Three pieces this week on timing. Every bound is written at one moment and has to be true at a later one. What sits between those two moments is where the week's argument lives.
The three answers converge. A declaration fixes a bound once and the run happens afterward, and what a governor adds is a decision taken at the second moment rather than a restatement of the first.
This week.
The Claim the Safety Case Can Keep (August 31). A safety case is a structured argument, supported by evidence, that a system is acceptably safe in a stated operating context. It names a system, names the context, states the hazards, and holds as long as its subject holds. That constraint was affordable when the subject was a fixed artifact, verified once and fielded, computing ten years later what it computed on the day the case was signed. An adaptive system is a different subject. Its behavior in month nine is not the behavior the case examined in month zero, and the interval between material changes falls below the interval a re-argument takes. The claim a conventional case makes is broad. This system will not leave its envelope. A governor in the action path supports a narrower one. No action carrying authority outside the declared envelope reaches the actuator. That subject is a control that sits in one place, adds no intelligence of its own, and does not learn, and a property of a path is established by inspecting the path. Four questions about it are answerable by inspection and fixed at build time. Whether the enforcement point sits on the only path to a durable effect. What an action carries when no grant arrives. Which direction an uncertain forward look rounds. Whether a grant already set can be widened from inside the run. Three debts stay with the case. Declaring the envelope is a separate act with a separate owner, and a governor holding a wrong envelope holds it exactly. A hazard that perturbs nothing the governor measures produces a clean reading and a full grant. A governor placed beside the actuator rather than in front of it returns the argument to a promise.
The Grant Outlives the Reading (September 2). A governor sets how much authority the next action carries, and it sets that at one instant, on what it can read at that instant. The action then takes time to complete, and everything between the grant and the effect is covered by a reading that is already behind. Some actions are close enough to instantaneous. A message emitted, an authorization returned, a single write to a row. Many are not. A funds transfer settles across an interval, a batch job runs against a remote system for minutes, a physical maneuver holds continuous actuation, and an agent tool call opens a connection, negotiates, waits, and returns when it returns. The horizon of the forward look and the duration of the action are the same quantity. Forecast quality falls with horizon, so a long action pays twice, once for the longer interval and once for the worse estimate covering it. Three moves close the interval and they are not interchangeable. Shorten the action by decomposing it into steps that each get their own grant, which a settlement or a maneuver often cannot do. Shorten the grant with an expiry, which requires the enforcement point to take authority back from work already underway. Widen the margin by granting less than the forward look supports, which asks nothing of the actuator and costs capability on every action. Only the third is always available. Withdrawal is a different operation from refusal. Refusal happens before the action starts and leaves nothing behind. Withdrawal happens to an action already in flight and leaves a partial effect that something has to own.
A Fraction of a Decision(September 4). On August 31, 2026 the California Legislature approved SB 947, the No Robo Bosses Act of 2026, which bars an employer from relying solely on an automated decision system to discipline or terminate a worker. Solely is a word about how much authority the system carried on one decision. Most AI legislation bounds one of three things. What data may enter, what purpose the output may serve, and who has to be told. This one bounds how much of the decision the system was allowed to be. Read literally, solely describes a share, and the trouble is that a decision does not divide. A worker is terminated or is not, and there is no ninety percent of a firing. What divides is the authority behind it. Two arrangements satisfy the statute identically on paper. In the first a reviewer reads the file, has access to what the system did not see, and reaches a different outcome often enough to matter. In the second a reviewer approves a queue of recommendations at the rate they arrive, the system's effective authority over the outcome is total, and the language is still satisfied. SB 947 sets its bound by category and sets it once, drawn before any particular case arrives by a legislature that will never see one. A governor works at the other end, setting how much authority the next action carries per action at runtime, against an envelope declared before the run and outside it, starting from withheld and granting only what it can assure. The statute fixes a ceiling for a class. A governor sets the grant for the case.
What changed.
