Articles

Field notes from the runtime layer.

Writing on agentic AI governance, audit substrates, regulatory cadence, and the eighteen-month window between today and the next examination cycle.

September 9, 2026

For Model risk leaders, model validation teams, AI governance leads, CCOs, system integrators, AI compliance counsel

Which Way the Number Points

A governor's grant leaves as a number, and a number carries no direction with it. The enforcement path never has to know which way it points. Every surface a person reads it on does.

A governor sets how much authority the next action carries, and that grant leaves the governor as a number on a bounded scale. A number crossing a boundary carries no direction with it. There are two natural ways to put authority on a scale from zero to one and both are in use, often inside the same deployment. Authority granted, where one is a full grant and zero is a blocked action and the value rises as the assessment of the system improves, which is the sense the enforcement point needs. Constraint applied, where one is a freeze and zero is unconstrained and the value rises as risk rises, which is the sense a risk surface wants. They cover the same interval and run in opposite directions, granted plus applied is one, and neither is self-describing. A misread unit announces itself, since seconds fed into a field expecting milliseconds is absurd by three orders of magnitude. A misread direction produces nothing absurd. Every value stays inside zero and one, every chart renders, every export validates, and the reading is wrong by exactly the amount that matters and by nothing that shows. The worst case is the one most likely to survive review. The governor withheld authority entirely and emits zero, a surface built on the other convention reads that zero as zero constraint applied, and the most restrictive verdict the governor can reach renders as the most permissive state the page can show. Actions carrying a full grant invert into apparent freezes, which produces a question and gets the bug found. The withheld ones invert into silence. What makes this survivable is that enforcement does not read the display. The grant is applied at the enforcement point standing between the proposed action and the actuator, consuming the number in the sense the governor emits it, and an inverted dashboard does not widen a grant or admit an action the envelope refused. The run was governed correctly and the picture of the run was wrong. A system whose safety depends on a person reading a screen correctly has put the control in the screen. The report is still an artifact somebody acts on, and wrong in this direction it causes an unsafe decision about the system rather than an unsafe action. A bound gets relaxed because the page showed room. A review closes because nothing appeared constrained. Every human oversight obligation now on the books names a person and a duty and stops there, and none of them names the artifact the person reads. EU AI Act Article 14 places the oversight duty on the deploying party, with high-risk obligations falling on December 2, 2027 for standalone systems and August 2, 2028 for AI embedded as a safety component under the Digital Omnibus that entered into force on July 27, 2026. Colorado SB 26-189, enacted May 14, 2026 and effective January 1, 2027, requires a reviewer with authority to override who does not default to the system's output. California SB 947 bars sole reliance on an automated decision system to discipline or terminate a worker. Each names a person who has to be able to intervene, and a person intervenes on what they are shown. SR 26-2 took effect on April 17, 2026 and placed generative and agentic AI outside its scope, with the interagency request for information still pending nearly five months later. The NAIC AI Systems Evaluation Tool pilot closes this month across twelve states, with re-exposure through September and October and adoption sought at the Fall National Meeting in November 2026, and its governance exhibit asks a carrier to describe the framework it operates. A description is a rendering too. The fix is to name both quantities and carry both, convert in exactly one place, and assert that granted plus applied equals one on every record rather than trusting review. A scalar that arrives with no declared sense is unknown, and unknown rounds toward less authority. The direction matters most on the counterintuitive grants, because a governor can grant less authority on an action whose present trust reads higher, when its forward look caught a divergence coming before the outcome landed, and rendered in the wrong sense that grant stops looking counterintuitive and starts looking like a defect somebody will go fix.

Read the article →

September 7, 2026

For Model risk leaders, AI governance leads, CISOs, system integrators, AI compliance counsel, chief AI officers

What Counts as One Action

A governor sets how much authority the next action carries. Something upstream decided what one action is, and every bound in the envelope is written in that unit whether or not anyone stated it.

A governor sets how much authority the next action carries, per action, at runtime. Before it can do that, something has to decide what one action is, and that decision is made upstream of the governor, before the run, usually by whoever wrote the integration, and it is almost never written down. The governor receives a proposed action with its boundary already drawn. One tool call, one transaction, one containment step against one host across one window, one maneuver segment. Nothing in the governor establishes that boundary. It reads the declared envelope, assesses divergence, sets the grant, and enforces it on the object presented to it, and the arithmetic is exact on that object with no way to know it was handed the wrong one. A bound is a number and a unit, the envelope states the number, and the unit comes from the integration, so two builds can load the same envelope file, enforce it correctly, and govern two different systems. Envelope bounds fall into families that answer different questions. Reach asks how far one action extends, across targets, hosts, tenants, accounts, or rows. Rate asks how many actions occur per interval. Magnitude asks how much each one moves. They are not interchangeable, and the same measured quantity fed into the wrong family produces a bound that is enforced correctly and means nothing correct. A reach bound does not limit how many events a single action covers, since an action that quarantines one host covers every event on that host and the reach bound was satisfied once. Map one governed action onto each arriving event and a rate bound refuses nearly all of them, on a stream whose arrival rate is a property of the sensor rather than of the risk. Map one governed action onto each target across a window and the same envelope, unchanged, admits the work. When the unit is wrong the shortfall presents as a discovered property of the domain rather than as a bug, and the report reads like governance doing its job under a hard constraint. There is a tell. A real ceiling scales with the consequence of the action, the confidence available at decision time, or the reach of the effect. A manufactured one scales with the arrival rate of the input, so if ingesting the same telemetry at twice the sampling frequency halves the automated share while nothing about the hazard changed, the ceiling is describing the instrument. What gets handed to a person is not governed by the governor. Routing an action to a review queue is a grant of zero authority attached to a claim that something else will decide, and that something else is a channel with a finite throughput. Either the remainder waits, and a containment step deferred four hours is a different action from the same step taken now, or it flows through on approval at the rate it arrives, which satisfies every count in the report and changes nothing about the outcome. Coverage belongs on the constraint side of the design rather than the output side, because when every arriving event falls inside exactly one governed action there is no remainder to route anywhere. The unit of the grant should be the unit of the effect, which makes it a declared object rather than an implementation detail, and for each class of action the envelope should carry what one action is, what it reaches, and how long it runs. The governor can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence coming before the outcome landed, and that forecast is made about a specific action over a specific span, so drawing the boundary wrong leaves the forward look anticipating the wrong thing accurately. Colorado enacted SB 26-189 on May 14, 2026, replacing the 2024 Colorado AI Act, effective January 1, 2027, requiring meaningful human review by a reviewer with authority to override who does not default to the system's output. EU AI Act Article 14 places the human oversight duty on the deploying party, with high-risk obligations falling on December 2, 2027 for standalone systems and August 2, 2028 for AI embedded as a safety component. Both name a path for a decision. Neither states how many decisions per hour that path has to absorb, because an obligation written per decision does not carry a rate, and the rate is supplied by the unit the integration chose. SR 26-2 took effect on April 17, 2026 and placed generative and agentic AI outside its scope with the interagency request for information still pending nearly five months later. The NAIC AI Systems Evaluation Tool pilot closes this month across twelve states, with re-exposure through September and October and adoption sought at the Fall National Meeting in November 2026. An evaluation tool asks what a governance framework covers. The prior question is what one covered thing was.

Read the article →

September 6, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, functional-safety and certification leads, chief AI officers

Field notes, week of September 6, 2026

Three pieces this week on the distance between the moment a bound is written and the moment it has to hold. A safety case fixed before the system is fielded. A grant fixed at an instant the action outlives. A statutory ceiling fixed for a class before any case arrives.

Three pieces this week on timing. Every bound is written at one moment and has to be true at a later one. What sits between those two moments is where the week's argument lives. A declaration fixes a bound once and the run happens afterward, and what a governor adds is a decision taken at the second moment rather than a restatement of the first. The Claim the Safety Case Can Keep took the argument written before a system is fielded, which holds as long as its subject holds, and showed that a governor in the action path shrinks the subject from a system that changes to a control that does not, so the broad claim that a system will not leave its envelope becomes the narrow one that no action carrying authority outside the declared envelope reaches the actuator. The Grant Outlives the Reading took the interval between the grant and the effect, since a governor reads at one instant and the action then takes time to complete, so the horizon of the forward look and the duration of the action are the same quantity, and only widening the margin is always available because decomposing the action and expiring the grant both ask something of the plant. A Fraction of a Decision took California SB 947, the No Robo Bosses Act of 2026, which bars an employer from relying solely on an automated decision system to discipline or terminate a worker, and showed that a decision does not divide while the authority behind it does, so the statute fixes a ceiling for a class and a governor sets the grant for the case. The Legislature approved SB 947 on August 31, 2026 by 53 to 14 in the Assembly and 28 to 10 in the Senate, and the Governor's window to sign or veto closes on September 30, 2026, with an operative date of July 1, 2027 if it is signed. The European calendar has the same shape at a larger scale. The Digital Omnibus entered into force on July 27, 2026 and moved the EU AI Act high-risk obligations off August 2, 2026 to December 2, 2027 for standalone systems in the Annex III list and August 2, 2028 for AI embedded as a safety component under Annex I, while Article 50 transparency duties, the Article 5 prohibited-practices regime, and the obligations on general-purpose model providers all stayed where they were. A deferral moves the date the argument is due and not the date the systems go into service. SR 26-2, the revised interagency guidance on model risk management effective April 17, 2026 alongside OCC Bulletin 2026-13 and FDIC FIL-15-2026, placed generative and agentic AI outside its scope and promised a request for information that has not issued nearly five months later. The NAIC AI Systems Evaluation Tool pilot has run since March 2026 across twelve states and closes this month, with re-exposure through September and October and adoption sought at the Fall National Meeting in November 2026, and an evaluation tool is the list of questions a regulator will ask, which becomes the shape carriers build their files to. A bound written in advance is a statement about a class, and an action is a member of a class only in retrospect. A governor can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence coming before the outcome landed. No document written in advance can do that, and no review step added afterward can do it either.

