Articles

Field notes from the runtime layer.

Writing on agentic AI governance, audit substrates, regulatory cadence, and the eighteen-month window between today and the next examination cycle.

July 26, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Field notes, week of July 26, 2026

Three pieces this week on where an obligation lands. A registry names the agent, a disclosure rule binds the output, and the authority that governs an action is set in front of the action, not declared above the run.

Three pieces this week on where an obligation actually lands. Two regulators moved this month, and each attached a duty to a particular action rather than to the system that took it. China's agent opinions became enforceable and grade an action into an authorization tier. The European Commission's Article 50 guidelines fix disclosure to the instant an output reaches a person. Registration declares that an agent exists. A disclosure rule binds one output. Neither is discharged by a document held above the run. The authority that governs an action, and the duty that binds it, are both fixed at the instant the action runs, and a governor standing in front of that action sets the one and discharges the other. A governor can grant less authority on a step whose present trust reads higher, because its forward look caught a divergence before the outcome landed.

Read the article →

July 24, 2026

For AI governance leads, model risk leaders, CCOs, AI compliance counsel, platform engineering leads

The Moment of Disclosure

The Commission's Article 50 guidelines fix disclosure to an instant. An obligation that attaches to a particular output is discharged by a control standing in front of that output, not by a policy written above it.

On July 20, 2026 the European Commission adopted the final Guidelines on the transparency obligations in Article 50 of the EU AI Act, and those obligations apply from August 2, 2026. Every duty in the article attaches to a moment. The interaction notice is owed at the latest at the first interaction. The marking duty attaches at output generation. The deep-fake disclosure attaches before or at presentation. None of those is a state a program can be in, and each binds a particular output rather than the system that produced it. An agent run separates the step that generates content from the step that puts it in front of a person. A duty that binds an individual action is discharged by a governor standing ahead of that action, setting how much authority the emit is granted and narrowing the grant when provenance is thin.

Read the article →

July 22, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, chief AI officers

Higher Trust, Less Authority

The authority a governor grants is set on where the action is heading, not only on how clean the action looks right now. A forward look can grant less on a step whose present trust reads high.

Most runtime controls widen a system's latitude when its present signal looks good. The signal the system emits about its own health comes from the same process that is acting, so a control keyed to present confidence loosens exactly when confidence is least earned. Trust and authority are two quantities, not one. Trust is what the system reports about itself. Authority is what the governor grants for the next action, and the two are allowed to move in opposite directions. The governor sets authority on where the trajectory is heading, not only on how clean the current step looks. It can grant less authority on a decision whose present trust reads higher, because its forward look caught a divergence the current step has not surfaced. Higher trust, less authority, because it anticipated.

Read the article →

July 20, 2026

For Model risk leaders, AI governance leads, CCOs, procurement leads, AI compliance counsel

The Registry and the Record

A regulator's agent registry records that an agent exists and what it was declared to do. It cannot hold what one action the agent took was authorized to do, and that is the fact an examiner pulls.

Governments are beginning to require that an agent be registered before it runs. A national regime became enforceable this month, and a bill in the US Senate would put certain user-facing agents on a federal register before they may reach the platforms they act on. Registration establishes that the agent exists and what it was declared to do. A declared purpose is a category, and an action is a particular that falls inside it or does not. The register is a provisioning-time object. It says the agent is allowed to operate. It does not say a single action the agent took was governed. Registration is the roster. The record is the account, and the examiner pulls one decision to read the account.

Read the article →

July 19, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Field notes, week of July 19, 2026

Three pieces this week on obligations the run sets and the convenient build leaves optional. When the record has to seal, what a control has to bound before an attack has a name, and the authority a reviewer's click actually granted.

Three pieces this week on one fault. Each names an obligation the run itself imposes, and each shows the convenient build treating it as optional. The deadline a later action sets, not the latency budget the operator picks. The bound a control has to hold before the attack it faces has been named. The authority a reviewer's click actually granted, not the name and timestamp the log keeps. Before the run sets it, each obligation looks like a choice. After, it is the fact the examiner pulls one decision to find.

