Skip to main content
05 — AI Governance & Security

Control and secure AI at scale.

Agents that can act inside your systems are a new class of privileged identity. They need to be governed like one.

The problem

Nobody can list the AI systems currently running in the business.

Copilots were bought by departments. Agents were built by a project team. Staff paste company data into consumer tools. Each is defensible alone; together they are an ungoverned surface with no inventory, no owner and no audit trail.

  • 01No inventory of what AI exists, who owns it, or what data it touches.
  • 02Agents holding far broader permissions than their task requires.
  • 03Prompt injection and untrusted content treated as a theoretical risk.
  • 04No record of what an AI system did, to what, or on whose approval.
What Pentagon X builds

The approach.

The moment an AI system can read your data and call your tools, it becomes part of your attack surface and your compliance perimeter. We help organizations establish the inventory, policy, permissions, guardrails, monitoring and audit trail that make scaling AI a controlled decision rather than an accepted risk.

System view — AI control layer
01Inventory
  • Agent & system registry
  • Owners and purpose
  • Data and tool scope
02Policy
  • Risk tiering
  • Autonomy levels
  • Approval thresholds
03Enforcement
  • Identity & least privilege
  • Guardrails outside the prompt
  • Egress controls
04Assurance
  • Monitoring & anomalies
  • Audit trail
  • Red teaming & evaluations

Controls that live in the prompt can be talked around. These do not.

Capabilities

What sits inside this discipline.

Engagements draw on a subset of these, scoped to the outcome you are buying.

AI Governance Assessment

Assess current AI usage, systems, agents, risks, ownership, policies, data access and human oversight against a defined control set.

AI Inventory & Agent Registry

A single register of what exists, who owns it, what it does, what data it reads, what tools it can call and what risk tier it sits in.

AI Policy Design

Practical policy covering acceptable use, sensitive data, model usage, agent autonomy, human approval thresholds, employee AI use and internal development standards.

Human-in-the-Loop Controls

Autonomy tiers agreed with the business: categorizing an email is not drafting an external reply, and neither is authorizing a payment.

AI Risk Management

Identify and classify operational, data, model, business, security and compliance risk, with owners and mitigations attached to each.

AI Evaluation & Assurance

Continuous evaluation of accuracy, reliability, hallucination, policy compliance, task performance and safety — with results that survive an audit.

AI Security Assessment

Identify vulnerabilities across models, agents, integrations, data pipelines, prompts, tools, APIs and permission models.

AI Threat Modeling

Prompt injection, data leakage, unauthorized tool use, excessive agent permissions, malicious documents, compromised integrations and insecure agent-to-agent interaction.

Agent Identity & Access Control

Who may invoke an agent, what it may access, which tools it may call, and which actions it may perform — enforced, not documented.

Least-Privilege AI

Every agent scoped to the minimum permission its task requires, with elevation as an explicit, logged and time-bound event.

Guardrails

Technical controls on what an AI system can access, say, call and do — enforced outside the prompt, where they cannot be talked around.

AI Monitoring & Audit Trails

Behaviour, tool usage, data access, failures, anomalies, cost and performance monitored in production — with a durable record of what happened, to what data, and who approved it.

AI Red Teaming

Adversarial testing against prompt injection, unsafe behaviour, information leakage and unexpected workflow paths, before someone else finds them.

How it works in practice

Worked examples.

These are illustrative constructions, not client case studies. We do not publish customer names, savings figures or results we have not verified.

Illustrative use case

Agent registry and autonomy tiering

The problem

AI systems have been introduced by several teams. Risk and IT cannot produce a list of what is running, what it can reach, or who signed it off.

What we would build

An agent registry capturing every AI system with its owner, data scope, tool permissions and risk tier, alongside an agreed autonomy model defining which actions require human approval.

How it works

  1. 01Discover AI usage across business units and platforms
  2. 02Record owner, purpose, data scope and tool permissions per system
  3. 03Assign a risk tier against agreed criteria
  4. 04Define the autonomy tier and approval gate for each action class
  5. 05Establish a review cadence and a route for registering new systems

Potential business impact

Leadership gets a single answer to “what AI is running here”, and every future deployment enters through a defined door.

Illustrative use case

Prompt injection red team on a document agent

The problem

An agent reads supplier documents and can call internal tools. The documents come from outside the organization and are treated as trusted input.

What we would build

A structured red team exercise attempting to steer the agent through crafted document content, followed by remediation of the tool and permission model rather than the prompt alone.

How it works

  1. 01Model the attack surface across content, tools and permissions
  2. 02Craft injection payloads embedded in realistic documents
  3. 03Attempt unauthorized tool calls, exfiltration and policy bypass
  4. 04Report findings by severity with concrete remediations
  5. 05Re-test after changes and convert findings into standing evaluations

Potential business impact

Untrusted content is treated as untrusted, the tool surface is narrowed to what the task needs, and the failures become permanent regression tests.

Client outcome

What changes for the business.

  • A defensible inventory of every AI system operating in the business
  • Agent permissions scoped to task, not inherited from a service account
  • An audit trail that answers what happened, to what, and who approved it
  • AI adoption that scales as a controlled decision rather than a risk backlog