Read the article →

September 4, 2026

For Model risk leaders, AI governance leads, employment and AI compliance counsel, CCOs, HR technology owners, system integrators

A Fraction of a Decision

California passed a law on August 31 barring an automated system from deciding a firing on its own. Solely is a word about authority, and authority is the one part of a decision that actually divides.

On August 31, 2026 the California Legislature approved SB 947, the No Robo Bosses Act of 2026, by 53 to 14 in the Assembly and 28 to 10 in the Senate. It bars an employer from relying solely on an automated decision system to discipline or terminate a worker. The bill is with the Governor, and its requirements become operative on July 1, 2027 if it is signed. Solely is a word about how much authority the system carried on one decision, and no legislature had written the bound that way before. Most AI legislation bounds one of three things. What data may enter, what purpose the output may serve, and who has to be told. This one bounds how much of the decision the system was allowed to be. Read literally, solely describes a share, so the system supplied less than all of the decision and some remainder came from somewhere else. The trouble is that a decision does not divide. A worker is terminated or is not, and there is no ninety percent of a firing. What divides is the authority behind it. Two arrangements satisfy the statute identically on paper. In the first a reviewer reads the file, has access to what the system did not see, and reaches a different outcome often enough to matter. In the second a reviewer receives a queue of recommendations and approves them at the rate they arrive, the system's effective authority over the outcome is total, and the language is still satisfied. The bill anticipates this and asks for independent corroboration rather than review alone, which means a second determination reached from something other than the first system's output. What makes a determination independent is a property of the path the decision travelled, and a statute cannot inspect a path, it can only require that one exist. SB 947 sets its bound by category and sets it once, drawn before any particular case arrives by a legislature that will never see one. A governor works at the other end, setting how much authority the next action carries per action at runtime against an envelope declared before the run and outside it, starting from withheld and granting only what it can assure. The statute fixes a ceiling for a class. A governor sets the grant for the case. The bill also prohibits predictive behavior analysis, and that prohibition and a governor's forward look are easy to confuse. The banned forecast takes a person's data, predicts what the person will do, and is used to act on the person ahead of anything they have actually done. A governor's forward look takes the governed system's own realized behavior and predicts where it is heading relative to what the system was assured to do, so its subject is the system rather than a person and its consequence runs the other way. A governor can grant less authority on a decision whose present trust reads higher, because its forward look caught a divergence coming before the outcome landed, and the forecast is used to make the system do less. If the bill is signed, employers have until July 1, 2027, and the artifact most of them will produce is a policy stating that no automated system decides alone plus a review step in the workflow. A policy asserts the bound. A control holds it. The difference appears in the path between the recommendation and the effect, and if the termination can be executed without the grant then the bound describes intended behavior rather than actual behavior. Five days earlier, on August 26, 2026, the Australian Securities and Investments Commission published its Corporate Plan for 2026-27 and wrote that AI use must not weaken accountability. Two jurisdictions, one week, the same shape. The obligation is named in public and the mechanism is left to whoever builds it.

Read the article →

September 2, 2026

For Model risk leaders, AI governance leads, autonomous-systems safety engineers, CISOs, system integrators, chief AI officers

The Grant Outlives the Reading

A governor sets authority on an assessment taken at one instant, and the action it grants takes time to land. The forward look has to reach at least as far as the action runs, or the grant is holding a bound against a world that has already moved.

A governor sets how much authority the next action carries, and it sets that at one instant, on what it can read at that instant. The action then takes time to complete, and everything between the grant and the effect is covered by a reading that is already behind. Per-action governance carries an assumption that usually goes unstated, that the action is an event with no width, decided at one moment and finished at the same moment. Some actions are close enough. A message emitted, an authorization returned, a single write to a row. Many are not. A funds transfer settles across an interval, a batch job runs against a remote system for minutes, a physical maneuver holds continuous actuation for seconds, and an agent tool call opens a connection, negotiates, waits, and returns when it returns. For those the grant is issued at one time and the effect lands at another, so the assertion that the action sat inside the declared envelope leaves open when it was true. The governor can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence coming before the outcome landed, and that forward look is a forecast with a horizon. The horizon of the forward look and the duration of the action are the same quantity. A forecast that reaches one second, applied to an action that runs for ten, covers the first second, and the grant stays in force across all ten because a grant does not know how long the thing it granted takes. Forecast quality falls with horizon, so a long action pays twice, once for the longer interval and once for the worse estimate covering it. Three moves close the interval and they are not interchangeable. Shorten the action by decomposing it into steps short enough that each gets its own grant, which requires the action to be decomposable and a settlement or a maneuver often is not. Shorten the grant with an expiry that lets authority lapse mid-flight, which requires the enforcement point to take authority back from work already in progress. Widen the margin by granting less than the forward look supports, which asks nothing of the actuator and costs capability on every action. Only the third is always available, and which of the first two is available is a property of the system being governed rather than of the governor. Withdrawal is a different operation from refusal. Refusal happens before the action starts and leaves nothing behind. Withdrawal happens to an action already underway and leaves a partial effect that something has to own, half a settlement, a maneuver stopped mid-arc, a batch that wrote some of its rows. An enforcement point built to refuse has exactly one moment of leverage, and attaching an expiry to a grant does not manufacture a second one, it produces a note that the first moment has passed. An action that cannot be stopped once it starts has to be granted on a forward look that covers its whole length, or not granted. The envelope therefore has to carry, for each class of action, how long that class runs and whether authority can be taken back once it has started, and both are facts about the plant and the integration rather than about the model. An action class with no stated duration is treated as the longest the envelope admits, and one with no stated interruptibility is treated as uninterruptible, both rounding toward a smaller grant. SR 26-2 took effect on April 17, 2026 and placed generative and agentic AI outside its scope with the interagency request for information still pending. EU AI Act high-risk obligations, Article 9 among them, fall on December 2, 2027 for standalone systems and August 2, 2028 for AI embedded as a safety component, and Article 9 asks for a risk management system that runs continuously across the lifecycle, which is a statement about intervals rather than about instants. The NAIC Model Bulletin has been adopted in more than half the states and the NAIC AI Systems Evaluation Tool pilot runs through September 2026 across twelve states. Each of these instruments asks about the decision. None of them asks how long the authorization was good for.

Read the article →

August 31, 2026

For Autonomous-systems safety engineers, functional-safety and certification leads, model risk leaders, AI governance leads, AI compliance counsel

The Claim the Safety Case Can Keep

A safety case argues that a system is acceptably safe, and it is written before the system is fielded. A governor in the action path shrinks the object the argument has to hold, from a system that changes to a control that does not.

A safety case is a structured argument, supported by evidence, that a system is acceptably safe in a stated operating context. It names a system, names the context, states the hazards, and holds as long as its subject holds. That constraint was affordable when the subject was a fixed artifact, verified once and fielded, computing ten years later what it computed on the day the case was signed. An adaptive system is a different subject. Its behavior in month nine is not the behavior the case examined in month zero, every material change reopens the argument, and the interval between changes falls below the interval a re-argument takes. The claim a conventional case makes is broad. This system will not leave its envelope. That subject is large, it moves, and the evidence behind it is a sample of behavior collected under conditions the evaluator chose, binding no run that has not happened yet. A governor in the action path supports a narrower claim. No action carrying authority outside the declared envelope reaches the actuator. That subject is a control which sits in one place, adds no intelligence of its own, and does not learn, and a property of a path is established by inspecting the path. The narrow claim covers the same hazards through a smaller object. The governor sets, for each action, how much authority that action carries, reading a bound declared before the run and outside it, starting from withheld and granting only what it can assure. It can grant less on an action whose present trust reads higher, because the pullback is set on where the action is going rather than on how clean it looks right now. Four questions about it are answerable by inspection and fixed at build time. Whether the enforcement point sits on the only path to a durable effect. What an action carries when no grant arrives. Which direction an uncertain forward look rounds. Whether a grant already set can be widened from inside the run. Three debts stay with the case. The governor does not make the envelope right, since declaring the bound is a separate act with a separate owner and a governor holding a wrong envelope holds it exactly. Coverage is the second, because a hazard that perturbs nothing the governor measures produces a clean reading and a full grant, so the measurement carrying evidence of each hazard belongs in the declared envelope beside the bounds. Placement is the third, since a governor beside the actuator rather than in front of it returns the argument to a promise. SR 26-2 took effect on April 17, 2026 and placed generative and agentic AI outside its scope with the interagency request for information still pending. EU AI Act high-risk obligations, Article 9 risk management among them, fall on December 2, 2027 for standalone systems and August 2, 2028 for AI embedded as a safety component, and the embedded date is the one that lands on functional safety practice. Article 9 asks for a risk management system that runs across the lifecycle, iterative and kept current, and against a system that changes between reviews the version that closes is the one where a control in the path holds the bound continuously and the periodic review examines the control.

