Altinn / Altinn/kihub

Epic 6 - Establish Minimum Viable Agentic AI Governance — KITT Team

Open
#74 1 comment 0 reactions 1 assignee Claimed by @MrCarrera View on GitHub
area/kitt priority/critical type/epic
Dominant language
TypeScript
Stars
5
Forks
0
Avg merge
1d 23h
Merged PRs (30d)
6

Description

## Description

KITT team is operating and enabling agentic AI workloads across the BOD department at Digdir, but governance infrastructure does not exist. There is no shared standard for declaring agents, no BOD-wide inventory of what is running in production, and no defined lifecycle for deployment, monitoring, or emergency shutdown. The framework is designed to scale beyond BOD as adoption grows.

This epic establishes the Minimum Viable Governance (MVG) layer required before agent adoption can safely scale across teams.

## Business Goal

Digdir can only responsibly adopt agentic AI at scale if the organisation knows which agents exist, who owns them, what they can do, and how to stop them fast when they cause harm. This epic delivers the foundational governance that makes production agents auditable and controllable.

## Acceptance Criteria

- The organisation has a shared standard for declaring an API-based agent and its ownership
- A registry of production agents exists under the `digdir` GitHub org and is kept current
- A kill-switch protocol is defined
- Any team deploying a production agent follows KITT-defined governance requirements
- Governance artefacts are accessible to all relevant stakeholders across BOD/Digdir

## Prerequisites

⚠️ Prerequisite: Formal accountability for enforcement — a BOD department director must be designated as accountable for compliance with this governance framework — Owner: Project Director

⚠️ Prerequisite: Governance enforcement model — currently policy and guidelines; enforcement mechanism may evolve as governance structure matures — Owner: Project Director + BOD leadership

## Child Issues

- #75 — Create `digdir/agent-registry` repo and define `.agent-card.yml` standard

---

### Guideline coverage tracker (added 11 Aug 2026)

Cross-checked against *Retningslinje for agentisk KI i Digdir v1.0 (15.06.2026)*. This epic is now accountable for all requirements below via its child issues:

- 5.1 Classification scheme — classification & approval-gate issue
- Krav 1 Classification before go-live — classification & approval-gate issue
- Krav 2 Bounded mandate — `.agent-card.yml` mandate/access issue
- Krav 3 Least privilege — `.agent-card.yml` mandate/access issue
- Krav 4 Approval checkpoint — human-approval-gate issue
- Krav 5 Kill-switch — kill-switch protocol issue
- Krav 6 Named owner & registry — #75 (existing)
- Krav 7 Logging & traceability — logging & traceability issue
- Krav 8 Privacy assessment / DPIA — privacy assessment issue
- Krav 9 Prompt-injection defense — prompt-injection defense issue
- Krav 10 Secure decommissioning — decommissioning issue
- Krav 11 Delegation limits — mandate-delegation issue
- Krav 12 Approval points in chains — human-approval-gate issue
- Krav 13 Agent-to-agent trust — prompt-injection defense issue
- Krav 14 Cross-agent traceability — logging & traceability issue
- Krav 15 System-level kill-switch — kill-switch protocol issue

See the mapping doc ("KI-Agentisk-Retningslinje - Backlog-kartlegging.docx") for the full gap analysis this tracker is based on.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.