EU AI Act · Article 50 transparency obligations apply as of August 2, 2026.  Check your AI governance free →  ·  Article 50, checked — on ScrutinEyes

DeputEyes · agent governance readiness · how to complete it

Your agent-governance self-assessment: an inventory first, a score second.

Agent-governance readiness assessments are coming soon. This guide previews how your self-assessment will work so you can build your agent inventory now. It isn't available for purchase yet — want it when it launches? Write alerts@initialeyes.com.

Your DeputEyes agent-governance readiness assessment measures how well you govern the AI agents you run or ship — systems that call tools, hold memory, act on accounts, and sometimes talk to other agents. It has thirty-eight controls in ten domains (AG-GV through AG-HT), each mapped to the OWASP agentic risks it mitigates. It isn't pass/fail and no framework behind it defines an official score: it's an editorial read of where you stand. Plan on about half a day — most of it building the agent inventory (AG-GV-01), which is the one control everything else depends on.

The three steps

  1. Inventory every agent first (AG-GV-01). One row per agent: owner, purpose, the systems it can reach, the tools it may call, the identity it acts under, and how it is stopped. Include agents inside vendor products and agents staff set up themselves — those are the ones nobody has written down.
  2. Mark a status for every control — Implemented, Partial, Not Implemented, or Not Applicable (with a reason) — and name the evidence you could show. "We'd notice" is not evidence; an alert you can point to is.
  3. Send the completed worksheet back. It returns as a readiness read with the gaps ranked by weight and by the OWASP agentic risks they expose you to, each with a remediation step.

What each status actually means

IMPLEMENTED

The control is in place, enforced technically where it can be, and you could show it. Example: every agent has its own service identity and audit logs attribute actions to it, not to a person (AG-ID-01).

PARTIAL

The control exists for some agents or in some environments, or relies on instruction rather than enforcement. Example: a refusal list is written into the prompt but nothing technically blocks the listed actions (AG-GV-04).

NOT IMPLEMENTED

The control isn't in place today. Mark it honestly — a gap you can see is a gap you can rank.

NOT APPLICABLE

The control doesn't apply, with a written reason. Example: no agent talks to another agent, so AG-MA-01 through AG-MA-03 are out of scope — until that changes.

Have these in hand before you start

The controls organizations most often misread

Inventory what actually runs, not what was approved. The agents that cause incidents are the ones nobody wrote down — a staff member's assistant with mailbox access, an automation that kept running after its owner left. An honest inventory produces a roadmap that covers the real attack surface; a tidy one produces a roadmap for the agents you already govern.

What happens after you submit

When agent-governance assessments open, your completed worksheet will be reviewed and returned as a readiness read: gaps ranked by control weight and by the OWASP agentic risks they expose you to, each with a remediation step and the evidence that would close it. A human reviews every report before it is released. No framework behind this assessment defines a certification — this is readiness, not an audit.

A readiness assessment is a planning tool built from your self-reported answers — not an audit, an attestation, or a certification. Control statements are InitialEyes originals. Risk taxonomy: OWASP Top 10 for Agentic Applications (2026), OWASP GenAI Security Project, CC BY-SA 4.0 — identifiers and titles referenced with attribution. Governance spine: NIST AI RMF 1.0, a US Government work. Questions? Write alerts@initialeyes.com.