Friday's piece anchored on a bill that is still unsigned. The Legislature approved SB 947 on August 31, 2026 by 53 to 14 in the Assembly and 28 to 10 in the Senate, and it is now with the Governor, whose window to sign or veto closes on September 30, 2026. Its predecessor, SB 7, was vetoed in October 2025 on the reasoning that its scope was too broad and overlapped existing employment and discrimination law. If SB 947 is signed, its requirements become operative on July 1, 2027, which leaves employers a defined interval to build something.
That interval is the week's subject in a different costume. The obligation is fixed by a legislature at one moment, over a category of employer and a category of system, before any particular termination exists. The behavior it governs happens continuously afterward, case by case, in a workflow no legislator will ever see. What most employers will produce in the interval is a policy stating that no automated system decides alone, plus a review step in the workflow. A policy asserts the bound. A control holds it. The difference appears in the path between the recommendation and the effect, and if the termination can be executed without the grant, the bound describes intended behavior rather than actual behavior.
The European calendar has the same shape at a larger scale. The Digital Omnibus entered into force on July 27, 2026, three days after publication in the Official Journal, and moved the high-risk obligations of the EU AI Act off August 2, 2026. Standalone systems in the Annex III list now fall on December 2, 2027, and AI embedded as a safety component of a product already covered by EU product safety law under Annex I falls on August 2, 2028. Three sets of duties did not move. Article 50, the transparency and AI-content-labeling duties. Article 5, the prohibited-practices regime in force since February 2025. The obligations on general-purpose model providers, applying since August 2025. A deferral moves the date the argument is due. It does not move the date the systems go into service, and the systems are in service now. Every month of the deferral is a month of production behavior the eventual argument has to cover in retrospect, out of records written by whoever thought to write them.
The supervisory record did not move either. SR 26-2, the revised interagency guidance on model risk management that took effect on April 17, 2026 alongside OCC Bulletin 2026-13 and FDIC FIL-15-2026, replaced the 2011 guidance and placed generative and agentic AI outside its scope on the reasoning that the technologies are novel and rapidly evolving. The agencies said then that a request for information covering banks' use of generative, agentic, and AI-based models would follow. Nearly five months later it has not issued. Institutions are fielding agents against enterprise risk, cybersecurity, data governance, and operational risk frameworks written for something else, and the interval between the carve-out and the instrument meant to fill it is being spent in production.
What we are tracking.
Whether SB 947 is signed, and what gets built if it is. The bill asks for independent corroboration rather than review alone, which means a second determination reached from something other than the first system's output. What makes a determination independent is a property of the path the decision travelled, and a statute cannot inspect a path. It can only require that one exist. The file that satisfies a reviewer in 2027 is the one showing what the system was actually permitted to decide on the case in front of it, on the day it decided.
The insurance evaluation tool, because the questions become the compliance object. The NAIC AI Systems Evaluation Tool pilot has run since March 2026 across twelve states, with pilot states meeting monthly, and it closes this month. The tool is to be updated on pilot feedback through September and October, re-exposed for public review, and put forward for adoption at the Fall National Meeting in November 2026. An evaluation tool is the list of questions a regulator will ask about an AI system, and once adopted it becomes the shape carriers build their files to. A tool asking how a system was tested before deployment and monitored after gets one kind of file. A tool asking what authority a system carried on a specific decision gets another. The window in which those questions can still change closes in the next two months.
The federal silence, and what fills it. A deferral does not pause deployment, and the vocabulary written during one tends to become the working description of due care by the time an instrument lands. The voluntary standards and industry frameworks being drafted right now, in the absence of the promised request for information, are the documents supervisors will read first when they finally write one.
All three pieces this week ended in the same place. A bound written in advance is a statement about a class, and an action is a member of a class only in retrospect. What a governor adds is a decision taken at the moment the action is about to run, against an envelope declared before the run and outside it, starting from withheld. It can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence coming before the outcome landed. No document written in advance can do that, and no review step added afterward can do it either.
Thirty minutes. Architecture, not sales.
A conversation about which of your declared bounds are asserted in a policy and which are held by something standing in the action path, and what your agent stack does with an action it cannot assess in time.
JonathanLuethke@WayfinderSystemsGroup.com