Read the article →

July 17, 2026

For Model risk leaders, AI governance leads, CISOs, internal auditors, AI compliance counsel

What the Override Granted

An agent that escalates hands the decision up. The click that sends it back down is an act of authority, and the record almost always holds who clicked instead of what they granted.

Every agent platform shipping today has an escalation path. The agent stops, and asks a person. That half is built. The return path is a button, and what the button granted is not written down anywhere. Joint guidance now tells operators to fail safe and escalate under uncertainty, and a DHS-CISA analysis this month asks for documented human-override mechanisms. Most implementations read that as logging they already do. The log holds a name and a timestamp. A grant of authority has a scope, an end, a binding to the specific action the reviewer saw, and the reviewer's own envelope. Approval is the event. The grant is the artifact, and it is the one the examiner reads.

Read the article →

July 15, 2026

For CISOs, security architects, AI governance leads, model risk leaders, AI compliance counsel

The Signature Arms Race

A detector has to recognize an attack to stop it, so every novel technique works until its signature is written. A control that reads behavioral divergence bounds the effect of the attack it cannot yet name.

The security layer for agents is filling with detectors. A prompt-injection classifier, a tool-poisoning scanner, a monitor for a corrupted memory. Each one has to recognize the attack before it can stop it, and every technique that has not been catalogued yet passes. A subverted agent does not break out. It uses the tools it was already cleared to use to pursue a goal it was never given, and the identity, the credentials, and the permission set all stay intact. What changed is not at the boundary. It is in the behavior. A runtime authority control reads that divergence directly and clamps what the agent may do next, without needing the attack's name. The detector's problem grows with every new technique. The governor's problem is fixed, and the record seals either way.

Read the article →

July 13, 2026

For Model risk leaders, AI governance leads, platform engineering leads, system integrators, CISOs

Time to Receipt

Every piece in this series seals a record. The unasked question is by when, and the deadline is fixed by the moment a later action starts to depend on the one just taken.

A governed agent action produces a sealed record. The standing question is how much the sealing slows the agent, and that question is incomplete. The record has a deadline the run itself sets. An action lands an effect, and a later step reads that effect and acts on it. If the record of the first action is not sealed before the second depends on it, the run has built on an action that is not yet provable. Time to receipt is bounded by that causal edge, not by a latency budget the operator chooses. Throughput asks how fast the governor signs. The governance SLA asks whether the record is sealed before any later action is permitted to depend on it.

Read the article →

July 12, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Field notes, week of July 12, 2026

Three pieces this week on the single moment an agent action runs. The authority that governs it is set there, the record of it has to seal there, and the record sealed there is the one every regulator reads afterward.

Three pieces this week on one moment. An agent action runs once, and that instant fixes three things at once. The authority that governs the act is set there. The record of it has to close there. And the record sealed there is the one every regulator reads long after the act is done. Before that moment a permission is only a boundary. After it an explanation is only a description. The control that governs the act and the record that proves it both live on the near side of the one instant the action becomes real.

Read the article →

July 10, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

One Record, Every Regulator

A regulated firm answers to more than one authority, but an agent action is a single event. The record of that action should be sealed once, framework-neutral, and read by each regulator through its own lens.

A regulated firm rarely answers to one regulator. A bank sits under the Fed, the OCC, and the CFPB at once. An insurer answers to every state that adopted the NAIC model. Any firm operating in the EU answers to the AI Act on top of all of it. The agent action underneath those regimes is one event. Most firms capture a record shaped to the framework in force when the system shipped, and that record cannot answer a framework that did not exist when the action was sealed. The move is to seal one canonical record at the moment the action runs, framework-neutral, and treat the mapping to any regime as a projection applied when the record is read. One act, one sealed record, many readers.

Read the article →

July 8, 2026

For Model risk leaders, AI governance leads, CISOs, chief AI officers, AI compliance counsel

The Point of No Return

An agent action becomes a durable effect at one moment. A control that reads the action after that moment can describe the effect. Only a control that sits before it can govern the action or seal the record of it.

