Three pieces this week on the single moment an agent action runs. The authority that governs it is set there, the record of it has to seal there, and the record sealed there is the one every regulator reads afterward.
An agent action runs once, and that one instant fixes three things at once. The authority that governs the act is set there. The record of it has to close there. And the record sealed there is the one every regulator reads long after the act is done.
Before that moment a permission is only a boundary. After it an explanation is only a description. The control that governs the act and the record that proves it both live on the near side of the one instant the action becomes real.
This week.
Permission Is Not Authority (July 6). A scoped permission set is drawn once, at provisioning, and fixes what the agent may touch. It does not decide what a single action, taken partway through the run, is allowed to do. An agent can act outside its intended purpose while staying inside the permissions it was granted. Permitted is not governed. The authority that governs one action is a runtime value set when the agent proposes the act, and a standing grant does not carry one.
The Point of No Return (July 8). An agent action becomes real when the effect lands. A payment leaves an account. A row is written to a system of record. Before that boundary the action is contingent and can still be reduced, held, or refused. After it there is only the account of what already happened. The control that governs the act has to sit on the near side of the boundary, and the record it signs has to close there too, before the run that produced the effect could revise it.
One Record, Every Regulator (July 10). A regulated firm answers to several authorities at once, and the agent action underneath them is one event. A record shaped to the framework in force when the system shipped answers that framework and reconstructs for the rest. Seal one canonical record at the moment the action runs, in a schema that names the facts of the decision rather than the clauses of any one rulebook, and the mapping to each regime becomes a projection applied when the record is read. One act, one sealed record, many readers.
What changed.
The EU AI Act simplification package cleared its votes and now waits on the printer. The European Parliament endorsed the agreement on June 16 and the Council gave final approval on June 29. The revised timeline binds on publication in the Official Journal, not on the vote, and as of this writing the text has not appeared. Until it does, the August 2, 2026 transparency obligations are the ones in force. On publication, the high-risk obligations defer toward December 2, 2027 for stand-alone systems and August 2, 2028 for AI embedded in regulated products. The same package writes a new Article 5 prohibition on AI-generated non-consensual intimate imagery and abuse material, with compliance set for December 2, 2026. The vote is not the deadline. Publication is.
The federal carve-out holds, and the agencies are asking for input. The model-risk guidance that took effect April 17 still places generative and agentic AI outside its scope, and the interagency request for information the agencies signaled has not yet issued. The Federal Reserve is separately soliciting input on governance approaches for these systems. The burden did not move. It sits with the institution until the RFI draws the line between model risk and agent assurance.
The Senate bill defining agents is still the identity story. It would treat an agent as software a user authorizes to act on their behalf in a documented, limited, and revocable way. The mechanism is registration and a bounded grant, not a signed per-decision record. A grant bounds what the agent may do. It does not record what one action, taken inside that grant, was allowed to do, which is the distinction this week's first piece drew.
The state insurance examiner stays on schedule. The NAIC AI Systems Evaluation Tool pilot runs through September across twelve states, with an update in the fall and adoption expected at the November national meeting. Carriers are pushing back on how much it asks. The instrument still reaches the market-conduct examiner before the federal banking rule is written.
What we are tracking.
The Official Journal date. The revised high-risk timeline binds on publication, not on the Council vote. The gap between the vote and the print date is the window in which a firm decides what its own record looks like, because until the text lands the old deadlines still govern.
The line between model risk and agent assurance. The banking agencies have signaled an RFI on model risk and banks' use of generative and agentic AI. Where it draws the boundary between a model you validate once and an agent run you have to reconstruct is the question with the most riding on it.
Pre-execution placement. More approaches now move the control before a durable effect is created, and several qualify the proposed action before it commits to memory or fires a tool. Placement answers where the control stands. It leaves open what the control decided, at what authority, and whether the record of that decision was sealed on the near side of the effect and can be replayed by a party who trusts neither vendor.
Thirty minutes. Architecture, not sales.
A conversation about where your enforcement point sits relative to the moment an agent action becomes irreversible, and whether the record you seal there can be read by a framework that arrives tomorrow.
JonathanLuethke@WayfinderSystemsGroup.com
