Three pieces this week. Each one separates a control that resembles governance from the authority an examiner actually pulls.
One control is set at the wrong moment. One records the wrong fact. One records a single actor where two authorities governed. The authority that governed a single act is fixed when the agent acts. A clearance issued before the run cannot hold it. An explanation assembled after the run does not contain it. A record of one approver cannot show that a second authority concurred before the act. The examiner pulls one decision and asks what bound it, and none of the three answers on its own.
This week.
Training Time Is Too Early (June 22). Most AI governance acts before the agent runs. It calibrates a model frozen at release, against inputs the live run will not resemble. An agent does not hold still. It composes inputs the certification never saw and acts on tool results that did not exist when it was cleared. A clean pre-deployment evaluation does not transfer to the decision the agent makes at inference. The examiner pulls one decision that affected a person and asks what governed it, and a training-time record answers a different question.
Explanation Is Not Authority (June 24). Explainability is the control most often reached for when an agent makes a decision someone has to answer for. It returns an account of why the model produced the output, assembled after the action has already run. That account is not the authority that governed the act. It does not say what the agent was allowed to do, which policy was in force, or whether the action was reduced or stopped before it executed. The examiner who pulls one decision needs the authority that bound it, not the reason the model gave.
The Second Authority (June 26). A high-consequence action does not run on one approval. A wire above a threshold or a model promoted to production needs two parties to concur, and the record has to hold both, with the second concurrence fixed before the act and bound to the specific action proposed. An agent collapses the two roles by default. It proposes and it acts on one credential in the same instant, so the second authority is the first thing that goes missing. The examiner pulls one decision and asks who else had to say yes, and when, and a log of one actor cannot answer.
What changed.
The federal model-risk guidance that took effect April 17 left generative and agentic AI outside its scope, and independent commentary this month read the carve-out the way the examiner will. The burden did not disappear. It moved to the institution. SR 26-2 points banks back at their own risk practices and signals an interagency request for information on AI that has not yet issued. The window between the carve-out and the RFI is where a firm decides what its own record looks like.
The EU Digital Omnibus advanced. The European Parliament endorsed the provisional agreement on June 16, and formal adoption by the Council is the remaining step before publication in the Official Journal. On publication, the high-risk obligations defer toward December 2, 2027 for stand-alone Annex III systems and August 2, 2028 for AI embedded in regulated products. Until the text is published, the August 2, 2026 date on the books has not formally moved, and the transparency obligations tied to that date still apply.
A new agentic-AI governance framework published this month names the three needs the series keeps returning to. Visibility into what the agent did. Access control that does not rest on the agent's own identity. An audit trail a regulator can review. Naming the needs is not producing the artifact. Reporting this month also describes agent deployments paused or rolled back in production, with data exposure and hallucinated output the named causes. The operational case for a per-decision record is arriving ahead of the regulatory one.
The NAIC AI Systems Evaluation Tool pilot runs through September across twelve states, with adoption expected at the Fall National Meeting in November. Carriers are pushing back on how much it asks. The state insurance examiner is still on track to hold both the instrument and the method before the federal banking examiner finishes its own rule.
What we are tracking.
The interagency RFI. The banking agencies have signaled a request for information addressing model risk and banks' use of AI, generative and agentic. The carve-out holds until it lands. Where the RFI draws the line between model risk and agent assurance is the line we are watching.
The Official Journal date. Provisional agreement is not law. The revised high-risk timeline binds on publication. Until the Omnibus appears in the Official Journal, the deadlines in force are the old ones.
Pre-execution placement. The wave of approaches that move the control before a durable effect is created keeps growing. Authorization before the tool call. Qualification of the output before it commits to memory or fires a tool. Placement answers where the control stands. It still leaves open what the control decided, at what authority, and whether the record of that decision can be replayed by a party who trusts neither vendor.
Thirty minutes. Architecture, not sales.
A conversation about what the trajectory record has to contain to survive the next examination cycle, and where the artifact should live in your organization.
JonathanLuethke@WayfinderSystemsGroup.com
