Three pieces this week on the same defect in three places. A governor's grant leaves as a number, and a number does not describe itself. What makes it mean anything was settled somewhere upstream, by somebody else, usually without being written down.
The governor is exact on the object it is handed, and it has no way to know it was handed the wrong one.
This week.
What Counts as One Action (September 7). A governor sets how much authority the next action carries, per action, at runtime. Before it can do that, something has to decide what one action is, and that decision is made upstream, before the run, usually by whoever wrote the integration. One tool call. One transaction. One containment step against one host across one window. One maneuver segment. Nothing in the governor establishes that boundary. It reads the declared envelope, assesses divergence, sets the grant, and enforces it on the object presented to it. A bound is a number and a unit. The envelope states the number and the integration supplies the unit, so two builds can load the same envelope file, enforce it correctly, and govern two different systems. Envelope bounds fall into families that answer different questions. Reach asks how far one action extends across targets, hosts, tenants, accounts, or rows. Rate asks how many actions occur per interval. Magnitude asks how much each one moves. Feed a measured quantity into the wrong family and the bound is enforced correctly and means nothing correct. An action that quarantines one host covers every event on that host, and the reach bound was satisfied once. Map one governed action onto each arriving event instead and a rate bound refuses nearly all of them, on a stream whose arrival rate is a property of the sensor rather than of the risk. The failure is quiet because both readings are arithmetically clean, and the shortfall presents as a discovered property of the domain rather than as a bug. There is a tell. A real ceiling scales with the consequence of the action, the confidence available at decision time, or the reach of the effect. A manufactured one scales with the arrival rate of the input. If ingesting the same telemetry at twice the sampling frequency halves the automated share while nothing about the hazard changed, the ceiling is describing the instrument.
Which Way the Number Points (September 9). The grant leaves the governor as a number on a bounded scale, and a number crossing a boundary carries no direction with it. There are two natural ways to put authority on a scale from zero to one and both are in use, often inside the same deployment. Authority granted, where one is a full grant and zero is a blocked action, which is the sense the enforcement point needs. Constraint applied, where one is a freeze and zero is unconstrained, which is the sense a risk surface wants. They cover the same interval and run in opposite directions. Granted plus applied is one, and neither is self-describing. A misread unit announces itself, because seconds fed into a field expecting milliseconds is absurd by three orders of magnitude. A misread direction produces nothing absurd. Every value stays inside zero and one, every chart renders, every export validates, and the reading is wrong by exactly the amount that matters and by nothing that shows. The worst case is the one most likely to survive review. The governor withheld authority entirely and emits zero, a surface built on the other convention reads that zero as zero constraint applied, and the most restrictive verdict the governor can reach renders as the most permissive state the page can show. What makes it survivable is that enforcement does not read the display. The grant is applied at the enforcement point standing between the proposed action and the actuator, and an inverted dashboard does not widen a grant or admit an action the envelope refused. The run was governed correctly and the picture of the run was wrong. The fix is to name both quantities and carry both, convert in exactly one place, and assert that granted plus applied equals one on every record rather than trusting a reviewer to catch a direction.
Both Tests Look Backward(September 11). On September 4 the first comment deadline passed in Colorado's rulemaking on automated decision-making technology. One of the open questions in the notice is how to tell whether an automated system materially influenced a decision, and the Attorney General put two candidate standards in front of the public and asked which to adopt. The first puts an output outside the Act only when its effect on the outcome was trivial. The second lets it fall outside when independent information played a substantially larger role. Both ask what the decision would have been without the output, and nobody ran that decision. There is one file, one outcome, and one person who had already read the score before forming a view. A counterfactual can be estimated across a population and it cannot be read off a single case, and the obligation attaches to the case. The agreement evidence is the weaker half, because a reviewer who agrees with the system almost every time may be deferring to it or may be right almost every time about a population where the system is also right. A governor inverts the measurement problem. Colorado is asking how to recover a share from an outcome, and a governor does not recover the share because it wrote it, and what fell outside the grant never reached the actuator to influence anything. The piece also took the label problem to its end. If one outcome token covers both a restricted grant that nobody was asked about and a decision floored to a person by policy, a compliance crosswalk downstream reads the first as evidence of the second, and the report asserts oversight that nobody performed. Nothing in it is fabricated. The token meant two things and the counter picked one.