Read the article →

August 30, 2026

For Model risk leaders, model validation teams, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Field notes, week of August 30, 2026

Three pieces this week on what can be established about a governor at all. A corpus number describes the estimator standing next to it. A historical log stops describing the run at the first grant. A clean reading is evidence of coverage only where coverage was declared.

Three pieces this week on evidence. What a number measured on a corpus says about a governor. What a historical log can establish about a control that changes the sequence. What a clean reading is evidence of. A governor is checked rather than scored, and the properties that make it checkable were fixed before the run started. The Governor Has No Accuracy separated the two components standing in front of a governed action, one that estimates and one that bounds, and showed that the quoted number belongs to the estimator while the governor is answerable by inspection. A Governed Run Is a Different Run showed why a historical log cannot score a control that changes the sequence, since a replay is faithful up to the first intervention and fiction after it, and the anticipatory case is where scoring against history goes furthest wrong, because the governor can grant less authority on an action whose present trust reads higher, having caught a divergence before the outcome arrived. The Quiet Channel showed that whether a failure is visible at all is a property of the failure and its relationship to the channels the governor reads, so a control blind to a fault class is not degraded on it, it is clean. The federal move this month was to evaluate the model. The White House finalized a voluntary frontier AI safety testing framework and briefed it to industry on August 4, 2026, administered by the Center for AI Standards and Innovation inside NIST, opening a thirty-day pre-release access window for cybersecurity evaluation and creating no licensing or preclearance requirement. It reaches closed-weight frontier models, and open-weight releases sit outside it. A pre-release evaluation is a measurement taken on an artifact under conditions the evaluator chose, before the artifact has been placed in anything. The object it scores is the model. The object that acts in production is an agent built on that model, holding credentials, calling tools, and taking thousands of actions inside a single engagement. The evaluation is a claim about the artifact. A grant is a change to the action. SR 26-2 took effect on April 17, 2026, and the interagency request for information on generative and agentic AI the agencies said would follow has not issued, so the accumulating federal record is a Congressional one gathered without an instrument standing behind it. Tracking three things: whether the agent interoperability profile slated for the fourth quarter settles reach or only identity, whether a pre-release evaluation of a model gets cited as assurance about a deployment, and the UNECE guidance document under the automated driving system requirements, where the definition of adequate evidence for autonomous systems is being written paragraph by paragraph in public. A regulator deciding what evidence looks like is doing more consequential work than a regulator deciding whether a system is safe.

Read the article →

August 28, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, system integrators, chief AI officers

The Quiet Channel

A governor sets authority by reading divergence, and divergence has to show up in something it measures. A failure that leaves those channels undisturbed produces a clean assessment and a full grant, and nothing in the run reports that anything was missed.

A governor sets how much authority the next action carries by reading how far realized behavior has moved from what the system was assured to do, and that reading is taken in particular channels. Whether a given failure is visible at all is a property of the failure and its relationship to those channels. Two families of signal carry most of what a runtime control can see. Agreement, which asks whether several independent sources for the same quantity still say the same thing. Magnitude, which asks how far a realized value sits from the reference for it. They are silent in opposite places. A fault living in one source relative to the estimator that consumes it leaves every other source correct, and because they are correct they still agree, so the agreement signal reads healthy and reads healthy accurately while the residual carries the entire fault. A disturbance that corrupts every source at once, a spoofed reference, a jamming source, a clock or power fault, leaves each source internally plausible while their mutual agreement falls apart. A governor reading one family and not the other is not degraded on the class it cannot see. It is clean. It reports a healthy assessment, issues the widest grant it has, and the run proceeds with the control fully behind it. The same forward look that lowers authority on a step whose present trust reads higher is only as wide as the channels it reads. The pattern is not particular to sensors. An agent whose retrieved context has been corrupted through one upstream source emits tool calls that are internally consistent, arrive at the expected rate, and satisfy every check written about the shape of the call. When a signal fails to separate a fault class, moving the threshold until a separation appears fits the instrument to the answer and carries that fit into production as confidence. The alternative is to ask whether the fault physically perturbs the quantity being measured and accept the null when it does not. Coverage belongs in the declared envelope beside the bounds. For each hazard, name the measurement that carries the evidence of it developing, and treat a hazard with no measurement behind it as a stated gap that starts from a lower grant, because a class the forward look cannot observe is the limiting case of an uncertain forward look. The EU AI Act high-risk obligations fall on December 2, 2027 for standalone systems and August 2, 2028 for AI embedded as a safety component, and a logging duty records what the chosen channels saw rather than what they were never able to see. SR 26-2 took effect on April 17, 2026 and pointed institutions at practice that knows how to challenge a number a model produced. This failure produces no number to challenge. A quiet channel and a clean system produce the same reading, and only the declaration distinguishes them.

Read the article →

August 26, 2026

For Model risk leaders, model validation teams, AI governance leads, CCOs, autonomous-systems safety engineers, chief AI officers

A Governed Run Is a Different Run

A detector reads a sequence without touching it, so a historical log can score it. A governor changes the sequence, so the log stops describing the system the moment the first grant lands.

A governor sets how much authority the next action carries, and the amount it grants changes what the system does next. That is the point of putting it there. It is also the reason the usual validation move does not survive contact with it. Take the log of a run that already happened, stand the candidate control over it, and count the actions it would have stopped. That procedure is sound for a component that watches and breaks on a component that acts. Every historical agent log is a record of a run where nothing intervened, causally closed on itself. Put a governor on that path and the first reduced grant breaks the chain. The action that executes is narrower than the one proposed, the state that follows is not the state in the log, and the agent makes its next proposal from a position it never occupied in the recorded run. A replay is faithful up to the first intervention and fiction after it. The longer the run, the smaller the fraction of the log that still means anything, and agent runs are long by construction. Shadow mode answers one narrow question. At the moment of a known bad action, did this control lower authority. The deployment question is what the run looks like once the grants land, and in a shadow run the grants never land. The anticipatory case is where scoring against history goes furthest wrong, because a governor can grant less authority on an action whose present trust reads higher, having caught a divergence before the outcome arrived. At that step the telemetry is clean and the labels say benign, so a scorer marks the correct call an error. A detector is a function and a corpus is a fair test of it. A governor is a loop, and the action that executes under its grant produces the telemetry it reads on the following pass, so no fixed corpus stands outside it. What can be established about a loop is the set of properties that hold on every pass. Whether the enforcement point sits on the only path to a durable effect. What the action carries when no grant arrives. Which direction an uncertain forward look rounds. Whether the envelope can be rewritten from inside the run. The counterfactual is unavailable and the governed run is not. On every action there is what the agent proposed and what the governor granted, and the difference between them is the intervention stated at the moment it happened. SR 26-2 took effect on April 17, 2026 and placed generative and agentic AI outside its scope while pointing institutions at existing model risk practice. The NAIC Model Bulletin, adopted in more than half the states, asks carriers for evidence that AI systems were tested before deployment and monitored after. Both are written for components that estimate, and a backtest of a bound measures a run the bound would never have allowed to happen.

Read the article →

August 24, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, system integrators, chief AI officers

The Governor Has No Accuracy

A detector makes a claim about the world and can be wrong about it. A governor applies a declared bound to a number it did not produce, so its correctness is read off the construction rather than measured on a corpus.

A governor sets how much authority the next action carries. It does that by applying a bound it did not write to a number it did not produce. Ask how accurate it is and the question has landed on a different component. Two things stand in front of a governed action. One estimates. The other bounds. They are usually sold as one product and evaluated as one number, and the number that gets quoted belongs to the estimator. A detector makes a claim about the world, and a claim about the world can be false, so a detector has an error rate and the error rate is the honest way to describe it. A governor makes no claim about the world. It receives an estimate, reads a bound declared before the run, and sets the authority of the action in front of it. Whether it did that correctly is answerable by inspection. Was it on the path the action had to take. Did it produce a grant before the action ran rather than a verdict after. A detector is scored. A governor is checked. When a governance product is asked how accurate it is, the figure that comes back was measured on a corpus, in one domain, at one operating point, and it does not travel the way the procurement conversation implies. An estimator trained on the failure classes someone had labels for degrades on the classes nobody had labels for yet, and that open-set case is the one that arrives in production. The governor does not know what a process plant is. A payment, an intrusion, a grip force, and a flow rate arrive at it in the same shape, and that ignorance is what makes the component portable across an aircraft's control surface, a robot arm's grip, and a plant's valve. A component with no model of the domain cannot be wrong about the domain. It can only be wrong about the rule, and the rule is short enough to read in full. The two outputs also move independently, which is how the governor can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence before the outcome landed. What is left to verify is structural. Whether the governor is on the only path to the effect, what the action carries when no grant arrives, whether an uncertain input grants less or more, whether a grant already set can be widened from inside the run. SR 26-2 took effect on April 17, 2026 and placed generative and agentic AI outside its scope while pointing institutions at existing model risk practice, and existing practice knows how to challenge a number a model produced. A control whose correctness is structural does not fit that template.

