Most AI governance watches the action. The agent decides, and a control reads the decision against the policy in force. There is a second moment, and almost no control watches it. The moment the model is permitted to change.
A learning event is not a decision. It is the model rewriting the function that produces decisions. Govern the action after the change and you are governing an instrument that already moved.
Two events. One of them governed.
A decision event is bounded. One input arrives, one output leaves, and the pair can be logged. The work of the last month has been about recording that pair as a trajectory rather than a single line.
A learning event is a different object. A weight update, a fine-tune, an adaptation the run carries forward. It does not affect one decision. It resets the disposition behind every decision that follows it.
Runtime governance shipping today reads the decision. It scores the action, allows or blocks it, and writes a log. The update that changed the model between yesterday's decision and today's passes underneath that layer, unread. The control is watching the output of a function while the function is being rewritten.
The one regime that names the change.
There is a regulatory framework built around the moment a model changes. The FDA's Predetermined Change Control Plan, finalized in August 2025, lets a manufacturer pre-authorize a class of modifications to an AI-enabled device without filing a new submission for each one. It has three parts. A description of the modifications. A protocol for developing and validating them. An assessment of their impact.
The PCCP is the envelope. It states, before the device ships, which updates are inside the line and which are outside it.
A plan is not a record. The PCCP describes the modifications a manufacturer may make. It does not, by itself, capture which modification the model actually made, on which day, against which version of the envelope, and whether the change that committed stayed inside the bound. The authorization is filed once. The runtime evidence of what the authorization admitted is a separate artifact, and it is the one almost no one is producing.
The banks inherit the same gap, without the envelope.
SR 26-2 took effect on April 17, 2026, replacing SR 11-7. It placed generative and agentic AI outside its scope and pointed institutions back at their own risk practices. A separate request for information on AI, agentic AI included, is still forthcoming.
Those practices were written for a model that is validated once and then holds still. They have no equivalent of a change control plan, because the model they were built for did not change in production. An adaptive model has no filed envelope and no admission record. The update happens, and the only trace is a retrain log that was never designed to be read by an examiner.
This is the failure mode of the companion piece to this one. When the model that made a decision has been overwritten by a later update, there is nothing to freeze and replay. The reconstruction window closes at the moment of the change, and the change left no receipt.
What the admission gate has to record.
A control that governs the learning event sits before the update commits, not after. It admits the change, refuses it, or admits it under a constraint, and it records the decision. Six fields are what the record has to contain.
The state of the model before the change. The trigger that proposed it, the drift signal or the new labels or the operator request. The bound it was tested against, the authorized envelope in force at that moment. The verdict, admitted or refused or constrained. The state after. The signature linking this entry to the one before it, so the sequence cannot be reordered or edited after the fact.
The gate has to record what it admitted, not only what the model did next. An examiner who asks what changed the model between the March decision and the June one should receive a chain, not a retrain log and an interview.
This is the same discipline the decision record already demands, applied to the second event. Pre-authorize the envelope. Admit or refuse each change against it at runtime. Sign the admission. Then govern the decisions the changed model goes on to make. Governing the decision while the model rewrites itself underneath is a receipt for a transaction whose terms moved after it was signed.
What we are building.
Wayfinder Systems Group builds the control that stands at both events. It governs the decision as it forms, and it governs the learning event before it commits, signing each admission onto a tamper-evident chain at the moment it happens. The artifact is produced automatically. The reviewer reads the exceptions. The examiner reads the chain. It does not retrain the model or redesign the autonomy stack. It sits above control and below intelligence. Patents held in The Wayfinder Trust. We call her Velma.
Thirty minutes. Architecture, not sales.
A conversation about which of your AI controls govern the decision, which govern the moment the model changes, and where the admission record should live in your organization.
JonathanLuethke@WayfinderSystemsGroup.com
