AI Governance Tools vs an AI Audit: What Each One Actually Proves
This week’s agent-governance products sell detection and enforcement: they watch your agents, decide what they may do, and can stop them. An audit asks three different questions — who was accountable for a specific action, what was in scope, and what evidence survives — and buying the first does not produce the second.
WSO2 announced Agent Manager’s general availability on September 15, 2026; InfoQ covered it on September 18: “WSO2 has announced the general availability of WSO2 Agent Manager, an open-source platform designed to provide centralized governance, identity management, security controls, and operational oversight for AI agents running across different models, frameworks, and deployment environments.” Opal Security launched Opal Zero on September 17, 2026: “Opal Zero decides each agent request the moment it’s made, against the security team’s policy and organizational context, then enforces it as carefully scoped permissions in the gateway already in place.” iProov published HAPS — reported by Biometric Update on September 18 — an experimental specification for binding human presence and approval to a machine-readable action, with a partial reference implementation on GitHub and an invitation for critique rather than any reported deployment. That report draws the line that matters: “AI agents can access tools and services, but that does not prove a human intended or approved the actions they take.” SiliconANGLE’s September 17 report from Workiva’s Amplify event — sponsored-event coverage, not independent reporting — carried the finding from Josh Robinson, chief audit executive at Vast Space LLC: “Enterprise audit teams are finding that the evidence trail they depend on does not survive contact with AI agents.” TechTarget’s September 18 analysis of agent autonomy and CIO controls, and CIO.com’s September 18 round-up of sixteen governance tools, cover the same market from the buyer’s side. None of these products performs an audit or satisfies a regulator.
What each one leaves behind
Each row below is an artifact rather than a quality claim: what you would hand a reviewer or a client if they asked. Behind it sits the question the checklist’s new silent-delegation section asks of a specific agent.
| Aspect | What a governance tool proves | What an audit produces |
|---|---|---|
| Agent inventory and scope | The register it keeps: the agents it has onboarded and the permissions it issued them. Its reach is its boundary — an agent nobody registered stays invisible to it. | A dated scope record per agent: which systems, actions and data are in bounds, which actions wait for a human, and who granted that authority and when — with live permissions that still match the page. |
| Monitoring and detection | Signals: policy violations, anomalous action patterns, and a dashboard of what the agents did. The evidence is a log entry in the tool’s store. | A test you can run unassisted: take one agent-initiated change and produce the approver, timestamp, target and outcome for it from records you already hold. |
| Least-privilege enforcement | The enforcement decision: what the gateway allowed or denied at the moment the request was made, against the policy you configured. | The authority behind whichever actions were allowed: the evidence that the person whose approval was required gave it, and that their remit covered this action. |
| Approval and override records | The approval step it ran and the record it kept: which policy fired, and which request passed through it. | The approval stored alongside the action itself, plus a documented reversal path: who can undo it, how, and how long a reversal takes to become possible — logged against the same entry. |
| Accountability attribution | Attribution as configured: an agent identity, a role, a policy, a team. | One accountable person attached to the agent record — a name, not a queue and not the vendor — with a stated split between the decisions it may take unattended and those that require a person. |
| Evidentiary retention and independence | Retention for the life of the licence, in a store the vendor operates, with export on request. | A retention period in writing that outlasts your incident-response cycle, in a store that sits outside the agent team’s control, still readable 90 days later, and held independently of the tool that produced it. |
A governance tool hands you its console, the policy you configured, an alert history and a log export while the licence lasts — artifacts describing what the tool saw, held in the vendor’s store; what it does not hand you is a record of authority, a named owner, or anything that outlives the subscription. An audit hands you the scope record, the approval record for a named action, the override path, the named owner and a retention commitment: documents that stand on their own when the tool is not in the room. Buy the tool for control: it is the fastest way to constrain what your agents can do this quarter. Commission the audit for evidence: what a reviewer asks for is not a dashboard but a record naming the action, the approver and the authority, carried by the person who answers for it.
Sources.
WSO2 Agent Manager — InfoQ, “WSO2 Releases Agent Manager as Enterprises Look to Control Growing AI Agent Sprawl”, by Craig Risi (September 18, 2026) (infoq.com). General availability announced September 15, 2026, as reported by AI Stack Current (page dated September 16, 2026). The outlet’s own article slug is ws02-agent-manager, not wso2.
Opal Zero — Opal Security release, “Opal Security Launches Opal Zero to Make Least Privilege a Reality for Enterprise AI Agents” (dateline September 17, 2026) (opal.dev). Business Wire syndicated the release on September 18, 2026. Capability described as the release states it.
iProov HAPS — Biometric Update, “iProov’s experimental HAPS protocol aims to close governance gaps for AI agents”, by Joel R. McConvey (September 18, 2026, 12:36 pm EDT) (biometricupdate.com). The specification is published on GitHub under Apache-2.0 with a partial Rust reference implementation and test vectors; iProov reports no deployment, customer or standard-body status. The vendor’s own release was not retrievable at the time of writing, so Biometric Update is the cited source.
NetSuite audit-assurance gap — SiliconANGLE, “AI agents erase the paper trail, reshaping audit assurance”, by Jonathan Anthony (updated 16:22 EDT, September 17, 2026) (siliconangle.com). Sponsored-event coverage: theCUBE is a paid media partner for Workiva’s Amplify event. The finding is attributed to Josh Robinson, chief audit executive at Vast Space LLC, not to the outlet or the sponsor.
AI agent autonomy — TechTarget, “AI agent autonomy puts CIO controls to the test”, by Liz Hughes (published September 18, 2026) (techtarget.com).
16 governance tools — CIO.com, “16 governance tools for securing your AI fleet”, by Peter Wayner (Feature September 18, 2026) (cio.com). A vendor round-up; the tools are described as their vendors pitch them, so no single product description in it is treated here as a verified capability.
Info-Tech Research Group — PR Newswire, “AI Agents Are Influencing Product Decisions Without Explicit Human Authorization, Warns Info-Tech Research Group” (September 18, 2026) (prnewswire.com). Cited as the trigger for the checklist’s silent-delegation section; no figure from it is used in this note.