Read the article →

August 23, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Field notes, week of August 23, 2026

Three pieces this week on the bound going missing while everything that reports on it still reads correct. Missing in time, missing in scope, missing from the artifact that shipped.

Three pieces this week on absence. A governor that cannot answer before the action runs. A grant that bounds the step and not the run. A build that ships without the stage that changes what executes. In all three the control is up, its output is well formed, and its own reporting reads healthy. What holds the bound cannot be the thing that reports on the bound. When the Governor Cannot Answer took the case where the window closes with no grant in hand, and what happens then was decided when the enforcement point was written. Each Step Was Inside the Bound took the run that stays inside every grant it was given and still lands where the envelope forbids, which is why the grant has to be drawn against a quantity the run consumes, and why authority can fall on a step whose present trust reads higher. Decide, Record, Do Nothing took the build packaged without its enforcement point, which still starts, still scores, still signs, and no longer changes what runs. The open federal record on agentic AI in United States financial services is now a Congressional one. The House Financial Services Committee minority's request for information closed on August 14, 2026, with responses recommending human oversight of consumer-facing AI and disclosure of the role AI played. SR 26-2 took effect on April 17, 2026 and placed generative and agentic AI outside its scope pending an interagency request for information that has not issued four months later. Human oversight named at the level of the firm is discharged at the level of the action, and oversight discharged as review is a throughput ceiling. Tracking three things: whether voluntary agent standards written during the sixteen-month deferral choose identity or reach as the governed object, whether oversight gets specified as an amount, and whether the claim rests on the detector or on the envelope. How detectable a failure is turns out to be a property of the fault class rather than of the control. A bound on what an action may reach never had to recognize anything first.

Read the article →

August 21, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, system integrators, chief AI officers

Decide, Record, Do Nothing

Assessment produces a score and the audit stage produces an artifact. Enforcement produces an absence, and an absence is the one thing a build can lose while every check downstream still passes.

A governor packaged without its enforcement point still starts. It reads telemetry, sets an authority grant on every action, and signs every decision it made. The one thing it no longer does is change what runs. Observe, assess, modulate, enforce, audit. Four of those stages leave something behind. Enforcement leaves the action that did not happen. A write confined to a narrower scope than the one requested. A transfer capped below the amount proposed. A command that was never issued at all. Enforcement is the only stage of a governor whose output is an absence, and an absence cannot be looked up. Ask whether the governor is running and a build with no enforcement point answers yes. Ask whether it is producing decisions and it produces a stream of them. Ask whether the chain verifies and it verifies. A governor rarely reaches the system it governs as source. It reaches it as a package. A vendored snapshot. A container image. A static library linked into a firmware bundle, cut at one moment and carried into a build the governing team does not own and cannot watch. Copies drop things, and none of that requires an adversary. The record such a build produces is well formed and true about itself while it stops being a statement about what the actuator did. The entry says authority was reduced. The action ran as proposed. A version string is a claim about provenance made by the artifact whose provenance is in question, so the check that holds compares the shipped package against the canonical engine by capability. Which translation units are present. Whether the enforcement point is among them. A control that can start in a configuration where it changes nothing will eventually ship in that configuration, which is why a governor with no enforcement point on the action path should refuse to come up at all. The EU AI Act high-risk obligations fall on December 2, 2027 for standalone systems and August 2, 2028 for AI embedded as a safety component, and the embedded case carries the longest distance between the artifact that was assessed and the artifact that was installed.

Read the article →

August 19, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, chief AI officers

Each Step Was Inside the Bound

A governor sets how much authority one action carries. A run is thousands of actions, and an agent can stay inside every grant it is given while the run arrives where the envelope forbids.

A governor sets how much authority the next action carries, and it sets that amount fresh on every action. A run is thousands of actions. If the only object the governor bounds is the action in front of it, an agent can stay inside every grant it was given and still land the run somewhere the envelope forbids. Nothing was exceeded at any step. The envelope was exceeded by the sequence. An envelope is written about outcomes, and a ceiling on a single action is a proxy that holds only while the action and the outcome are the same size. They stop being the same size the moment a system takes many actions to do one thing. A write confined to a narrow scope, taken across enough scopes, covers the store. A transfer capped below a review threshold, repeated, moves the amount the threshold was installed to catch. Reading one record is not a disclosure. Reading the table is. None of that is an evasion technique in the first instance. An agent handed a goal breaks it into steps small enough to execute and check, so the control that reads one step is looking at the cleanest evidence the run will ever produce, by construction. The grant has to be drawn against a quantity the run consumes, so reach already taken is an input to the next grant and authority falls as the run spends it. That is where the governor produces its least intuitive result. It can grant less authority on a step whose present trust reads higher, because its forward look caught where the accumulation was heading before the outcome landed. The accounting cannot live with the agent, and it has to travel with delegated authority, or the cheapest way to refill a depleted budget is to start a new worker. SR 26-2, effective April 17, 2026, placed agentic AI outside its scope and pointed institutions at existing model risk practice, which validates the decision. When a system takes a thousand actions to reach one outcome, the aggregate has no owner in the framework as written.

Read the article →

August 17, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, chief AI officers

When the Governor Cannot Answer

A governor sets the authority of each action before it runs. What the action carries when no grant arrives, because the governor was late or because it was gone, was decided at build time, and that decision is the bound.

A governor sets how much authority the next action carries, and it has to set it before the action runs. The deadline is fixed by the run, not by a latency target the operator picked, and the work behind it is real. The governor is projecting where the next step is heading, which is the part that takes time and the part that can grant less authority on a step whose present trust reads higher. So the window sometimes closes with nothing in hand. The forward look does not resolve in time. The telemetry stops arriving. The process is starved or restarting. The path between the enforcement point and the governor is partitioned while both ends are healthy. Different causes, one shape: an action is held, the clock has run out, and there is no grant. What happens then was decided when the enforcement point was written, and often it was not decided at all, because the branch that forwards the action as proposed is the branch that gets written when the case is treated as an error path. Two builds that behave identically every day the governor is up differ on the day it is not, which is the day the control exists for. If absence of a grant means the action runs as written, the cheapest route past the bound is around the governor's availability rather than through its judgment. Starve it, flood it, partition it, cut off its telemetry. A saturated host and a bad deploy reach the same place with no adversary at all. So whatever holds when the governor is gone cannot be held by the governor. It sits in the enforcement point, on the path the action takes, and it is graded rather than uniform, because the safe state of a payment is to do nothing and the safe state of a vehicle at speed is not. Which class an action falls into is declared in the safety envelope before the run, by the party accountable for the outcome, not adjusted at runtime when the holds get inconvenient.

Read the article →

August 16, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Field notes, week of August 16, 2026

Three pieces this week on the grant. Where it lands, what stops it from being widened, and why the bound is the part of oversight that scales. Then the week produced its own demonstration, in forensics published on August 12 on a multi-agent system that widened its own reach over four days.

Three pieces this week on the grant, the amount of authority a governor sets on one action. Where it lands. What stops it from being widened. Why it is the part of oversight that survives scale. A verdict is a label placed beside the action. A grant is a change to the action that runs. What Reaches the Actuator put the amount on the action itself, so the actuator sees the action the governor allowed rather than the one the agent proposed. Optimized to Allow showed why the grant cannot be tuned open, because the envelope is declared outside the run and getting out of the way is not one of the grant's inputs. Half the Operations read a sovereign conversion target and found that what scales is the bound, not the review. The week then supplied the case in the negative. On August 12, 2026 security researchers published an account of the first publicly reported near-autonomous AI attack on a state. Over four days a multi-agent framework ran twelve waves against Taiwanese government systems, mapped twenty-one of them, compromised eighty-five accounts, and then extended on its own to the country's nuclear safety regulator and to energy companies outside the original set. Every credential stayed valid. What grew was reach, and reach is the quantity nothing in the path was setting. The obligations moved out the same month. The Digital Omnibus pushed the Annex III high-risk duties from August 2, 2026 to December 2, 2027, with embedded high-risk AI moving to August 2, 2028. A sixteen-month extension is a change to a calendar. It is not a change to what a credentialed agent action can do in the interval. Tracking three things: whether the obligation moves from identity to reach, what gets built in the sixteen months, and whether authority reduced inside a run is permitted to climb back. A reduction that can be undone from inside the run is not a bound.

