Explainability is the control most often reached for when an agent makes a decision someone has to answer for. It returns an account of why the model produced the output. The account is assembled after the action has already run.
An account of a decision is not the authority that governed it.
Two questions. One of them governs.
Explainability answers one question. Why did the model produce this output. The answer is a statement about the model's internal reasoning, an attribution over inputs, a ranking of features, a rationale rendered in words.
Governance answers a different question. What was this agent permitted to do at this step, and was the action held to that limit before it executed. The answer is a value, the authority the action carried, and a record that the value was applied.
The first question is about the model's reasons. The second is about the action's authority. The examiner who pulls one decision out of a year of them is asking the second.
The explanation arrives after the effect.
Post-hoc explanation is read off the model once the output exists. The attribution map, the surrogate model, the rationale in plain language. Each is generated after the fact, against a decision the agent has already made.
By the time the explanation can be produced, the tool call has fired, the record has been written, the funds have moved. The explanation describes an action that already committed. It never stood between the decision and its effect.
A control that runs after the effect is forensics. Forensics has a place. It is not the control that sets the bound before the action is allowed to run.
An explanation does not record authority.
The explanation states why. It does not state what the agent was allowed to do, which policy was in force at that moment, or whether the action was reduced or stopped against it. Those are different facts, and the explanation carries none of them.
Hold two agents side by side. Same output, same attribution, same rationale. One acted at full authority. The other had its authority cut by a control that judged the moment risky. The explanation reads identically for both. The fact that separates them is the authority that bound the act, and the explanation does not hold it.
Explanation is a reconstruction. Authority is a constraint applied before the act.
The regulator named explanation. The enforcement was deferred.
Explanation is a named regulatory good. The NIST AI Risk Management Framework lists explainability and interpretability among the characteristics of a trustworthy system. The transparency expectations in the EU framework point the same way.
The system that would put a control in the decision path is the part that slipped. EU AI Act Article 9 high-risk obligations were deferred to December 2, 2027 for standalone systems and August 2, 2028 for embedded ones under the Digital Omnibus. SR 26-2 took effect April 17, 2026, carved agentic AI out of scope, and pointed institutions back at their own risk practices, with an interagency RFI still forthcoming.
The expectation to explain is on the books. The obligation to govern the act at runtime is not yet. Firms are closing the visible half of that gap with tooling that documents reasoning and leaves the action ungoverned.
What the control records instead.
A control that governs the act sits before the effect commits. It reads the divergence between expected and observed behavior. It bounds the trust the behavior earns. It modulates the authority of the next action against that bound. It enforces the reduced authority at the point of action. It signs what it decided.
The artifact it leaves is not a story about the model's reasoning. It is the authority that was in force, the action that was permitted, and the limit applied, written the moment the decision forms onto a chain a third party can verify.
An explanation has to be summoned by a question. This record is produced by the act of governing, whether or not anyone asks.
What we are building.
Wayfinder Systems Group builds the control that sits in the decision path and governs the act before it commits. It does not explain the model. It bounds what the model's agent is allowed to do, applies the bound the moment the decision forms, and signs the authority it set onto a tamper-evident chain. The reviewer reads the exceptions. The examiner reads the chain. It does not retrain the model or redesign the autonomy stack. It sits above control and below intelligence. Patents held in The Wayfinder Trust. We call her Velma.
Thirty minutes. Architecture, not sales.
A conversation about which of your AI controls explain a decision after it runs, which govern the act before it commits, and where the authority record should live in your organization.
JonathanLuethke@WayfinderSystemsGroup.com
