Three pieces this week on where a control has to stand to bind an action. The reference it grades against is declared outside the run, the bound holds only on the only path to the effect, and a power that inspects the provider after the fact stands at a third place entirely.
A runtime governor's authority to bind an action comes from where it stands relative to the action, not from the policy it happens to carry. The declared envelope puts the reference outside the run, so the acting system cannot move the line it is graded against. The construction puts the bound on the only path to the effect, so the agent cannot reach the actuator around it. And the enforcement power that became applicable today stands at a third place, above the provider and after the fact.
A control set above the run declares. A power that inspects the provider fines. The governor decides in the path, before the effect lands, and against a reference the acting system did not draw. A power that inspects the provider reaches a product after the fact. A bound that governs an action reaches it in the path, before the effect lands. That altitude difference is what the week's three pieces separate.
This week.
The Declared Envelope (July 27). A governor modulates authority against a reference it did not produce, and that reference is the safety envelope. Where it comes from decides whether the governor is governing anything at all. A boundary the acting system draws for itself is not a boundary, because it drifts with the behavior it is meant to bound. The envelope has to be declared before the run, held outside the acting process, and not rewritable by the run. Whoever declares it holds the reference every authority decision is measured against, so it cannot be the system under governance and should not by default be only the vendor whose system is governed. On an action the envelope never anticipated, the governor grants less authority, not the benefit of the doubt. Silence is not a grant.
Bounded by Construction(July 29). A governor sets how much authority an agent's next action carries, and that grant is only real if the agent cannot reach the effect by a path the governor does not sit on. Most agent builds express the bound as a rule the agent is asked to obey, a policy in the prompt or a checker beside the execution path. A rule the agent can be steered off, and a checker it can route around, both depend on the agent staying cooperative, and the one case governance exists for is the case where it does not. Put the governor on the only path to the actuator and the agent's latitude is exactly what the governor grants, and no more, because there is no path to more. That is bounded autonomy as a construction, not a promise, and it holds at the exact moment an advisory bound fails: the compromised agent, the drifted agent, the agent pursuing an injected goal with valid credentials.
Enforcement Reaches the Provider(July 31). On August 2 the EU AI Act's supervision and enforcement powers over general-purpose AI model providers become applicable. The Commission can request the documentation, evaluate the model, order it withdrawn from the market, and impose a penalty. That power reaches the provider and the model as a product, on inspection and after the fact. An agent action is a different object. It happens thousands of times inside one run, and it becomes a durable effect at a single instant. A control that governs it has to sit in the path the action takes, before the effect lands, and set how much authority the action carries. A fine reaches the provider after the effect. A bound reaches the action before it.
What changed.
The August 2 milestone arrived. From today the European Commission and its AI Office hold enforcement powers over providers of general-purpose AI models. Request the technical documentation. Run an evaluation of the model. Demand risk-mitigation measures. Restrict or withdraw the model from the EU market. Impose a penalty. The substantive obligations on those providers applied a year ago, from August 2, 2025. The power to enforce them is what switched on today, and every power on that list acts on the provider and the model as a product, on inspection, after the effect. Enforcement that reaches a single agent action sits in the path the action has to take, not above the provider that shipped it.
The date was set to carry more. Under the Digital Omnibus, given final Council approval on June 29, the high-risk obligations that were once due today moved off it. The standalone high-risk deadline for Annex III systems is now December 2, 2027, and the embedded deadline for high-risk AI in regulated products under Annex I is August 2, 2028. What stayed on August 2 is the general-purpose enforcement power and the Article 50 transparency duties, which the Omnibus left where they were. Those transparency duties bind a particular output at the instant it reaches a person, and that instant sits inside the run, not above it.
The federal carve-out holds. The model-risk guidance that took effect April 17 places generative and agentic AI outside its scope, and the interagency request for information the agencies signaled has not issued. The burden sits with the institution until that line is drawn. The state insurance track keeps its own schedule. Twenty-five states and the District of Columbia have adopted the NAIC model bulletin, the multi-state evaluation tool is in pilot across a dozen states, and both broader adoption and the tool itself are expected at the fall national meeting.
What we are tracking.
The altitude the enforcement power operates at. Today's EU power reaches the provider and the model as a product. The unit the month's other moves keep naming is the individual action. China's agent opinions grade an action into an authorization tier. Registry bills name the agent before it runs. The question underneath all of them is where the control that meets a per-action obligation actually sits, above the run or in the action's path.
Who declares the envelope. If authority is graded against a boundary, the boundary has an author, and the accountable party is not always the vendor whose system is governed. Where regulation lands the duty to set and hold that boundary, and whether it can rest with the system under governance, is the open question the declared-envelope piece opened this week.
The line between model risk and agent assurance. SR 26-2 pointed institutions back at their own practices and signaled an RFI that has not issued. Where it draws the boundary between a model you validate once and an agent run you have to reconstruct is the question with the most riding on it.
Thirty minutes. Architecture, not sales.
A conversation about where your system's authority is set today, whether the bound that governs an action sits on the only path to the effect or beside it, and who holds the reference the governor grades each action against.
JonathanLuethke@WayfinderSystemsGroup.com