Read the article →

August 14, 2026

For AI governance leads, model risk leaders, CCOs, public-sector technology leads, AI compliance counsel

Half the Operations

A government set a two-year deadline this week for converting half of its federal operations to agentic AI, under the stated principle that a human leads and AI enables. A target fixes how many actions agents will take. How far each one may reach is set by a control standing in front of it.

On August 9, 2026 the United Arab Emirates opened the strategic phase of its National Agentic AI Project. The stated target is to convert fifty percent of federal government operations, services and tasks to agentic AI models within two years. Seven areas are named, among them policy development, governance, and government performance. The guiding principle is stated as human leads, AI enables. Nearly every agentic-AI governance event of the past year attached a duty to agents someone had already decided to run. This one decides to run them, at sovereign scale, on a clock. A rule creates an obligation on a system that already exists. A target creates the systems. The target is precise about how many and silent about how far each action may reach, and no percentage fixes that second quantity. A share of operations converted resolves into a rate of individual acts per day taken by a system rather than by a person. Leading at that density is an authority relation, not an attendance requirement. A person who approves every agent action becomes the throughput ceiling of the government. A person who approves none holds a principle with no mechanism under it. What scales is not the review. It is the bound. A human sets how much authority a class of action may carry, and a control in the path of every action holds that grant when no one is watching. That control sets the grant on where the action is heading rather than only on how clean the present step looks, and it can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence before the outcome landed. Two years is long enough to build the control into the conversion and short enough that a program which defers it will convert first and govern second.

Read the article →

August 12, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, chief AI officers

Optimized to Allow

A safety control tuned to stay out of the way grants more than it should over time. The two mistakes it can make cost different amounts and land at different times, and optimizing the one the operator feels rounds the grant open.

A runtime control standing in front of an action can be wrong two ways. It can stop an action that was fine, or it can pass an action that breaches the envelope. The two mistakes cost different amounts and land at different times. A false stop bills immediately, in friction the operator feels and the tuner hears about. A missed bound bills later, when the effect surfaces, often on someone else's desk. Put those two bills in front of anyone tuning a control and the incentive is one-directional. Widening the grant removes the cost that is felt and defers the cost that is not, so a safety layer measured on staying out of the way drifts open on its own, one reasonable adjustment at a time, until it clears the case it was installed to catch. A governor has nowhere to drift. It sets the grant against a declared envelope held outside the run and not rewritable by the operator under friction, and it starts each action from least authority. Getting out of the way is not one of the grant's inputs. The only party who can widen the bound is the one who declared it, on the record. What holds the line is the part of the control the pressure cannot reach.

Read the article →

August 10, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, chief AI officers

What Reaches the Actuator

A gate returns a verdict about an action. A governor returns the action itself, cut to the authority it granted, so the only thing that reaches the effect is the action already bounded to what the grant allows.

A governor sets how much authority an action carries, and then it makes that grant real by handing the actuator the action already cut to it. Most controls stop one step earlier. They read the action, return a verdict, allow, block, or send it to a person, and let the action itself pass through as the agent wrote it. A verdict is a label placed beside the action. A grant is a change to the action that runs. Authority is a quantity, how far this action may reach, and a gate collapses it to one bit at the threshold. The governor keeps the quantity and lands it on the action. When it grants less than the action asked for, the enforcement point constructs the bounded action and hands the actuator that. A write is confined to a narrower scope. A transfer is capped below the amount proposed. The actuator never sees the action the agent proposed. It sees the action the governor allowed, and reduced authority becomes a property of what executed rather than a note beside it. The governor can hand the actuator a smaller action on a step whose present trust reads higher, because its forward look caught a divergence before the outcome landed. The allow-modify-block middle setting does not reach this. Modify swaps in another preset that runs whole, while modulation is a continuous cut on this specific action, set to a grant computed fresh every time, and no menu is long enough to hold every value it can take.

Read the article →

August 9, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Field notes, week of August 9, 2026

Three pieces this week on the governor as a minimal control. It withholds authority by default and grants only what it can assure, it sits below the intelligence and adds none of its own, and the first financial supervisor to bring agents in scope put the duty at the one altitude where a control this spare can hold it.

Three pieces this week on a governor built from subtraction. The Burden of Assurance set the direction of its default: withheld, granting only what a forward look can positively assure against the declared envelope, because absence of a bad signal is not assurance. Below Intelligence set its altitude: under the model that decides and above the control that executes, adding no intelligence of its own and reading one quantity, how far realized behavior is diverging from the assured trajectory. In Scope, Before the Action read the week's regulatory move. The Monetary Authority of Singapore confirmed agentic AI sits inside its binding AI risk-management guidelines, the first major financial supervisor to bring autonomous agents into scope rather than carve them out. Three supervisors now stand at three altitudes over one action. The United States carved agentic AI out under SR 26-2 pending an interagency request for information. The European Union's August 2 powers reach the provider after the effect. Singapore put the obligation closest to the run, under a principles-based framework that leaves the mechanism to the institution and places the burden of proof on it. A control this minimal can still grant less authority on an action whose present trust reads higher, because its forward look caught a divergence before the outcome landed, and that is the property that makes the bound hold when the action is the one no classifier was trained to catch.

Read the article →

August 7, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

In Scope, Before the Action

This week a financial supervisor put autonomous agents inside its binding guidelines and asked institutions for oversight across the AI lifecycle. A principle names the duty. A governor standing in front of the action is what discharges it while there is still an action to bound.

This week the Monetary Authority of Singapore confirmed that agentic AI sits inside its supervisory Guidelines on Artificial Intelligence Risk Management, expecting board and senior management oversight and sound controls across the AI lifecycle. It is the first major financial supervisor to bring autonomous agents into scope rather than carve them out. Three supervisors now stand at three altitudes over one object. The United States carved agentic AI out of model-risk scope under SR 26-2 pending an interagency request for information. The European Union's powers that became applicable on August 2 reach the provider, on inspection, after the effect has landed. Singapore brought the agent in scope now, under a principles-based framework. Principles-based supervision names what has to hold and leaves the mechanism to the institution, and the mechanism is where an agent parts from a scored model. A model returns one output and stops. An agent acts thousands of times inside a single run. Oversight of a model is a review. Oversight of an agent is a control that operates at the speed the agent operates, standing in the path of the action and setting how much authority the action may carry against a declared envelope. A duty named at the level of the institution is discharged at the level of the action. The governor can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence before the outcome landed. A principles-based regime places the burden of proof on the institution, and the institution that ran a governor in the path can show the authority it set, the envelope it measured against, and the divergence that moved the grant.

Read the article →

August 5, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, chief AI officers

Below Intelligence

A governor bounds how much authority an action carries. It does not choose the action, and it adds no intelligence of its own. It sits below the intelligence that decides and above the control that executes, and that placement is the whole of what it is.

When an agent does something someone has to answer for, the reflex is to put something smarter above it. A supervisor agent, a judge model, a critic that re-plans the step. Each is another adaptive system that drifts, can be injected, and has bad days of its own, so stacking it on top moves the unanswered question up a level rather than bounding it. A governor is not a second opinion. It does not propose a better action. It takes the action the agent already chose and decides how much authority that action may carry against a declared envelope. Choosing the action and bounding it are two different jobs. A control placed above the intelligence has to be at least as capable as the thing it overrules, and then it is the new top of the stack with the same question on it. A control placed below needs one quantity. How far realized behavior is diverging from the trajectory the agent was assured to follow. It can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence before the outcome landed, and it caught it without understanding the task. The agent stays as capable as it can be. Every action still carries only what the governor granted.

Read the article →

August 3, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, chief AI officers

The Burden of Assurance

A governor does not start an action at full authority and pull some back when a signal trips. It starts from withheld and grants only what it can positively assure. The direction that default rounds is the safety property, and most controls round the other way.

A governor sets how much authority the next action carries, and the whole safety question is the direction of its default. A control that permits by default and subtracts on a recognized problem is bounded only against the problems it already recognizes. Absence of a matched signal is not assurance, it is absence of information, and the action governance exists for is the one no classifier was trained to catch. A governor inverts the burden. An action does not carry authority because nothing objected. It carries the authority the governor granted against a positive read of where the action is heading relative to the declared envelope, and when that read is thin the grant is small. Not because the action is suspect, but because nothing yet establishes that it is safe. When telemetry drops, when the situation is one the envelope never named, when the forward look has not resolved before the action's deadline, the governor grants less, not more. It can withhold authority a step has not earned even when the present looks clean, because looking clean now is not being assured where the step is heading. Least authority is the resting state, re-set on every action, and the unproven action runs reduced until it earns more.

Read the article →

August 2, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Field notes, week of August 2, 2026

Three pieces this week on where a control has to stand to bind an action. The reference it grades against is declared outside the run, the bound holds only on the only path to the effect, and a power that inspects the provider after the fact stands above it.

Three pieces this week on placement. A runtime governor's authority to bind an action comes from where it stands relative to the action, not from the policy it carries. The declared envelope puts the reference outside the run, so the acting system cannot move the line it is graded against. The construction puts the bound on the only path to the effect, so the agent cannot reach the actuator around it. And the enforcement power that became applicable today stands at a third place, above the provider and after the fact. From August 2, 2026 the European Commission holds enforcement powers over general-purpose AI model providers: request documentation, evaluate the model, order withdrawal, impose penalties. Every one acts on the provider and the model as a product, on inspection, after the effect. Enforcement that reaches a single agent action sits in the path the action has to take. A fine reaches the provider after the effect. A bound reaches the action before it.

