← All articles

July 26, 2026

Field notes, week of July 26, 2026

Three pieces this week on where an obligation lands. A registry names the agent, a disclosure rule binds the output, and the authority that governs an action is set in front of the action, not declared above the run.

By Jonathan Luethke

Three pieces this week on where an obligation lands. A registry names the agent, a disclosure rule binds the output, and the authority that governs an action is set in front of the action, not declared above the run.

Two regulators moved this month, and each attached a duty to a particular action rather than to the system that took it. China's agent opinions became enforceable and grade an action into an authorization tier. The European Commission's Article 50 guidelines fix disclosure to the instant an output reaches a person. Registration declares that an agent exists. A disclosure rule binds one output. Neither is discharged by a document held above the run.

The authority that governs an action, and the duty that binds it, are both fixed at the instant the action runs. A governor standing in front of that action sets the one and discharges the other. A governor can grant less authority on a step whose present trust reads higher, because its forward look caught a divergence before the outcome landed. That is the week's sharpest fact, and it is the reason a control set above the run cannot do the governor's work. A filing declares. A banner asserts. The governor decides, in the path, before the action commits.

This week.

The Registry and the Record(July 20). Governments are beginning to require that an agent be registered before it runs. China's implementation opinions on intelligent agents became enforceable July 15, and a bill in the US Senate would put certain user-facing agents on a federal register before they may reach the platforms they act on. Registration establishes that the agent exists and what it was declared to do. It is silent on what a single action the agent took was authorized to do. A declared purpose is a category. An action is a particular that falls inside it or does not. Registration is the roster. The record is the account of what a registered identity actually did, under what authority, and whether the action was reduced or stopped before it ran.

Higher Trust, Less Authority(July 22). Most runtime controls widen a system's latitude when its present signal looks good, and the signal comes from the same process that is acting. Trust and authority are two quantities, not one. Trust is what the system reports about itself. Authority is what the governor grants for the next action, and the two are allowed to move in opposite directions. The governor sets authority on where the trajectory is heading, and it can grant less on a decision whose present trust reads higher, because its forward look caught a divergence the current step has not surfaced. Higher trust, less authority, because it anticipated. The grant is a ceiling the acting system cannot exceed, and it does not swing back on the system's own report that all is well.

The Moment of Disclosure (July 24). On July 20 the European Commission adopted the final Guidelines on the Article 50 transparency obligations, which apply from August 2. Every duty in the article attaches to a moment. The interaction notice is owed at first interaction. The marking duty attaches at output generation. The deep-fake disclosure attaches before or at presentation. An agent run separates the step that generates content from the step that puts it in front of a person, and provenance crosses those hops only if something carries it. A duty that binds one output is discharged by a governor standing ahead of the emit, granting less authority when provenance is thin and the marking may not have survived the trip.

What changed.

The Commission's Article 50 guidelines are the concrete event of the week. Fifty-one pages of practical guidance, adopted July 20, less than two weeks before the obligations apply on August 2. The guidance fixes the standard and leaves the mechanism open. Clear and distinguishable. Detectable in machine-readable form. Owed at the latest at first interaction. Those are properties of a system while it is running, and the guidance does not say how a multi-step agent holds them across a chain of tool calls. That gap belongs to the deployer, and the date is now days away.

Read the month's moves together and one direction shows. China's agent opinions became enforceable July 15 and grade an action into an authorization tier. Singapore's national AI-testing framework added multi-step and autonomous-action testing this month. The EU fixes disclosure to the instant an output reaches a person. Three jurisdictions, one direction. Each is moving the unit of governance from the system to the individual action, which is the unit a runtime governor already sets authority on. The obligation is converging on the action. The control that meets it has to live in the action's path.

The state insurance examiner stays on schedule. At least twenty-four states and the District of Columbia have adopted the NAIC model bulletin, and broader adoption is expected at the fall national meeting. The multi-state evaluation-tool pilot runs through September. The instrument reaches the market-conduct examiner on its own timeline, ahead of any federal banking rule.

The federal carve-out holds. The model-risk guidance that took effect April 17 places generative and agentic AI outside its scope, and the interagency request for information the agencies signaled has not issued. The burden did not move. It sits with the institution until that line is drawn.

What we are tracking.

August 2. The Article 50 obligations apply in days. The question underneath them is mechanical. Where in the agent path does the disclosure decision sit, and what proves the marking survived the trip from the step that generated the content to the step that emitted it.

The line between model risk and agent assurance. SR 26-2 pointed institutions back at their own practices and signaled an RFI that has not issued. Where it draws the boundary between a model you validate once and an agent run you reconstruct is the open question with the most riding on it.

Authorization as a graded value. The agent-specific regimes now grade an action into a tier, which is a discrete pick from a short list. Whether that grade is a value on a continuum, set on where the action is heading rather than on how the present step looks, and whether the fact that it was applied is sealed where a later reader can replay it, is the question underneath all of them.

Next step

Thirty minutes. Architecture, not sales.

A conversation about where your system's authority is set today, whether the disclosure and authorization decisions sit in the agent's path or in a document above it, and what a governor has to read to set the grant before the action commits.

JonathanLuethke@WayfinderSystemsGroup.com