While model governance for AI agents has matured, the mechanisms controlling what agents actually do remain underdeveloped, creating a gap that the EU AI Act’s December 2027 compliance deadline is making impossible to ignore. Three layers require attention: per-instance identity credentials tied to human sponsors, audit trails that survive agent-to-sub-agent delegation, and an orchestration layer with runtime policy enforcement sitting outside the agent to gate tool calls before execution. The post provides guidance for CTOs and security leads building agent authorization infrastructure aligned with Articles 9-13 of the EU AI Act governing risk management, data governance, and automatic record-keeping.