Read the article →

July 31, 2026

For AI governance leads, model risk leaders, CCOs, AI compliance counsel, chief AI officers

Enforcement Reaches the Provider

On August 2, 2026 the EU AI Act's supervision and enforcement powers over general-purpose AI providers become applicable. That power inspects the provider and fines after the fact. The enforcement that reaches a single agent action sits in the path the action has to take.

This Sunday the EU AI Act's enforcement machinery switches on. From August 2, 2026 the Commission gains supervisory and enforcement powers over general-purpose AI model providers: request documentation, evaluate the model, order withdrawal, and impose fines up to thirty-five million euros or seven percent of turnover. That power has teeth, and it acts at one altitude. It reaches the provider and the model as a product, on inspection and after the fact. An agent action is a different object. It happens thousands of times inside one run, and it becomes a durable effect at a single instant. A control that governs it has to sit in the path the action takes, before the effect lands, and set how much authority the action carries. A runtime governor can grant less authority on a step whose present trust reads higher, because its forward look caught a divergence before the outcome landed. A fine reaches the provider after the effect. A bound reaches the action before it. The provider that runs a governor in the path answers the August 2 power with a record produced at runtime, not reconstructed from logs that were never built to hold it.

Read the article →

July 29, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, chief AI officers

Bounded by Construction

A governor bounds an agent's autonomy only when the agent cannot reach a durable effect except through it. A limit the agent is asked to respect is a request. A limit built into the only path to the actuator is a construction.

A governor sets how much authority an agent's next action carries. That grant is only real if the agent cannot reach the effect by a path the governor does not sit on. Most agent builds express the bound as a rule the agent is asked to obey, a policy in the prompt or a checker beside the execution path. A rule the agent can be steered off, and a checker the agent can route around, both depend on the agent staying cooperative, and the one case governance exists for is the case where it does not. Put the governor on the only path to the actuator and the bound changes character. The agent's latitude is exactly what the governor grants on each action, and no more, because there is no path to more. The system can act only inside what the governor grants, and it cannot step around the grant. That is bounded autonomy as a construction, not a promise, and it holds at the exact moment an advisory bound fails: the compromised agent, the drifted agent, the agent pursuing an injected goal with valid credentials.

Read the article →

July 27, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, chief AI officers

The Declared Envelope

A governor modulates authority against a reference it did not produce. That reference is the safety envelope, it is declared before the run, and the party who declares it holds a control the governed system cannot overrule.

The governor sets how much authority a system is granted on every action, and it sets that authority against a boundary. The boundary is the safety envelope, and where it comes from decides whether the governor is governing anything at all. A boundary the acting system draws for itself is not a boundary, because it drifts with the behavior it is meant to bound. The envelope has to be declared before the run, held outside the acting process, and not rewritable by the run. Whoever declares it holds the reference every authority decision is measured against, so it cannot be the system under governance and should not by default be only the vendor whose system is governed. The accountable party sets the bound the outcome had to stay inside, and the governor grades each action against that declared space rather than against a single door left open at provisioning. On an action the envelope never anticipated, the governor grants less authority, not the benefit of the doubt. Silence is not a grant.

Read the article →

July 26, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Field notes, week of July 26, 2026

Three pieces this week on where an obligation lands. A registry names the agent, a disclosure rule binds the output, and the authority that governs an action is set in front of the action, not declared above the run.

Three pieces this week on where an obligation actually lands. Two regulators moved this month, and each attached a duty to a particular action rather than to the system that took it. China's agent opinions became enforceable and grade an action into an authorization tier. The European Commission's Article 50 guidelines fix disclosure to the instant an output reaches a person. Registration declares that an agent exists. A disclosure rule binds one output. Neither is discharged by a document held above the run. The authority that governs an action, and the duty that binds it, are both fixed at the instant the action runs, and a governor standing in front of that action sets the one and discharges the other. A governor can grant less authority on a step whose present trust reads higher, because its forward look caught a divergence before the outcome landed.

Read the article →

July 24, 2026

For AI governance leads, model risk leaders, CCOs, AI compliance counsel, platform engineering leads

The Moment of Disclosure

The Commission's Article 50 guidelines fix disclosure to an instant. An obligation that attaches to a particular output is discharged by a control standing in front of that output, not by a policy written above it.

On July 20, 2026 the European Commission adopted the final Guidelines on the transparency obligations in Article 50 of the EU AI Act, and those obligations apply from August 2, 2026. Every duty in the article attaches to a moment. The interaction notice is owed at the latest at the first interaction. The marking duty attaches at output generation. The deep-fake disclosure attaches before or at presentation. None of those is a state a program can be in, and each binds a particular output rather than the system that produced it. An agent run separates the step that generates content from the step that puts it in front of a person. A duty that binds an individual action is discharged by a governor standing ahead of that action, setting how much authority the emit is granted and narrowing the grant when provenance is thin.

Read the article →

July 22, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, chief AI officers

Higher Trust, Less Authority

The authority a governor grants is set on where the action is heading, not only on how clean the action looks right now. A forward look can grant less on a step whose present trust reads high.

Most runtime controls widen a system's latitude when its present signal looks good. The signal the system emits about its own health comes from the same process that is acting, so a control keyed to present confidence loosens exactly when confidence is least earned. Trust and authority are two quantities, not one. Trust is what the system reports about itself. Authority is what the governor grants for the next action, and the two are allowed to move in opposite directions. The governor sets authority on where the trajectory is heading, not only on how clean the current step looks. It can grant less authority on a decision whose present trust reads higher, because its forward look caught a divergence the current step has not surfaced. Higher trust, less authority, because it anticipated.

Read the article →

July 20, 2026

For Model risk leaders, AI governance leads, CCOs, procurement leads, AI compliance counsel

The Registry and the Record

A regulator's agent registry records that an agent exists and what it was declared to do. It cannot hold what one action the agent took was authorized to do, and that is the fact an examiner pulls.

Governments are beginning to require that an agent be registered before it runs. A national regime became enforceable this month, and a bill in the US Senate would put certain user-facing agents on a federal register before they may reach the platforms they act on. Registration establishes that the agent exists and what it was declared to do. A declared purpose is a category, and an action is a particular that falls inside it or does not. The register is a provisioning-time object. It says the agent is allowed to operate. It does not say a single action the agent took was governed. Registration is the roster. The record is the account, and the examiner pulls one decision to read the account.

Read the article →

July 19, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Field notes, week of July 19, 2026

Three pieces this week on obligations the run sets and the convenient build leaves optional. When the record has to seal, what a control has to bound before an attack has a name, and the authority a reviewer's click actually granted.

Three pieces this week on one fault. Each names an obligation the run itself imposes, and each shows the convenient build treating it as optional. The deadline a later action sets, not the latency budget the operator picks. The bound a control has to hold before the attack it faces has been named. The authority a reviewer's click actually granted, not the name and timestamp the log keeps. Before the run sets it, each obligation looks like a choice. After, it is the fact the examiner pulls one decision to find.

Read the article →

July 17, 2026

For Model risk leaders, AI governance leads, CISOs, internal auditors, AI compliance counsel

What the Override Granted

An agent that escalates hands the decision up. The click that sends it back down is an act of authority, and the record almost always holds who clicked instead of what they granted.

Every agent platform shipping today has an escalation path. The agent stops, and asks a person. That half is built. The return path is a button, and what the button granted is not written down anywhere. Joint guidance now tells operators to fail safe and escalate under uncertainty, and a DHS-CISA analysis this month asks for documented human-override mechanisms. Most implementations read that as logging they already do. The log holds a name and a timestamp. A grant of authority has a scope, an end, a binding to the specific action the reviewer saw, and the reviewer's own envelope. Approval is the event. The grant is the artifact, and it is the one the examiner reads.

Read the article →

July 15, 2026

For CISOs, security architects, AI governance leads, model risk leaders, AI compliance counsel

The Signature Arms Race

A detector has to recognize an attack to stop it, so every novel technique works until its signature is written. A control that reads behavioral divergence bounds the effect of the attack it cannot yet name.

The security layer for agents is filling with detectors. A prompt-injection classifier, a tool-poisoning scanner, a monitor for a corrupted memory. Each one has to recognize the attack before it can stop it, and every technique that has not been catalogued yet passes. A subverted agent does not break out. It uses the tools it was already cleared to use to pursue a goal it was never given, and the identity, the credentials, and the permission set all stay intact. What changed is not at the boundary. It is in the behavior. A runtime authority control reads that divergence directly and clamps what the agent may do next, without needing the attack's name. The detector's problem grows with every new technique. The governor's problem is fixed, and the record seals either way.

Read the article →

July 13, 2026

For Model risk leaders, AI governance leads, platform engineering leads, system integrators, CISOs

Time to Receipt

Every piece in this series seals a record. The unasked question is by when, and the deadline is fixed by the moment a later action starts to depend on the one just taken.

