AI agent governance

Who allowed it. What it did. Show the record.

JUTEQ Governance helps organizations govern the AI agents they already run, starting in regulated industries: a decision at the moment an agent acts, and a record your auditors can use.

Available now

Two ways to start.

Your own agents

The agents your teams built, governed where they run.

AgentGate, in private beta, does the work. Six weeks, fixed fee.

Week 1

Assessment of which agents run, and on whose authority.

Weeks 2 to 4

Blocking enabled for the action types agreed in week 1.

Weeks 5 to 6

Evidence review, including what is covered and what is not yet.

From you: a named owner, access, and a few hours a week from security, risk and platform.

Coding agents

Coding agents under your identity provider.

For teams whose rollout is held up by a security review. Built on controls your vendors already ship. Fixed fee, four to eight weeks.

We have built agentic, cloud and data platforms for clients in financial services and insurance, industrial, telecom, SaaS and retail automotive.

The argument

What changed.

1

Agents moved from suggesting to acting.

The risk now is a real command, file or API call, often with nobody watching.

2

Your controls watch the old risk.

Gateways, sandboxes and data loss prevention were built for people, not for an agent acting alone.

3

The people asking want a record.

Auditors, underwriters and supervisors want to know what the agent did, and on whose authority.

Governance is now a decision when the agent acts, and a record afterwards.

On the calendar

Record-keeping rules are arriving.

Canada

OSFI Guideline E-23 applies to federally regulated financial institutions from 1 May 2027. It brings AI models under model risk management.

United States

SR 26-2 replaced SR 11-7 as bank model risk guidance on 17 April 2026. It does not mention AI.

European Union

The AI Act requires automatic logging for high-risk AI systems, from 2 December 2027 for most of them.

None of them names agents. An agent acting on a model's output is still what examiners will ask about.

Questions

Common questions.

What is AI agent governance?

Deciding what your AI agents may do, and being able to show afterwards what they did and on whose authority. In practice: a decision at the moment an agent acts, and a record an auditor can check.

How long does an engagement take?

Six weeks for the agents your teams built, at a fixed fee agreed before we start. Coding agents under your identity provider take four to eight weeks.

Do we need AgentGate to start?

Not for coding agents: that work uses controls your vendors already ship. For the agents your teams built, AgentGate does the work, and week 1 is an assessment of which agents run and on whose authority.

Which regulations have you mapped?

Canada's OSFI E-23 is our first mapping. We have not mapped the US or EU rules yet. The record is built for the questions auditors ask: who allowed an action, what the agent did, and under which policy.

Who

Practitioners first.

We build agentic AI, cloud and data platforms inside regulated enterprises. The governance practice exists because every engagement ended with the same question: it works, now what did it do?

Rakesh Gohel
Founder and Managing Director, JUTEQ

Speaker at the Gartner CIO Summit.

Notes

We publish what we find, including where the controls do not hold.

Three pieces are in progress this autumn. Each title becomes a link the day it is published; until then it is a commitment, not a record.

AgentGate is in private beta and parts of the enforcement model are still under active investigation. What we have established, and what we have not, goes on this page as we go.

ForthcomingSept 2026

A vendor-neutral procedure for bounding what an agent may do

Permission bounding for non-human identities, scoping sub-agents, session tokens, and a kill-switch playbook. Written to be used without buying anything from us.

Forthcoming30 Sept 2026

Our comments on the Agent Baseline draft

Four submissions to the industry baseline for agent security. Filed on the public record on the comment deadline, and linked here the same day.

ForthcomingOct 2026

What E-23 will ask about agents, even though it does not say the word

Reading the model risk guideline from the point of view of an agent that acts on a model's output.

Notes arrive by email when they are published, not on a schedule. Ask to be on the list.

Private beta

AgentGate, by JUTEQ. The record of what your agents actually did, and a decision at the moment they act.

Deploying now with a limited number of organizations.