Three pieces this week. Each one names a property the runtime control has to have before its record counts as evidence.
Where the control stands. What it emits. Whether it can fail with the agent it watches. Position, output, independence. A control that stands at the wrong moment, emits the wrong shape, or shares a failure with the thing it governs produces a log, not evidence.
This week.
Training Time Is Too Early(June 15). Most AI governance acts before the agent runs. Alignment, red-team evaluation, guardrail tuning, the sign-off that clears the build. All of it calibrated against a model frozen at release, against inputs the live run will not resemble. Training time sets the model's disposition. Inference time is where the decision happens, and a control fixed at the first does not bind the second. The examiner pulls one decision that affected a person and asks what governed it. A training-time record shows the model was sound when it shipped. It does not show what the control did when the agent denied this claim, on this day, on the tool results in front of it.
Between Allow and Block (June 17). Most agent enforcement answers one question. May this action run. The answer comes back as a pick from a short list. Allow. Block. Send it to a human. The authority the action actually carried is not on that list. A discrete gate can pass an action or stop it. It cannot pass the action with its authority reduced, and most decisions an agent makes sit in that missing middle. The examiner does not pull a category. The examiner pulls one action and asks what governed it. A record that says the action was allowed answers almost nothing. The record has to hold the value the action carried, not the bucket it fell into.
The Common Mode(June 19). A controller that logs its own performance as nominal, and a monitor that believes the log, fail at the same moment. The doer/checker architecture splits the capable component from the conventional one that holds the safe operating envelope. The moment the checker grants partial authority instead of a binary stop, the two have to be argued not to fail together, and freedom from common-mode failure becomes the whole safety case. One common mode closes by construction. A checker whose trust reads the doer's self-report shares a failure with it, so the checker's trust must not read the self-report at all. It scores the action on the divergence between what the action implied and what the world returned. The rest of the independence argument stays owed in full.
What changed.
The federal banking carve-out held, and the examiner kept asking anyway. SR 26-2 took effect April 17, 2026 and placed generative and agentic AI outside its scope, pointing institutions back at their own risk practices, with a separate interagency request for information on AI signaled but not yet issued. Reporting this month describes AI-governance questions entering standard bank examinations, while industry surveys this spring put a majority of banks unable to confirm they could halt a malfunctioning AI model or report the failure to a regulator. The distance between deploying the model and proving control over it is an examination item the carve-out called premature.
The EU Digital Omnibus is moving from provisional agreement toward law. Formal adoption is now expected in the coming weeks, with publication in the Official Journal anticipated this summer. On publication, the high-risk obligations defer toward December 2, 2027 for stand-alone Annex III systems and August 2, 2028 for AI embedded in regulated products. The same package adds a new Article 5 prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material. Until the text is published, the deadlines on the books are the old ones, and the August 2, 2026 date has not formally moved.
The NAIC AI Systems Evaluation Tool pilot runs March through September across twelve states, with adoption expected at the Fall National Meeting in November. The state insurance examiner is still on track to move before the federal banking examiner finishes writing its own rule.
What we are tracking.
The pre-execution placement wave. A cluster of agent-governance approaches now positions control before a durable effect is created. Authorization before the tool call. Qualification of the output before it commits to memory or fires a tool. Placement before the effect answers where the control stands, which is the right half of the problem. It does not by itself produce the signed, replayable record of what the control decided and at what authority. Placement without a record is half the control loop.
The interagency RFI. The banking agencies have signaled a request for information that addresses AI, generative AI, and agentic AI directly. The carve-out points institutions back at their own risk practices until it lands. Where that RFI draws the line between model risk and agent assurance is the line we are watching.
The Official Journal date. Provisional agreement is not law. The revised high-risk timeline becomes real on publication, and the date that publication lands is the date the deferral binds. Until then the old deadlines remain the ones in force.
Thirty minutes. Architecture, not sales.
A conversation about what the trajectory record has to contain to survive the next examination cycle, and where the artifact should live in your organization.
JonathanLuethke@WayfinderSystemsGroup.com