A governed agent action produces a sealed record. The standing question is how much the sealing slows the agent, and that question is incomplete. The record has a deadline the run itself sets. An action lands an effect, and a later step reads that effect and acts on it. If the record of the first action is not sealed before the second depends on it, the run has built on an action that is not yet provable. Time to receipt is bounded by that causal edge, not by a latency budget the operator chooses. Throughput asks how fast the governor signs. The governance SLA asks whether the record is sealed before any later action is permitted to depend on it.

Read the article →

July 12, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Field notes, week of July 12, 2026

Three pieces this week on the single moment an agent action runs. The authority that governs it is set there, the record of it has to seal there, and the record sealed there is the one every regulator reads afterward.

Three pieces this week on one moment. An agent action runs once, and that instant fixes three things at once. The authority that governs the act is set there. The record of it has to close there. And the record sealed there is the one every regulator reads long after the act is done. Before that moment a permission is only a boundary. After it an explanation is only a description. The control that governs the act and the record that proves it both live on the near side of the one instant the action becomes real.

Read the article →

July 10, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

One Record, Every Regulator

A regulated firm answers to more than one authority, but an agent action is a single event. The record of that action should be sealed once, framework-neutral, and read by each regulator through its own lens.

A regulated firm rarely answers to one regulator. A bank sits under the Fed, the OCC, and the CFPB at once. An insurer answers to every state that adopted the NAIC model. Any firm operating in the EU answers to the AI Act on top of all of it. The agent action underneath those regimes is one event. Most firms capture a record shaped to the framework in force when the system shipped, and that record cannot answer a framework that did not exist when the action was sealed. The move is to seal one canonical record at the moment the action runs, framework-neutral, and treat the mapping to any regime as a projection applied when the record is read. One act, one sealed record, many readers.

Read the article →

July 8, 2026

For Model risk leaders, AI governance leads, CISOs, chief AI officers, AI compliance counsel

The Point of No Return

An agent action becomes a durable effect at one moment. A control that reads the action after that moment can describe the effect. Only a control that sits before it can govern the action or seal the record of it.

An agent action does not become real when the model decides it. It becomes real when the effect lands. A payment leaves an account. A row is written to a system of record. Before that moment the action is contingent and can still be reduced or refused. After it there is only the account of what already happened. A control set before the run is too early. A control that reads the action after the effect landed is too late. Only a control on the near side of that boundary can govern the action, and the record has to be sealed on the near side too.

Read the article →

July 6, 2026

For Model risk leaders, AI governance leads, CISOs, procurement leads, AI compliance counsel

Permission Is Not Authority

A permission set is drawn once, before the run, and bounds what the agent may touch. The authority that governs a single action is a runtime value, and an agent that never leaves its permissions can still take the action a governor would have stopped.

A scoped permission set is the control most teams reach for to govern an agent. It is set at provisioning, before the run, and it fixes what the agent may touch. It does not decide what a single action, taken partway through the run, is allowed to do. An agent that never leaves its permissions can still act outside its intended purpose. Permitted is not the same as governed. The examiner pulls one action inside the permission set and asks what authority governed it, and a standing grant does not carry one.

Read the article →

July 5, 2026

For Model risk leaders, AI governance leads, internal auditors, CCOs, AI compliance counsel

Field notes, week of July 5, 2026

Three pieces this week on one demand a record has to meet. It is evidence only when the party under examination could not have shaped it.

Three pieces this week, each closing a way an agent could vouch for its own record. It cannot alter the record after the act. It cannot hand its own authority back inside the run. It cannot be the party that signs the account of what it did. A record the actor could shape is a claim. The examiner needs the one it could not. Integrity closes the first path, the direction authority is allowed to move closes the second, and separation of duties closes the third.

Read the article →

July 3, 2026

For Model risk leaders, internal auditors, CCOs, procurement leads, AI compliance counsel

Separation of Duties

A century-old audit control the agent record has to satisfy. The party that executes an agent action cannot also be the party that signs the record of it.

Segregation of duties splits custody, authorization, and recording so no single party can both act and account for the act. Internal audit has enforced it for a century, and it is among the first things an examiner tests. An agent run collapses the split. One platform authorizes the action, executes it, and writes the log. A record the actor produces about its own conduct is a claim, not evidence. The examiner pulls one decision and asks who executed it and who recorded it, and whether those were the same party.

Read the article →

July 1, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, chief AI officers

Authority Only Falls

Inside a single agent run, authority can be reduced but not restored. It falls when behavior diverges from what the agent was assured to do, and it does not climb back on the agent's own signal.

An agent's authority is not fixed for the length of a run. The governor sets it before each action, and the direction it is allowed to move is the whole control. It falls when realized behavior diverges from the assured trajectory, and inside the run it does not climb back on the agent's own signal. A gate that lets authority rise again on the agent's report shares a failure mode with the behavior it is meant to bound. Recovery is a separate authorized act, recorded. The examiner pulls one action and asks what governed it, and whether a divergence that lowered authority was quietly handed back.

Read the article →

June 29, 2026

For Model risk leaders, AI governance leads, internal auditors, CISOs, AI compliance counsel

The Integrity Primitive

Identity proves who wrote the record and a schema proves what it holds. Integrity is the property that decides whether the record could have changed since the decision it documents.

A signed log proves who wrote it. A schema proves what it contains. Neither proves the record in front of the examiner is the one written at the moment of the decision. That third property is integrity, and it is the one the word hash-chained is increasingly used to gesture at without delivering. A record the operator can edit after the run is a claim about the past. Hash-linkage is what turns it into proof.

Read the article →

June 28, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Field notes, week of June 28, 2026

Three pieces this week on one fault line. The authority that governed an act is fixed when the agent acts. A control set before the run, an explanation produced after it, and a log of one approver each miss it.

Three pieces this week, each separating a control that resembles governance from the authority an examiner pulls. A control set before the agent runs cannot hold the authority a decision carried. An explanation produced after the run does not contain it. A log of one approver cannot show the second authority that had to concur. The authority that governed one act is fixed when the agent acts, and that is the fact the examiner pulls one decision to find.

Read the article →

June 26, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

The Second Authority

A high-consequence agent action that needs a second approval is governed by two authorities, and the record has to hold both, with the concurrence fixed before the act.

A high-consequence action does not run on one approval. A wire above a threshold. A model promoted to production. Two parties have to concur, and the record has to hold both, with the second concurrence fixed before the act and bound to the specific action proposed. Most agent logs hold one identity and one timestamp. The examiner pulls one decision and asks who else had to say yes, and when.

Read the article →

June 24, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Explanation Is Not Authority

Explainability accounts for why a model produced an output. The authority that governed the act is a different fact, and it is the one an examiner pulls.

Explainability is the control most often reached for when an agent makes a decision someone has to answer for. It returns an account of why the model produced the output, assembled after the action has already run. That account is not the authority that governed the act. It does not say what the agent was allowed to do, which policy was in force, or whether the action was reduced or stopped. The examiner who pulls one decision needs the authority that bound it, not the reason the model gave.

Read the article →

June 22, 2026

For Model risk leaders, AI governance leads, CISOs, chief AI officers

Training Time Is Too Early

Why the controls that ship before an agent runs cannot govern the decisions it makes once it does.

Most AI governance acts before the agent runs. It calibrates a model frozen at release, against inputs the live run will not resemble. An agent does not hold still. It composes inputs the certification never saw and acts on tool results that did not exist when it was cleared. A clean pre-deployment evaluation does not transfer. The examiner pulls one decision and asks what governed it, and a training-time record answers a different question.

Read the article →

June 21, 2026

For Model risk leaders, AI governance leads, CISOs, AI compliance counsel, autonomous-systems safety engineers

Field notes, week of June 21, 2026

Three pieces this week on the form a runtime control has to take before its record counts as evidence. Where it stands, what it emits, and whether it can fail with the agent it watches.

Three pieces this week, each on a property the runtime control has to have before its record counts as evidence. A control set at training time does not bind the decision made at inference. A verdict drawn from a short menu loses the authority the action carried. A checker that reads the doer's self-report fails with it. Position, output, independence. The log is not the evidence until all three hold.

Read the article →

June 19, 2026

For Autonomous-systems safety engineers, AV safety leads, functional-safety assessors, model risk leaders, AI governance leads

The Common Mode

A doer and a checker that draw on the same confidence fail together. The one mode you can close by construction is the checker whose trust never reads the doer's self-report.

A controller that reports its own health, and a monitor that believes the report, fail at the same moment. The doer/checker architecture splits the capable component from the one that holds the envelope. Continuous authority puts the pair in ASIL B(D), where freedom from common-mode failure becomes the whole safety case. One common mode closes at the design level. The rest is a D-level argument you still owe.

Read the article →

June 17, 2026

For Model risk leaders, AI governance leads, CISOs, chief AI officers

Between Allow and Block

Most agent enforcement returns one verdict from a short list, but the authority an action carried is a value on a continuum, and the record has to hold the value, not the bucket.

