Step 1: Conduct a risk assessment focused on agentic AI security risks
Is this legally binding?
Guidance. Voluntary guidance. Best practice, not obligation, until a contract or a regulator cites it.
Conduct a risk assessment based on industry best practices or the organisation's enterprise risk framework, extended for agentic AI with autonomy assessment, threat modelling (plus taint tracing) and capability-based risk identification.
What this connects to
2 relations. Official relations are the ones the source documents state; anything marked GAGE analysis is our reading, not an agency's.
Maps across to2
- ObligationStep 1: Conduct risk assessment focused on AI security risksGuidance
Addendum Step 1 extends the Guidelines' risk assessment with autonomy, threat modelling and capability analysis
- External frameworkFunction: MAPGuidance
Agentic risk assessment is MAP-function analysis for autonomous systems
Verified against the official source on 2026-08-17. GAGE is not affiliated with or endorsed by any agency named here, and nothing on this page is legal advice. How this is built and checked.