An agent action does not become real when the model decides it. It becomes real when the effect lands. A payment leaves an account. A row is written to a system of record. Before that moment the action is contingent and can still be reduced or refused. After it there is only the account of what already happened. A control set before the run is too early. A control that reads the action after the effect landed is too late. Only a control on the near side of that boundary can govern the action, and the record has to be sealed on the near side too.

Read the article →

July 6, 2026

For Model risk leaders, AI governance leads, CISOs, procurement leads, AI compliance counsel

Permission Is Not Authority

A permission set is drawn once, before the run, and bounds what the agent may touch. The authority that governs a single action is a runtime value, and an agent that never leaves its permissions can still take the action a governor would have stopped.

A scoped permission set is the control most teams reach for to govern an agent. It is set at provisioning, before the run, and it fixes what the agent may touch. It does not decide what a single action, taken partway through the run, is allowed to do. An agent that never leaves its permissions can still act outside its intended purpose. Permitted is not the same as governed. The examiner pulls one action inside the permission set and asks what authority governed it, and a standing grant does not carry one.

Read the article →

July 5, 2026

For Model risk leaders, AI governance leads, internal auditors, CCOs, AI compliance counsel

Field notes, week of July 5, 2026

Three pieces this week on one demand a record has to meet. It is evidence only when the party under examination could not have shaped it.

Three pieces this week, each closing a way an agent could vouch for its own record. It cannot alter the record after the act. It cannot hand its own authority back inside the run. It cannot be the party that signs the account of what it did. A record the actor could shape is a claim. The examiner needs the one it could not. Integrity closes the first path, the direction authority is allowed to move closes the second, and separation of duties closes the third.

Read the article →

July 3, 2026

For Model risk leaders, internal auditors, CCOs, procurement leads, AI compliance counsel

Separation of Duties

A century-old audit control the agent record has to satisfy. The party that executes an agent action cannot also be the party that signs the record of it.

Segregation of duties splits custody, authorization, and recording so no single party can both act and account for the act. Internal audit has enforced it for a century, and it is among the first things an examiner tests. An agent run collapses the split. One platform authorizes the action, executes it, and writes the log. A record the actor produces about its own conduct is a claim, not evidence. The examiner pulls one decision and asks who executed it and who recorded it, and whether those were the same party.

Read the article →

July 1, 2026

For Model risk leaders, AI governance leads, CISOs, autonomous-systems safety engineers, chief AI officers

Authority Only Falls

Inside a single agent run, authority can be reduced but not restored. It falls when behavior diverges from what the agent was assured to do, and it does not climb back on the agent's own signal.

An agent's authority is not fixed for the length of a run. The governor sets it before each action, and the direction it is allowed to move is the whole control. It falls when realized behavior diverges from the assured trajectory, and inside the run it does not climb back on the agent's own signal. A gate that lets authority rise again on the agent's report shares a failure mode with the behavior it is meant to bound. Recovery is a separate authorized act, recorded. The examiner pulls one action and asks what governed it, and whether a divergence that lowered authority was quietly handed back.

Read the article →

June 29, 2026

For Model risk leaders, AI governance leads, internal auditors, CISOs, AI compliance counsel

The Integrity Primitive

Identity proves who wrote the record and a schema proves what it holds. Integrity is the property that decides whether the record could have changed since the decision it documents.

A signed log proves who wrote it. A schema proves what it contains. Neither proves the record in front of the examiner is the one written at the moment of the decision. That third property is integrity, and it is the one the word hash-chained is increasingly used to gesture at without delivering. A record the operator can edit after the run is a claim about the past. Hash-linkage is what turns it into proof.

Read the article →

June 28, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Field notes, week of June 28, 2026

Three pieces this week on one fault line. The authority that governed an act is fixed when the agent acts. A control set before the run, an explanation produced after it, and a log of one approver each miss it.

Three pieces this week, each separating a control that resembles governance from the authority an examiner pulls. A control set before the agent runs cannot hold the authority a decision carried. An explanation produced after the run does not contain it. A log of one approver cannot show the second authority that had to concur. The authority that governed one act is fixed when the agent acts, and that is the fact the examiner pulls one decision to find.