Most agent enforcement answers one question. May this action run. The answer comes back as a pick from a short list. Allow. Block. Send it to a human. The authority the action actually carried is not on that list. A discrete gate can pass an action or stop it. It cannot pass the action with its authority reduced, and the examiner who pulls one decision needs the value that bound it, not the bucket it fell into.

Read the article →

June 14, 2026

For Model risk leaders, AI governance leads, CISOs, AI compliance counsel, procurement leads

Field notes, week of June 14, 2026

Three pieces this week, each separating a lookalike for governance from the record an examiner can use.

Three pieces this week, each separating a lookalike for governance from the record an examiner can use. A claim measured on a private corpus. A detector that reports drift without governing it. A plan that pre-authorizes a change without recording which one committed. Each one resembles governance. The record is the part that survives the question.

Read the article →

June 12, 2026

For Model risk leaders, AI governance leads, AI compliance counsel, chief AI officers

The Admission Gate

A predetermined change control plan says which updates are allowed. It does not record which one the model actually made, or whether anything stopped the ones that were not.

Most AI governance watches the action and reads the decision against the policy in force. A second moment goes unwatched. The moment the model is permitted to change. A learning event is not a decision. It is the model rewriting the function that produces decisions, and it resets the disposition behind every decision that follows. The FDA's Predetermined Change Control Plan names the change and pre-authorizes an envelope. A plan is not a record. The runtime evidence of which change committed, against which bound, and whether anything stopped the ones outside it, is the artifact almost no one is producing.

Read the article →

June 10, 2026

For Model risk leaders, AI governance leads, CISOs, chief AI officers

Drift Detection Is Not Governance

A detector reports that behavior moved. A governor decides what the agent was allowed to do once it did.

Drift detection is shipping across the agentic-AI stack. It reports that behavior moved. It does not decide what the agent was permitted to do once it moved, and it does not leave a record an examiner can read. A detector is a sensor. A governor is a control loop that sits in the decision path, sets the authority of the action before it executes, and signs what it decided. The examiner does not ask whether you noticed the drift. The examiner asks what you did and where the record is.

Read the article →

June 8, 2026

For Model risk leaders, AI governance leads, CISOs, procurement leads, AI insurance counsel

If the Corpus Is Private

A claim that cannot be replayed on a public benchmark is not a claim a counterparty can use.

Vendor demos cite numbers. Hit rate, latency, detection lift. The numbers are precise. The corpus they were measured on is internal, the pipeline is opaque, and the trace is gone. A number measured on private telemetry cannot fail in public. The discipline that makes a claim usable to a counterparty is unglamorous and old. Stand the pipeline on a corpus the counterparty can download. The number either survives or it doesn't.

Read the article →

June 7, 2026

For Model risk leaders, AI governance leads, CISOs, procurement leads, AI insurance counsel

Field notes, week of June 7, 2026

Three standing objections to a signed runtime record. Latency, contract, identity. One week, three answers.

Three pieces this week, each answering an objection to a signed runtime record. It is too slow to sit in the decision path. No one made us produce it. A signature proves nothing. Sixty-one microseconds answers the first. The contract answers the second. A verifiable identity answers the third. The record only counts as evidence when all three hold.

Read the article →

June 5, 2026

For CISOs, identity architects, model risk leaders, AI governance leads

Who Signs the Run

A signature on the trajectory is only evidence if a stranger can verify which agent stood behind it.

Every piece in this series ends at the same place. The record gets signed. A signature attests to an identity, and the identity is the part nobody has specified. Identity-governance for agents is shipping, but it answers whether the agent may act, not which agent did. A trajectory signed with one shared platform key proves the platform emitted bytes. It does not prove which agent, which version, under which policy. The examiner asks the agent what it asks an employee. Who were you, and prove it.

Read the article →

June 3, 2026

For Procurement leads, AI compliance counsel, system integrators, model risk leaders

The Procurement Clause

Why the agent contract, not the audit, is where the record gets won or lost.

SR 26-2 carved agentic AI out of scope and pointed institutions back at their own risk practices. Those practices were written for a model you buy once. An agent run is a service you rent, and the record lives wherever the vendor decides. The control just moved to the contract, and the buyer has leverage exactly once. Before signature.

Read the article →

June 1, 2026

For Model risk leaders, AI governance leads, platform engineering leads, system integrators

Sixty-One Microseconds

What it costs to put governance in the decision path, measured across thirty thousand decisions.

In-flight governance has one standing objection. A governor that fires before the next inference sits in the decision path, and every decision waits for it. We built the runtime and measured it. Sixty-one microseconds at the mean, eighty-three at the ninety-fifth percentile, across thirty thousand governed decisions. The same governor, reimplemented in a second language, signs a byte-identical record. That is what makes the audit object verifiable by a party who trusts neither build.

Read the article →

May 31, 2026

For Model risk leaders, AI insurance counsel, procurement leads, CCOs

Field notes, week of May 31, 2026

Who owns the record, who prices it, who writes it into the contract. Three pieces, three answers.

Three pieces this week. Each names a party who needs the agent record and a moment it has to be secured. The second line decides where it lives. The carrier cannot price what it cannot replay. The buyer has leverage exactly once, before signature. The record does not arrive on its own. Someone specifies it, or no one does.

Read the article →

May 27, 2026

For AI insurance counsel, chief underwriters, reinsurance pricing analysts, model risk leaders

The Underwriting Surface

Why an AI E&O line cannot price what it cannot replay.

An insurance market for adaptive-AI errors is forming. The product needs an underwriting surface. The agent run does not present one today. Carriers writing AI E&O are pricing without loss triangles. Reinsurers are quoting without a forensics path. Both are positions the market will not hold.

Read the article →

May 25, 2026

For Model risk leaders, internal auditors, CCOs, chief AI officers

Where Model Risk Ends

What model risk management keeps owning, and where agent assurance starts.

Model risk management was built for an artifact that does not move. An agent run is an artifact that does. The methodology that worked for the first does not extend to the second. SR 26-2 carved agentic AI out of MRM scope, and the agent run still has to live somewhere.

Read the article →

May 24, 2026

For Model risk leaders, AI governance leads, CCOs, procurement leads

Field notes, week of May 24, 2026

The vendor enforcement layer shipped this week. The audit-grade record did not.

Three pieces this week. One through-line. Enforcement is shipping. Observability is shipping. A signed audit chain that survives a vendor switch is not. The NAIC examination tool is mid-pilot, and SR 26-2 still carves agentic AI out of scope pending the interagency RFI. The runway is finite.

Read the article →

May 22, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel

Nothing to Freeze

Why replaying the model weights does not reconstruct an agent that learned inside the run.

Static-model audit rests on one move. Freeze the weights, replay the input, reproduce the output. An agent that learns inside a single run breaks that move. The weights never changed, but the behavior did, and there is nothing to freeze and replay against. The reconstruction window is the run itself.

Read the article →

May 20, 2026

For Procurement leads, model risk leaders, CISOs, chief AI officers

Portability Is the Leverage

Why the audit record has to outlive the agent vendor that produced it.

Retention is measured in years. Vendor tenure is measured in quarters. The audit record cannot live where the vendor lives. The third procurement question from the last piece was where the record goes when the agent vendor is replaced. That question is the one with leverage attached.

Read the article →

May 18, 2026

For AI governance leads, CISOs, model risk leaders, system integrators

The Tool-Call Boundary

Why the agent governance launches of the last thirty days enforce, but do not sign.

Thirty days. Three control planes. One missing artifact. Three governance toolkits shipped between April 2 and May 5, each enforcing tool-call policy at sub-millisecond latency. None of them produces the signed record of which calls were allowed, which were blocked, and what the agent did next.

Read the article →

May 15, 2026

For Model risk leaders, internal auditors, CCOs, chief AI officers

The Multi-Step Record Format

What the trajectory has to contain, told as one loan denial.

A bank denies a credit-card application in 2.3 seconds. Three weeks later, the applicant's attorney asks how. The bank logged the input, the output, and the timestamp. The bank did not record the decision graph the agent walked between them. Five primitives are what the record has to contain.

Read the article →

May 11, 2026

For Model risk leaders, internal auditors, CCOs, chief AI officers

The Accountability Gap

What the responsible party hands the examiner in 2029.

Most agency AI deployments today log the input and the output and call it a record. An agent run isn't an input and an output. It's a sequence of tool calls, branches, and intermediate state. Almost nobody is capturing it. Without that record, accountability is a position you take. Not something you can prove.

Read the article →

May 7, 2026

For Risk officers, model risk leaders, AI governance leads, system integrators

The Trajectory Is the Audit Object

What two agentic-AI governance launches in eight days did not solve.

Eight days. Two launches. One missing artifact. On May 6, IBM launched Sovereign Core. Eight days earlier, Atos launched Sovereign Agentic Studios. Two of the world's largest IT firms shipped agentic AI governance offerings inside a single week. Neither produces the evidence object an auditor is about to ask for.

Read the article →

New writing arrives as the work moves.

Write directly if you'd like to be added to the early-read list for forthcoming pieces.