What changed.
The Colorado calendar moves next. Comments received by September 4 are the ones the Department of Law weighs in the revised draft it circulates no later than September 23, and the full written window runs to October 26, when the rulemaking hearing is held. SB 26-189 and the Chatbot Safety Act both take effect January 1, 2027. The materially-influence test is the part to read when the revised draft lands, because that phrase decides who is inside the Act and the statute left it to the rules.
The larger shift this week is not a rule at all. The IETF is standing up a working group on auditing autonomous agents, proposed as Agent Use of Delegation and Interaction Traceability, with charter text circulating for feedback and the architecture draft behind it revised on September 7, 2026. The architecture treats authorization as a state that evolves over time, reconstructed from an ordered sequence of transition records, with delegation records carrying delegator, delegatee, scope and constraints, and action records captured at the boundaries where effects occur. Proposed deliverables include record data models, Standards Track extensions to existing protocols to carry audit information, and deployment guidance.
That is a different instrument from a statute and it moves differently. A rule creates a duty and leaves the mechanism open. A standard creates a default, and a default that ships in the protocol stack is what everything downstream ends up speaking whether or not anyone chose it. Two things in the architecture are located correctly. Authorization belongs on a timeline rather than fixed once before the run, and the record of an action belongs at the boundary where the effect occurs rather than in an application log beside it.
Where it stops is what the week's three pieces were about. An audit architecture describes what is recorded about an action. It does not decide the action. Reconstructing the authorization state in force at a past moment and setting the authority of the next action are two jobs at two different times, and only one of them has to finish before the actuator moves. A record format also fixes vocabulary, and that is where the label problem becomes durable. A token adopted as an interoperable default is the token every downstream counter reads, and the moment to separate a restricted grant from a decision handed to a person is while the data model is still in draft.
The rest of the calendar is dense. California SB 947, the No Robo Bosses Act of 2026, approved August 31 by 53 to 14 in the Assembly and 28 to 10 in the Senate, remains unsigned with the Governor's window closing September 30 and an operative date of July 1, 2027. The NAIC released version 5.0 of what it has renamed the AI Risk Evaluation Supplement on August 31, the first version issued under that name rather than as the AI Systems Evaluation Tool, with comments due September 29 and adoption sought at the Fall National Meeting in November 2026. The rename says what it is, a supplement to existing market conduct and financial examination procedures rather than a freestanding AI examination regime. SR 26-2 has been in effect since April 17 with generative and agentic AI outside its scope, and the interagency request for information it promised has not issued nearly five months later.
What we are tracking.
The revised Colorado draft, due on or before September 23. Whether the materially-influence test survives in a backward-looking form is the single most consequential line in it. A test that asks what the outcome would have been otherwise puts every deployer in the position of reconstructing a decision that was never run, out of a file that records one outcome. A test that asks what the system was permitted to decide is answerable from something a deployer can hold.
The standards track, and the words it settles. The record format question is upstream of every count a regulator will eventually read, and the vocabulary gets fixed earlier than the numbers do. A data model that gives one name to a restricted grant and to a decision floored to a person will produce human oversight statistics that nobody fabricated and nobody can defend. The window in which that is a drafting comment rather than a migration closes while the charter is still being discussed.
The two closing windows. SB 947 by September 30 and the insurance supplement by September 29, both inside the next three weeks, and both asking a deploying organization to describe its governance rather than to demonstrate what held at the moment of an action. An evaluation supplement becomes the shape carriers build their files to, and a statute becomes the shape employers build their workflows to. Neither shape includes the instant between the output and the effect.
All three pieces this week land in the same place. The governor decides one thing, whether the next action carries authority, and the magnitude of what it grants is a separate value it writes before the action rather than a share anyone recovers afterward. Unit, direction and label are the three facts that make that value readable, and every one of them is declared outside the governor by somebody who may never state it. A governor can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence coming before the outcome landed. That grant is the one most likely to be argued with, and it is unreadable to anyone holding the wrong unit, the wrong direction, or the wrong word for it.
Thirty minutes. Architecture, not sales.
A conversation about what one governed action is in your deployment, which quantity your governance surfaces are actually showing, and what your human review count is evidence of.
JonathanLuethke@WayfinderSystemsGroup.com