Read the article →

June 26, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

The Second Authority

A high-consequence agent action that needs a second approval is governed by two authorities, and the record has to hold both, with the concurrence fixed before the act.

A high-consequence action does not run on one approval. A wire above a threshold. A model promoted to production. Two parties have to concur, and the record has to hold both, with the second concurrence fixed before the act and bound to the specific action proposed. Most agent logs hold one identity and one timestamp. The examiner pulls one decision and asks who else had to say yes, and when.

Read the article →

June 24, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel, chief AI officers

Explanation Is Not Authority

Explainability accounts for why a model produced an output. The authority that governed the act is a different fact, and it is the one an examiner pulls.

Explainability is the control most often reached for when an agent makes a decision someone has to answer for. It returns an account of why the model produced the output, assembled after the action has already run. That account is not the authority that governed the act. It does not say what the agent was allowed to do, which policy was in force, or whether the action was reduced or stopped. The examiner who pulls one decision needs the authority that bound it, not the reason the model gave.

Read the article →

June 22, 2026

For Model risk leaders, AI governance leads, CISOs, chief AI officers

Training Time Is Too Early

Why the controls that ship before an agent runs cannot govern the decisions it makes once it does.

Most AI governance acts before the agent runs. It calibrates a model frozen at release, against inputs the live run will not resemble. An agent does not hold still. It composes inputs the certification never saw and acts on tool results that did not exist when it was cleared. A clean pre-deployment evaluation does not transfer. The examiner pulls one decision and asks what governed it, and a training-time record answers a different question.

Read the article →

June 21, 2026

For Model risk leaders, AI governance leads, CISOs, AI compliance counsel, autonomous-systems safety engineers

Field notes, week of June 21, 2026

Three pieces this week on the form a runtime control has to take before its record counts as evidence. Where it stands, what it emits, and whether it can fail with the agent it watches.

Three pieces this week, each on a property the runtime control has to have before its record counts as evidence. A control set at training time does not bind the decision made at inference. A verdict drawn from a short menu loses the authority the action carried. A checker that reads the doer's self-report fails with it. Position, output, independence. The log is not the evidence until all three hold.

Read the article →

June 19, 2026

For Autonomous-systems safety engineers, AV safety leads, functional-safety assessors, model risk leaders, AI governance leads

The Common Mode

A doer and a checker that draw on the same confidence fail together. The one mode you can close by construction is the checker whose trust never reads the doer's self-report.

A controller that reports its own health, and a monitor that believes the report, fail at the same moment. The doer/checker architecture splits the capable component from the one that holds the envelope. Continuous authority puts the pair in ASIL B(D), where freedom from common-mode failure becomes the whole safety case. One common mode closes at the design level. The rest is a D-level argument you still owe.

Read the article →

June 17, 2026

For Model risk leaders, AI governance leads, CISOs, chief AI officers

Between Allow and Block

Most agent enforcement returns one verdict from a short list, but the authority an action carried is a value on a continuum, and the record has to hold the value, not the bucket.

Most agent enforcement answers one question. May this action run. The answer comes back as a pick from a short list. Allow. Block. Send it to a human. The authority the action actually carried is not on that list. A discrete gate can pass an action or stop it. It cannot pass the action with its authority reduced, and the examiner who pulls one decision needs the value that bound it, not the bucket it fell into.

Read the article →

June 14, 2026

For Model risk leaders, AI governance leads, CISOs, AI compliance counsel, procurement leads

Field notes, week of June 14, 2026

Three pieces this week, each separating a lookalike for governance from the record an examiner can use.

Three pieces this week, each separating a lookalike for governance from the record an examiner can use. A claim measured on a private corpus. A detector that reports drift without governing it. A plan that pre-authorizes a change without recording which one committed. Each one resembles governance. The record is the part that survives the question.

Read the article →

June 12, 2026

For Model risk leaders, AI governance leads, AI compliance counsel, chief AI officers

The Admission Gate

A predetermined change control plan says which updates are allowed. It does not record which one the model actually made, or whether anything stopped the ones that were not.

