DORA & NIS2 AI governance evidence

Prove that AI agent skills are governed, trained, approved, and reviewable.

Bakara helps security teams create evidence around AI skills, role-based loadouts, training prerequisites, approvals, exceptions, usage, and review history.

The evidence gap

Cybersecurity regulations increasingly expect organizations to demonstrate governance, training, access control, resilience, and management accountability. At the same time, AI agents are gaining access to business systems, sensitive data, developer tools, and operational processes.

Security teams may know who completed training, but not which AI capabilities those users or agents can actually access.

Bakara helps close that gap by turning AI capabilities into governed loadouts with owners, approvals, training prerequisites, monitoring, and audit evidence.

Evidence categories

Six categories of AI capability evidence.

1

AI skill inventory

Evidence to show:

  • Which AI agents and AI-enabled workflows exist
  • Which skills, tools, connectors, and permissions they can use
  • Which systems and data types they can access
  • Who owns each AI capability
  • Which capabilities are considered high risk
2

Role-based access

Evidence to show:

  • Which roles or teams can access each AI capability
  • Which capabilities are restricted, blocked, or approval-based
  • Whether access is aligned to least privilege
  • Whether access is reviewed periodically
  • Whether exceptions expire
3

Training and awareness

Evidence to show:

  • Which modules are required for each role
  • Whether training is completed before high-risk skills are enabled
  • Whether policy acknowledgment is recorded
  • Whether training status affects AI access
4

Approval and accountability

Evidence to show:

  • Who approved each AI skill or loadout
  • Who owns each AI agent or workflow
  • Which skills require human oversight
  • Which changes were reviewed
  • Which exceptions were granted and why
5

Runtime and drift

Evidence to show:

  • When AI skills are used
  • When an agent gains a new tool, connector, or permission
  • When a skill is used outside the approved loadout
  • When a restricted capability is attempted
  • How risky changes are investigated
6

Audit and board reporting

Evidence to show:

  • Current AI capability risk posture
  • High-risk AI skills by business unit
  • Training coverage by role
  • Open exceptions and recent changes
  • Review status and evidence export

How Bakara supports readiness

Map expectations to controls and evidence.

Regulatory expectation

Training and awareness

Bakara control / evidence

Maps training prerequisites to AI skills and role-based loadouts.

Regulatory expectation

Access control and least privilege

Bakara control / evidence

Defines which AI capabilities each role, team, or agent is allowed to use.

Regulatory expectation

Governance and accountability

Bakara control / evidence

Records owners, approvers, review status, and exception history.

Regulatory expectation

Operational resilience

Bakara control / evidence

Helps monitor changes to AI capabilities, tools, workflows, and permissions.

Regulatory expectation

Audit evidence

Bakara control / evidence

Exports evidence for inventory, training, approvals, usage, exceptions, and reviews.

Regulatory expectation

Management reporting

Bakara control / evidence

Provides board/CISO-ready views of AI capability risk and governance status.

Make AI agent governance visible before the audit.

Bakara helps security teams create a live evidence trail for AI capabilities, training prerequisites, approvals, access decisions, exceptions, and reviews.

Bakara supports AI governance, security operations, and audit-readiness workflows. Regulatory obligations vary by organization, jurisdiction, use case, and implementation. This material is not legal advice.