Governing agents: the six rules and the first ninety days
The goal of the first ninety days is not transformation. It is an informed decision, made with your own evidence: what agents are worth to your organisation, on your workflows, under your controls. The six rules below make the pilot safe to run. The ninety-day plan makes the decision honest.
The six rules
Every agent that touches company work runs under all six. They are infrastructure choices, not policy aspirations, which is what makes them enforceable.
1. Sandboxed
Agents run on isolated infrastructure set up for the purpose, never on personal laptops. A sandbox limits what a misbehaving agent can reach, and it makes the environment reproducible when something needs investigating.
2. Least privilege
Agents get read-only access to data and a whitelist of tools, nothing more. The Five Eyes guidance on agentic AI puts it plainly: system prompts are instructions, not controls. The real controls live in permissions and infrastructure, so that is where the boundaries are set.
3. Approval gates
A human approves anything irreversible before it happens: send, publish, pay, delete. The agent can draft, queue and recommend, but the consequential click belongs to a person.
4. Logged
Every message, every tool call and every data access is recorded. Logs are what turn an incident into a lesson rather than a mystery, and they are the evidence base a regulator or a client will eventually ask for.
5. Right-sized models
Frontier brains for judgment, budget brains for volume. Most agent steps are routine and do not need the most capable model. The workshop demo made the cost gap between the two tiers tangible.
6. Data stays home
Company and client data stays in your jurisdiction, on infrastructure you control. Where the model runs and where the data rests are decisions you make deliberately, not defaults you inherit from a vendor.
The first ninety days
Three phases, twelve weeks, one decision at the end. Each phase has a concrete output, so progress is visible and the final call is grounded in measurement rather than sentiment.
| Phase | Weeks | What happens | Output |
|---|---|---|---|
| See | 1 to 2 | Inventory what already runs, amnesty included: staff declare the tools they use without penalty. Then write the policy. | A two-page policy: allowed, banned, needs-approval. |
| Pilot | 3 to 8 | One governed pilot. One workflow, real data, a task already measured in hours, humans in the loop throughout. | A running agent under all six rules, with logs. |
| Decide | 9 to 12 | Measure hours saved, quality and incidents. Scale what worked, kill what did not. | A published internal decision, so shadow agents come into the light. |
The amnesty in week one matters more than it looks. People are already using these tools quietly. An inventory that punishes honesty produces a fictional inventory; an amnesty produces the real one, which is the only one worth governing.
The Malaysian context
The government is moving on this. Malaysia's National AI Office launched on 12 December 2024. On 28 July 2026 the Prime Minister launched AI Malaysia in Cyberjaya as the permanent apex body for national AI governance, alongside the National AI Action Plan covering 2026 to 2030, which carries 28 initiatives toward the goal of "AI Nation by 2030". An AI Governance Bill is being drafted, targeted for completion by the end of 2026. All of this is documented in official releases from the Ministry of Digital Malaysia.
Where to start on Monday
Start with the smallest real step: name an owner, run the amnesty inventory, and draft the two-page policy before the month is out. Pick one workflow your team already measures in hours and scope it as the pilot. None of this requires a budget line or a transformation programme; it requires a decision to look at the question with your own evidence rather than someone else's slides. BASIC builds and hosts governed agent deployments on Malaysian infrastructure and is happy to compare notes.
Sources
| Source | Supports | Link |
|---|---|---|
| Ministry of Digital Malaysia, official release | National AI Office launch, 12 December 2024 | digital.gov.my |
| Ministry of Digital Malaysia, official release | AI Malaysia launch, National AI Action Plan, AI Governance Bill timeline | digital.gov.my |
| CISA with US and international partners | Guidance on secure adoption of agentic AI; system prompts as instructions, not controls | cisa.gov |
Related
BASIC · Agentic AI Workshop · aiagent.research.my