Most AI governance watches the action and reads the decision against the policy in force. A second moment goes unwatched. The moment the model is permitted to change. A learning event is not a decision. It is the model rewriting the function that produces decisions, and it resets the disposition behind every decision that follows. The FDA's Predetermined Change Control Plan names the change and pre-authorizes an envelope. A plan is not a record. The runtime evidence of which change committed, against which bound, and whether anything stopped the ones outside it, is the artifact almost no one is producing.

Read the article →

June 10, 2026

For Model risk leaders, AI governance leads, CISOs, chief AI officers

Drift Detection Is Not Governance

A detector reports that behavior moved. A governor decides what the agent was allowed to do once it did.

Drift detection is shipping across the agentic-AI stack. It reports that behavior moved. It does not decide what the agent was permitted to do once it moved, and it does not leave a record an examiner can read. A detector is a sensor. A governor is a control loop that sits in the decision path, sets the authority of the action before it executes, and signs what it decided. The examiner does not ask whether you noticed the drift. The examiner asks what you did and where the record is.

Read the article →

June 8, 2026

For Model risk leaders, AI governance leads, CISOs, procurement leads, AI insurance counsel

If the Corpus Is Private

A claim that cannot be replayed on a public benchmark is not a claim a counterparty can use.

Vendor demos cite numbers. Hit rate, latency, detection lift. The numbers are precise. The corpus they were measured on is internal, the pipeline is opaque, and the trace is gone. A number measured on private telemetry cannot fail in public. The discipline that makes a claim usable to a counterparty is unglamorous and old. Stand the pipeline on a corpus the counterparty can download. The number either survives or it doesn't.

Read the article →

June 7, 2026

For Model risk leaders, AI governance leads, CISOs, procurement leads, AI insurance counsel

Field notes, week of June 7, 2026

Three standing objections to a signed runtime record. Latency, contract, identity. One week, three answers.

Three pieces this week, each answering an objection to a signed runtime record. It is too slow to sit in the decision path. No one made us produce it. A signature proves nothing. Sixty-one microseconds answers the first. The contract answers the second. A verifiable identity answers the third. The record only counts as evidence when all three hold.

Read the article →

June 5, 2026

For CISOs, identity architects, model risk leaders, AI governance leads

Who Signs the Run

A signature on the trajectory is only evidence if a stranger can verify which agent stood behind it.

Every piece in this series ends at the same place. The record gets signed. A signature attests to an identity, and the identity is the part nobody has specified. Identity-governance for agents is shipping, but it answers whether the agent may act, not which agent did. A trajectory signed with one shared platform key proves the platform emitted bytes. It does not prove which agent, which version, under which policy. The examiner asks the agent what it asks an employee. Who were you, and prove it.

Read the article →

June 3, 2026

For Procurement leads, AI compliance counsel, system integrators, model risk leaders

The Procurement Clause

Why the agent contract, not the audit, is where the record gets won or lost.

SR 26-2 carved agentic AI out of scope and pointed institutions back at their own risk practices. Those practices were written for a model you buy once. An agent run is a service you rent, and the record lives wherever the vendor decides. The control just moved to the contract, and the buyer has leverage exactly once. Before signature.

Read the article →

June 1, 2026

For Model risk leaders, AI governance leads, platform engineering leads, system integrators

Sixty-One Microseconds

What it costs to put governance in the decision path, measured across thirty thousand decisions.

In-flight governance has one standing objection. A governor that fires before the next inference sits in the decision path, and every decision waits for it. We built the runtime and measured it. Sixty-one microseconds at the mean, eighty-three at the ninety-fifth percentile, across thirty thousand governed decisions. The same governor, reimplemented in a second language, signs a byte-identical record. That is what makes the audit object verifiable by a party who trusts neither build.

Read the article →

May 31, 2026

For Model risk leaders, AI insurance counsel, procurement leads, CCOs

Field notes, week of May 31, 2026

Who owns the record, who prices it, who writes it into the contract. Three pieces, three answers.

Three pieces this week. Each names a party who needs the agent record and a moment it has to be secured. The second line decides where it lives. The carrier cannot price what it cannot replay. The buyer has leverage exactly once, before signature. The record does not arrive on its own. Someone specifies it, or no one does.

