Insights

2026-07-08 · Article

TechSight TAG

Trust AI Governance: Tech Sight's framework for agentic AI, one maturity model, four pillars, no ambiguity about who signs off.

By Frans Vermaak, CEO and AI & Data Architect

TechSight TAG

Most AI governance frameworks are built to block. TAG is built to tell you exactly where you stand and what to fix next. That distinction is the whole point of this one.

Tech Sight's Agentic Coding & Governance series already established the underlying problem: coding-agent adoption has outrun coding-agent governance at every scale, from a five-person startup with an agent holding production credentials, to an enterprise discovering its AI agents have no independent identity in the audit log. TAG is the answer we give clients who ask what to actually build, not just what to avoid.

Where You Start: The Maturity Model

Every TAG engagement opens with the same honest question, answered before a single control gets designed: how much blast radius does this specific AI deployment actually have? Not "AI" in the abstract. This deployment, this data, this access level, today.

Tech Sight's Blast Radius Ladder is that maturity model, in four rungs:

Rung 1, Ungoverned: the agent holds the same credentials a human would, no separate environment, no approval gate. This is where the Replit incident happened: an AI coding agent deleted a live production database because nothing in its environment distinguished "permitted" from "catastrophic."

Rung 2, Scoped but content is still trusted: the execution environment is sandboxed, but the agent still treats everything it reads as a legitimate instruction. This is the CVE-2025-53773 pattern: a hidden instruction in a code comment triggered remote code execution in GitHub Copilot's "YOLO mode" without the agent's permissions ever being the problem.

Rung 3, Identity-governed: the agent is a distinct, revocable identity in the access-control system, not an invisible extension of whoever launched it. Industry-wide, only 21.9% of organisations have reached this rung, which is precisely the gap a state-sponsored actor exploited in the GTG-1002 campaign Anthropic disclosed in November 2025.

Rung 4, Framework-certified: governance mapped to NIST AI RMF, OWASP's Agentic AI Top 10, and ISO/IEC 42001, audited and maintained as a standing practice rather than a one-time project, the way JPMorgan runs 450-plus daily AI use cases behind a C-suite oversight council.

Placing the actual deployment on this ladder honestly, before any technical control gets designed around it, is the single highest-leverage thing a client does in the entire engagement. A control built for Rung 4 is wasted money at Rung 1. A Rung 1 deployment left ungoverned is a live incident waiting for a slow week. Every pillar below assumes you've done this first.

The Four Pillars

Each pillar maps to a specific failure mode Tech Sight has already documented in the field. None of them is a checkbox exercise.

Pillar 1: Alignment

Alignment is the discipline of keeping every technical and governance decision tied back to the rung the deployment actually sits on, not the rung the sales deck implies. As a deployment climbs the ladder, its Alignment obligations climb with it: a Rung 1 pilot needs a boundary and an approval gate; a Rung 3 production system needs a standing identity and revocation process. Re-checking Alignment isn't a one-time gate. It's a re-run on every material change to what the agent can touch.

Pillar 2: Guardrails

Guardrails are the technical controls that stop an agent acting on something it should never have trusted, mapped directly to OWASP's Top 10 for Agentic AI Applications rather than invented from scratch. In practice this means: every retrieved document, every code comment, every third-party skill or plugin is treated as untrusted input by default, not a legitimate instruction. Outputs are grounded against verified sources wherever the deployment's risk tier requires it, with confidence scoring and a defined fallback to human review when that confidence drops. Dependencies, extensions, and skills are pinned to known versions and scanned before install, the same discipline most engineering teams already apply to a lockfile, extended to the AI's own supply chain, closing the exact gap the 2026 ClawHavoc campaign exploited across more than 1,200 malicious OpenClaw skills.

Pillar 3: Telemetry

If a regulator, auditor, or your own board asks what a specific agent did and why, you need a complete answer inside minutes, not a forensic reconstruction project. Telemetry means every agent action is logged with an identity, a timestamp, and the reasoning or source behind it, in a form that satisfies ISO/IEC 42001's management-system requirements and NIST AI RMF's "Map, Measure, Manage, Govern" functions without needing a separate compliance layer bolted on afterwards. This is infrastructure, not a report you generate once a quarter.

Pillar 4: Oversight Core

Technology does not fail in a vacuum. It fails because the right person was not in the room at the right decision point. The Oversight Core is three distinct roles, each with real authority and a genuine veto where it matters:

The Sponsor owns business value and the ROI case, and is accountable for the deployment actually solving the problem it was built for.

The Engineer owns technical execution, data quality, and integration architecture, and is accountable for the system doing what it claims to do.

The Guardian owns risk, safety, and compliance, and holds the one veto that matters: nothing reaches production without Guardian sign-off, full stop. When the Guardian says no, the Guardian wins, regardless of how close the deadline is or how excited the Sponsor is about the demo.

This is not a committee. It is three specific, accountable people, named at project kickoff, whose names appear in the audit trail next to every major decision.

From Diagnosis to Delivery

TAG tells you where you are on the ladder and what "governed" actually means at that rung. It does not, by itself, get you from a diagnosed Rung 1 startup to a working, governed Rung 3 deployment in a defined timeframe. That is what TechSight 90 is for: the delivery methodology built on top of this maturity model, covered separately, which opens with its own light-touch version of this same ladder for clients who haven't run a full TAG assessment yet.

What TAG Is Not

It is not a product you install. It is not a document you file after go-live. It is the standing discipline Tech Sight applies to every AI deployment we scope, build, or audit, structured so that a CISO, a compliance officer, and a board member can each find the answer to their specific question inside the same maturity model and four pillars.


Sources: NIST AI Risk Management Framework (AI RMF 1.0 and the Generative AI Profile); ISO/IEC 42001:2023, Artificial Intelligence Management Systems; OWASP Top 10 for Agentic AI Applications; Anthropic's GTG-1002 disclosure, November 2025; CVE-2025-53773 (GitHub Copilot "YOLO mode"), reported by Johann Rehberger, 29 June 2025; ClawHavoc campaign reporting, January 2026; Replit AI coding agent database deletion incident, reported July 2025; Uber and JPMorgan governance architecture, 2026 enterprise AI security case studies; agent identity-governance statistics, Gravitee State of AI Agent Security 2026, all as previously cited across Tech Sight's Agentic Coding & Governance series.

Book the two-hour diagnostic

More from Insights

People Will Take the Bot. They Cannot Find the Door.

2026-08-26

The 45 Jobs That Were Not Redundant

2026-08-26

Nobody Published the Denominator

2026-08-26