What regulators will ask about your agents in 2026

Regulators, auditors and insurers are moving from one question to another. The old question was what happened. The new question is what was authorised, and how do you know. This report sets out the questions coming for organisations that operate autonomous agents, and the evidence each answer has to stand on.

The question is changing shape

For most of the last two decades, oversight questions about systems were observational. What did the system do, when did it do it, and who touched it. Logs, dashboards and audit trails answer that question comfortably, and most organisations answer it comfortably too.

Autonomous agents break the assumption underneath it. An agent that can act across systems, hold delegated credentials and move money does not merely produce events to observe. It exercises authority. Once that is understood, the question an examiner asks stops being what happened and becomes whether what happened was allowed.

Those are different questions, and they are answered with different evidence.

Five questions to expect

Who authorised this agent to act, and what were they authorising. The mandate, in writing, with limits that mean something.

What could the agent actually do at the moment of the action. Not what the policy document says, what the technical configuration permits across every system the agent touches.

How does the agent authenticate, and whose identity does the action carry. The answer that an action was performed under a shared service account is not an answer, it is a finding.

Who approved the agent's specific configuration. Model, tools, permissions, spending ceilings and the boundaries of its scope.

Show me the authority chain for this action. From the mandate, through the delegation, to the technical permission, to the record of what was done, joined up and independently verifiable.

Most organisations that have rehearsed the first three cannot answer the last two. The gap is not a documentation gap. It is a proof gap.

What an answer has to look like

An answer that survives scrutiny has three properties. It is independent, produced by something other than the system being assessed, because no system should grade its own homework. It is specific, connecting the exact action to the exact authority behind it, rather than gesturing at a governance framework. And it is current, because an attestation from a quarterly review says nothing about what the agent was permitted to do last Tuesday.

Screenshot evidence, exported logs and policy documents meet none of these properties. They are useful material, but they are not proof. Proof is a reconstructed chain that holds up outside your organisation.

The insurers are already asking

Regulators move on consultation timelines. Insurers move on renewal cycles, and the renewal is the nearer event. Cyber underwriters are already rewriting the questions they ask about agentic systems, because an agent can cause a real financial loss without anything that resembles a security incident.

The practical consequence is that the organisations best positioned for 2026 are not the ones with the most mature AI strategy. They are the ones that can already produce the evidence, and are treating it as an operating capability rather than a compliance artefact.

What to do about it now

The uncomfortable exercise is free. Take your most consequential agent and try to answer the five questions above from evidence your organisation can produce today, without asking the vendor, without opening a ticket, and without approximating. Where the answer comes slowly or not at all, that is your exposure.

If the exercise produces confidence, 2026 holds no surprises. If it produces a list of gaps, that list is worth more than any readiness survey, because it is drawn from your own systems.

Find out where your own agents stand.