Three pieces this week on obligations the run sets and the convenient build leaves optional. When the record has to seal, what a control has to bound before an attack has a name, and the authority a reviewer's click actually granted.
Each piece isolates a demand the run itself imposes on the record. A deadline no operator chose. A bound that has to hold before anyone can name the thing it holds against. A scope of authority fixed by the action a reviewer saw, not by the two fields a log kept.
Each obligation looks like a choice until the run sets it. Before the action runs, the latency budget reads as a design preference. So does the signature list, and so does the logging schema. After the action runs, each one is the fact an examiner pulls one decision to test.
This week.
Time to Receipt (July 13). A governed action seals a record, and the standing question is how much the sealing slows the agent. That question is incomplete. The record has a deadline the run sets, fixed by the moment a later step starts to depend on the action just taken. If the record is not sealed before the second action depends on the first, the run has built on an action it cannot yet prove. Throughput asks how fast the governor signs. The governance SLA asks whether the record is sealed before any later action is permitted to depend on it.
The Signature Arms Race(July 15). The security layer for agents is filling with detectors, and each one has to recognize an attack before it can stop it. Every technique that has not been written into a signature yet passes. A subverted agent does not break out. It uses the tools it was already cleared to use to pursue a goal it was never given, and the identity, the credentials, and the permission set all stay intact. A runtime authority control reads the behavioral divergence directly and clamps what the agent may do next, without needing the attack's name. The detector's problem grows with every new technique. The governor's problem is fixed.
What the Override Granted(July 17). Every agent platform shipping today has an escalation path. The agent stops and asks a person, and that half is built. The return path is a button, and what the button granted is not written down anywhere. A grant of authority has a scope, an end, a binding to the specific action the reviewer saw, and the reviewer's own envelope. The log holds a name and a timestamp. Approval is the event. The grant is the artifact, and it is the one the examiner reads.
What changed.
The EU AI Act simplification package cleared its last vote and now waits on the printer. The European Parliament endorsed the agreement on June 16 and the Council gave final approval on June 29. The revised timeline binds on publication in the Official Journal, not on the vote, and as of this writing the text has not appeared. Until it does, the August 2, 2026 obligations are the ones in force. On publication, the high-risk obligations defer toward December 2, 2027 for stand-alone systems and August 2, 2028 for AI embedded in regulated products. The date to watch is the print date, because the deadline in force is the old one until the new text lands.
A national framework for agents took effect on July 15. It sorts an agent's actions into tiers of required authorization and adds a filing obligation before certain agents operate. The mechanism is a grade applied to the action. A grade applied to an action is not yet a record that the grade was applied. The scheme names the authorization an action needs. The artifact that proves which grade governed a specific action, sealed where a later reader can replay it, is the part the regime still has to specify.
The federal carve-out holds, and the agencies are still asking for input. The model-risk guidance that took effect April 17 places generative and agentic AI outside its scope, and the interagency request for information the agencies signaled has not yet issued. The burden did not move. It sits with the institution until the RFI draws the line between a model you validate once and an agent run you have to reconstruct.
The state insurance examiner stays on schedule. The multi-state evaluation-tool pilot runs through September across twelve states, with an update in the fall and adoption expected at the November national meeting. The instrument reaches the market-conduct examiner before the federal banking rule is written.
What we are tracking.
The Official Journal date. The revised high-risk timeline binds on publication, not on the Council vote. The gap between the vote and the print date is the window in which a firm decides what its own record looks like, because until the text lands the old deadlines still govern.
The line between model risk and agent assurance. The banking agencies have signaled an RFI on model risk and banks' use of generative and agentic AI. Where it draws the boundary between a model you validate once and an agent run you reconstruct is the question with the most riding on it.
Authority as a graded value. Agent-specific regimes are beginning to grade an action into an authorization tier, which is a discrete pick from a short list. Whether that grade is a value on a continuum, and whether the fact that it was applied is sealed in a form a later reader can replay, is the open question underneath every one of them.
Thirty minutes. Architecture, not sales.
A conversation about where your enforcement point sits relative to the moment an agent action becomes irreversible, and whether the record you seal there can be read by a framework that arrives tomorrow.
JonathanLuethke@WayfinderSystemsGroup.com
