Erik — a Mac Mini on a wooden desk, with a folk-art mug on a coaster to the right and a pink bonsai by the window on the left

Agent Governance Is ISMS in a Different Costume

Somebody on your team has started using AI agents, the governance question just landed in your lap, and the auditor will ask in nine months. The reflex is to hire an ‘AI governance consultancy.’ I want to argue the opposite: if you already run a serious ISO 27001 or 22301 programme, you hold the unfair advantage. Five lessons from running an on-prem agent lab, each mapped onto controls you already operate.

May 29, 2026 · 5 min · Jan Lindquist