Abstract
Autonomous AI systems operate at a speed, scale, and level of contextual variability that periodic Governance, Risk, and Compliance processes were not designed to address. Models, tools, data, policies, identities, delegations, infrastructure conditions, and risk signals may change between scheduled assessments. By the time a retrospective audit identifies a control failure, an autonomous action may already have produced consequences across multiple systems. This article presents Continuous Governance, Risk, and Compliance — Continuous GRC as a cross-cutting operational governance capability for agentic AI. Continuous GRC connects approved organizational objectives to machine-enforceable policy, runtime authorization, dynamic risk evaluation, continuous control monitoring, governed exceptions, evidence collection, drift detection, and proportionate response. Governance therefore becomes part of the execution environment rather than a separate documentary process. The proposed model does not remove accountable human judgment. Instead, it distinguishes decisions that can be automated from those requiring human approval, escalation, review, or intervention. Control failures, missing evidence, policy drift, elevated risk, expired authority, and abnormal behavior can trigger responses such as narrowed permissions, step-up verification, suspension, revocation, containment, or safe degradation. Within SGAEIA — Secure Governed Autonomous Edge Intelligence Architecture, Continuous GRC links Zero Trust, bounded authority, authenticated delegation, runtime policy enforcement, and Evidence-as-Code into a continuously evaluated governance loop. The model is a conceptual architectural proposal and does not independently establish legal compliance, certification, or empirical proof of control effectiveness.
Suggested citation
Silva, Aridio. (2026). Continuous GRC for Agentic AI. Zenodo. https://doi.org/10.5281/zenodo.22728227
This page provides the author-written abstract and bibliographic metadata for discovery. The Zenodo record is the persistent source for citation, files, version, and license information.