Three pieces this week, each closing a way an agent could vouch for its own record. A record is evidence only when the party under examination could not have shaped it.
It cannot alter the record after the act. It cannot hand its own authority back inside the run. It cannot be the party that signs the account of what it did. A record the actor could shape is a claim, and the examiner needs the one it could not. Integrity closes the first path. The direction authority is allowed to move closes the second. Separation of duties closes the third.
This week.
The Integrity Primitive (June 29). A signed log proves who wrote it. A schema proves what it contains. Neither proves the record in front of the examiner is the one written at the moment of the decision. That third property is integrity, and it is the one the word hash-chained is increasingly used to gesture at without delivering. A record the operator can edit after the run is a claim about the past. Hash-linkage is what turns it into proof that the record has not moved since the decision it documents.
Authority Only Falls(July 1). An agent's authority is not fixed for the length of a run. The governor sets it before each action, and the direction it is allowed to move is the whole control. It falls when realized behavior diverges from the assured trajectory, and inside the run it does not climb back on the agent's own signal. A gate that lets authority rise again on the agent's report shares a failure mode with the behavior it is meant to bound. Recovery is a separate authorized act, recorded.
Separation of Duties (July 3). Internal audit has split custody, authorization, and recording for a century, so no single party can both act and account for the act. An agent run collapses the split. One platform authorizes the action, executes it, and writes the log. A record the actor produces about its own conduct is a claim, not evidence. The examiner pulls one decision and asks who executed it and who recorded it, and whether those were the same party.
What changed.
The EU AI Act simplification package cleared its last legislative gate. The European Parliament endorsed the provisional agreement on June 16, and on June 29 the Council gave its final approval. The remaining step is publication in the Official Journal, and the revised timeline binds on that date, not on the vote. On publication, the high-risk obligations defer toward December 2, 2027 for stand-alone Annex III systems and August 2, 2028 for AI embedded in regulated products. Until the text appears, the August 2, 2026 transparency obligations are still the ones in force. Provisional agreement is not law. Publication is.
The federal carve-out holds. The model-risk guidance that took effect April 17 still leaves generative and agentic AI outside its scope, and the interagency request for information the agencies signaled has not yet issued. The burden did not disappear. It sits with the institution until the RFI lands. Where that RFI draws the line between model risk and agent assurance is the line we are watching.
Congress moved toward agent identity. A Senate bill would require certain autonomous agents to register with a federal regulator before acting through platform interfaces they do not own, and would bound what such an agent is authorized to do to a documented, limited, revocable grant. The mechanism is registration, not a signed per-decision record. The premise underneath it is the one this series keeps returning to. An agent that acts on someone's behalf has to be identifiable as the specific agent that acted.
The state insurance examiner stays on schedule. The NAIC AI Systems Evaluation Tool pilot runs through September across twelve states, with adoption expected at the Fall National Meeting. Carriers are pushing back on how much it asks. The instrument and the method are still on track to reach the market-conduct examiner before the federal banking examiner finishes its own rule.
What we are tracking.
The Official Journal date. The revised high-risk timeline binds on publication, not on the Council vote. Until the Omnibus text appears, the deadlines in force are the old ones, and the August 2 transparency obligations still apply. The gap between the vote and the print date is where a firm decides what its own record looks like.
The interagency RFI. The banking agencies have signaled a request for information addressing model risk and banks' use of AI, generative and agentic. The carve-out holds until it lands. The line it draws between model risk and agent assurance is the one with the most riding on it.
Pre-execution placement. The wave of approaches that move the control before a durable effect is created keeps growing. Authorization before the tool call. Qualification of the output before it commits to memory or fires a tool. Placement answers where the control stands. It still leaves open what the control decided, at what authority, and whether the record of that decision can be replayed by a party who trusts neither vendor.
Thirty minutes. Architecture, not sales.
A conversation about what the trajectory record has to contain to survive the next examination cycle, and where the artifact should live in your organization.
JonathanLuethke@WayfinderSystemsGroup.com
