a contract to a public file host or find another account. Test the attempted workaround as well as the initial refusal.
  • Can missing evidence become a confident answer? Require the output to identify unavailable documents and unresolved facts. A completed-looking memo is not evidence that the source was retrieved.
  • Can delegation widen access? Identify where a second agent or downstream tool will receive files and which approval limits follow the work. A colleague's permission to start a task is not permission to use any destination that helps finish it.

These questions connect the reports to confidentiality, evidentiary reliability, and authority to act. The checks below make the answers part of the approval record.

AI Agent Governance Checklist for a Company Pilot

Use this checklist after AI governance intake has identified the assessments a request needs. An acceptable use policy sets employee rules across the company. This review records the operating conditions for one workflow.

The controls below are practical recommendations to adapt with security, privacy, and the business owner. Their relevance depends on the data, actions, and consequences involved. Counsel should separately identify applicable law and contractual commitments.

Define the Task and Its Owner

  • Name the business owner and the technical operator.
  • Describe the trigger, source material, expected output, and permitted destination.
  • State which decisions remain with a person.

“Support contract renewals” leaves too much open. A usable scope might permit an agent to read a designated agreement and negotiation thread, identify unresolved renewal terms, and prepare a response for counsel. Sending the response, accepting a new price, and signing an amendment each need their own authority.

Ask the business owner to define a successful result and an unacceptable consequence. Security verifies the implementation; counsel assesses legal conditions; the authorized business decision-maker accepts the remaining business risk.

Verify the Identity and Data Access

  • Identify the user account or service account the agent uses.
  • List the systems, folders, records, and data categories it can reach.
  • Test access from the account that will run the workflow.
  • Name who can grant, expand, and revoke access.

A user's ability to open a repository does not establish a business need for the agent to read everything in it. Ask the administrator to demonstrate the effective permissions, including restrictions inherited from connected systems.

Record approved recipients and storage locations for outputs as well as inputs. A workflow that reads confidential material and places its summary in a broadly shared folder has crossed a separate disclosure boundary.

Set Agent Permissions for Reading and Taking Action

  • Classify each available action as permitted, subject to approval, or blocked.
  • Review sending, editing, deleting, purchasing, publishing, and changing permissions separately where the system supports them.
  • Set destination, transaction, and execution limits that the system can enforce.
  • Define how any delegated agent or downstream automation inherits those limits.

OWASP’s guidance on excessive agency recommends minimizing functionality, permissions, and autonomy, and requiring human approval for high-impact actions. Ask the operator to show the configured tools and access controls alongside the written instructions.

For an initial pilot, permit the narrowest useful set of actions. An instruction to ask before sending is stronger when the send tool also requires approval. If the platform cannot enforce a material boundary, reduce the pilot's scope or keep that action outside the agent.

Define Human Oversight for Consequential Actions

  • Name the reviewer for each consequential action and a backup when that person is unavailable.
  • Show the reviewer the proposed action, recipient or destination, content, and relevant source material.
  • Require fresh review when a material part of the proposed action changes.
  • Define what happens when the reviewer declines or does not respond.

A review card needs enough detail for an informed decision. “Approve task completion” gives counsel little to assess if the task includes both preparing an internal analysis and emailing a counterparty.

For contract work, preserve the company's separate rules for approving terms and signing agreements. A person who can authorize an email may lack authority to accept the commercial commitment it contains.

KT Farley, Chief Privacy Officer and Associate General Counsel at Helix, uses shared checklist prompts to give junior teammates a consistent first pass before senior review. KT explains:

“Junior teammates now run the checklist prompt first and bring me the output as the predicate for my review.”

The team standardizes the first pass while the senior lawyer reviews its output. When designing an agent workflow, make that handoff equally explicit: who receives the draft, what they check, and what cannot proceed until they decide.

Review Data Handling and Contract Terms

  • Confirm the applicable product, account type, configuration, and contract.
  • Check training use, retention, deletion, subprocessors, and data locations.
  • Include connected services, logs, and persistent context in the review.
  • Record incident contacts, notice commitments, and the route for material vendor changes.

Ask where source content and generated outputs go at each step. A no-training commitment answers a different question from how long a provider retains data or who can access it.

Have privacy and legal reviewers assess the specific information involved, including personal data, privileged material, and third-party confidentiality restrictions. A platform security statement alone cannot determine whether a particular disclosure is appropriate or preserves privilege.

Test Failures Before Expanding Access

  • Use representative tasks and permitted test data.
  • Test unavailable sources, conflicting instructions, incorrect recipients, and denied permissions.
  • Include prompt injection: untrusted text in an email, document, or webpage that tries to redirect the agent.
  • Agree on pass criteria and a response to each failed test before running the pilot.

Ask the operator to demonstrate that an agent encountering a blocked file requests assistance instead of seeking another account, uploading material elsewhere, or inventing a missing answer. Test both whether it identifies the problem and whether the surrounding system prevents an unauthorized action.

The voluntary NIST AI Risk Management Framework addresses testing before and during operation, ongoing monitoring, and incident response. Use evaluations to assess the proposed workflow under stated conditions. A successful test set leaves uncertainty about behavior outside those conditions.