Read the article →

May 27, 2026

For AI insurance counsel, chief underwriters, reinsurance pricing analysts, model risk leaders

The Underwriting Surface

Why an AI E&O line cannot price what it cannot replay.

An insurance market for adaptive-AI errors is forming. The product needs an underwriting surface. The agent run does not present one today. Carriers writing AI E&O are pricing without loss triangles. Reinsurers are quoting without a forensics path. Both are positions the market will not hold.

Read the article →

May 25, 2026

For Model risk leaders, internal auditors, CCOs, chief AI officers

Where Model Risk Ends

What model risk management keeps owning, and where agent assurance starts.

Model risk management was built for an artifact that does not move. An agent run is an artifact that does. The methodology that worked for the first does not extend to the second. SR 26-2 carved agentic AI out of MRM scope, and the agent run still has to live somewhere.

Read the article →

May 24, 2026

For Model risk leaders, AI governance leads, CCOs, procurement leads

Field notes, week of May 24, 2026

The vendor enforcement layer shipped this week. The audit-grade record did not.

Three pieces this week. One through-line. Enforcement is shipping. Observability is shipping. A signed audit chain that survives a vendor switch is not. The NAIC examination tool is mid-pilot, and SR 26-2 still carves agentic AI out of scope pending the interagency RFI. The runway is finite.

Read the article →

May 22, 2026

For Model risk leaders, AI governance leads, CCOs, AI compliance counsel

Nothing to Freeze

Why replaying the model weights does not reconstruct an agent that learned inside the run.

Static-model audit rests on one move. Freeze the weights, replay the input, reproduce the output. An agent that learns inside a single run breaks that move. The weights never changed, but the behavior did, and there is nothing to freeze and replay against. The reconstruction window is the run itself.

Read the article →

May 20, 2026

For Procurement leads, model risk leaders, CISOs, chief AI officers

Portability Is the Leverage

Why the audit record has to outlive the agent vendor that produced it.

Retention is measured in years. Vendor tenure is measured in quarters. The audit record cannot live where the vendor lives. The third procurement question from the last piece was where the record goes when the agent vendor is replaced. That question is the one with leverage attached.

Read the article →

May 18, 2026

For AI governance leads, CISOs, model risk leaders, system integrators

The Tool-Call Boundary

Why the agent governance launches of the last thirty days enforce, but do not sign.

Thirty days. Three control planes. One missing artifact. Three governance toolkits shipped between April 2 and May 5, each enforcing tool-call policy at sub-millisecond latency. None of them produces the signed record of which calls were allowed, which were blocked, and what the agent did next.

Read the article →

May 15, 2026

For Model risk leaders, internal auditors, CCOs, chief AI officers

The Multi-Step Record Format

What the trajectory has to contain, told as one loan denial.

A bank denies a credit-card application in 2.3 seconds. Three weeks later, the applicant's attorney asks how. The bank logged the input, the output, and the timestamp. The bank did not record the decision graph the agent walked between them. Five primitives are what the record has to contain.

Read the article →

May 11, 2026

For Model risk leaders, internal auditors, CCOs, chief AI officers

The Accountability Gap

What the responsible party hands the examiner in 2029.

Most agency AI deployments today log the input and the output and call it a record. An agent run isn't an input and an output. It's a sequence of tool calls, branches, and intermediate state. Almost nobody is capturing it. Without that record, accountability is a position you take. Not something you can prove.

Read the article →

May 7, 2026

For Risk officers, model risk leaders, AI governance leads, system integrators

The Trajectory Is the Audit Object

What two agentic-AI governance launches in eight days did not solve.

Eight days. Two launches. One missing artifact. On May 6, IBM launched Sovereign Core. Eight days earlier, Atos launched Sovereign Agentic Studios. Two of the world's largest IT firms shipped agentic AI governance offerings inside a single week. Neither produces the evidence object an auditor is about to ask for.

Read the article →

New writing arrives as the work moves.

Write directly if you'd like to be added to the early-read list for forthcoming pieces.