Confirm the Record and the Stop Procedure

  • Identify which records capture inputs, source references, tool actions, approvals, and outcomes.
  • Assign access and retention rules for those records.
  • Name an operator who can stop execution and revoke credentials.
  • Test shutdown, incident escalation, and recovery.

Ask to see the record of a completed test. Check whether another reviewer can tell what the agent proposed, what a person approved, and what the connected system did. Protect logs that contain confidential information and apply the company's retention and preservation requirements.

A stop procedure also needs to address queued work, schedules, and downstream actions. Stopping the chat may leave a scheduled job active. Identify actions that can be reversed and those, such as an external disclosure, that require incident handling.

Set the Conditions for Continued Approval

  • Give the approval an owner, review date, and defined scope.
  • List changes that require a new review.
  • Assign monitoring and escalation responsibilities during the pilot.
  • Record exceptions, their rationale, and who accepted them.

Revisit the approval when the workflow gains a new connector, reaches a new data class, changes its model or tool configuration materially, or moves from preparing work to executing it. A change to the person or account operating the workflow may also change its effective access.

Set the review cadence according to the consequences and rate of change. A recurring review date should sit alongside event-triggered review so a material permission change receives attention when it happens.

Document the AI Agent Risk Assessment

Ritesh Patel, Chief Legal Officer at Viant Technology, uses GC AI for initial legal analysis before deciding whether a matter needs outside expertise. He explains why source checking matters to that review:

“Having sources and links right there builds trust. You can check the law yourself, and that trust drives adoption across the team.”

Keep that source-checking step in the approval process. The reviewer needs to inspect the evidence supporting the proposed action and identify what remains unresolved.

Use the following record in the existing intake or risk register. Link supporting documents and test results so the next reviewer can reconstruct the decision.

RecordWhat to Capture
Workflow and purposeTask, trigger, intended users, output, and approved destinations.
Account and configurationProduct, model or version where available, connected systems, executing identity, and dated permission settings.
Data and actionsAllowed data, excluded sources, permitted actions, approval checkpoints, and blocked actions.
EvidenceContract and privacy review, configuration evidence, test cases, results, known limits, and unresolved findings.
AccountabilityBusiness owner, technical operator, action reviewer, incident contact, and person authorized to accept residual risk.
Decision and limitsApproved, conditional pilot, or blocked; approving person and decision date; permitted users and duration; conditions to satisfy before broader use.
Ongoing controlMonitoring owner, record retention, stop procedure, review date, and events requiring reassessment.

Choose a decision that matches the evidence. Approve the defined use when the required reviews and controls support it. Authorize a conditional pilot when enforceable limits contain the remaining uncertainty. Block the proposed use when a material permission, data-handling, or approval requirement remains unresolved.

An exception should name the missing control and the person accepting the resulting risk. If nobody can explain what the exception permits, return it for a narrower request.

Apply AI Agent Governance in GC AI

Start with the legal material the task requires: the agreement, relevant policy, approved positions, and company context.

Ask GC AI to identify the issue, show the supporting language, and prepare the work product you need. Our Exact Quote feature lets you inspect quoted passages against the document. Our Playbooks apply standard and fallback positions to contract review in Word.

For work involving business systems, add the appropriate connected context and configure what GC AI may do next. A negotiation workflow can move from retrieving the relevant thread to comparing terms and preparing a response. The settings and the human checkpoint should match each step.

Our Agent Connectors feature connects applications to GC AI so counsel can retrieve context and act from chat. Available actions depend on the connected account. Each action type has a permission setting: Needs approval, Always allow, or Block.

Our documentation describes three access layers: the organization's connector policy, the member's connected account, and that member's tool permissions. Read actions default to Always allow; write and delete actions default to Needs approval. Members can change tool permissions within the organization's policy, so inspect the actual configuration rather than relying only on defaults.

For an illustrative negotiation-preparation pilot, ask counsel to retrieve the designated thread and agreement, prepare a response, and check the cited material and draft. Keep sending subject to approval. Counsel checks the recipient, attachments, terms, and authority to make the proposed commitment before approving, editing, or denying the action.

Record counsel's decision, the approved action, and its result in the company's chosen record system. Test the configuration with the people and accounts that will use it. These product controls support the review; the company still needs to establish that its particular workflow satisfies the checklist.

Bring one proposed workflow, its source set, and its required actions to the evaluation. Ask for a demonstration of a permitted action, a denied action, and the stop procedure. Use the results to complete the approval record and decide which permissions the pilot can receive.

SOC 2 certification badgeSOC 2
SOC 3 certification badgeSOC 3
GDPR badgeGDPR

Take the first step now

Let's explore about how we can make your life as an in-house lawyer a whole lot easier.

What to expect:

  • A walkthrough of the platform, tailored to your team's use cases.
  • Q&A session about security, integrations, and onboarding.
  • A 14-day free trial if the platform looks like a fit for your team.

Book a Demo

Dial code +1 (United States)

By submitting, you agree to our Terms and Privacy Policy.

Keep up with the latest content