A safety case is a structured argument, supported by evidence, that a system is acceptably safe in a stated operating context. It is written before the system is fielded and reviewed by someone who did not build it. A governor standing in front of the actuator changes what that argument has to carry, because the subject of the argument stops being the system and becomes the control that sets the authority of each action.
The argument has a subject.
A safety case names a system, names the context it runs in, states the hazards, and argues that the design and the evidence together bring risk to a level someone is prepared to accept. The argument holds as long as its subject holds. Change the system and the argument describes a system that no longer exists.
That constraint was affordable when the subject was a fixed artifact. A control law is written, verified, frozen, and fielded. Ten years later it computes what it computed on the day the case was signed.
An adaptive system is a different subject. Its behavior in month nine is not the behavior the case examined in month zero, and that divergence is a property of the object rather than a defect in the review. Every material change reopens the argument. The interval between changes falls below the interval a re-argument takes, and the case runs permanently behind the system it describes.
Two claims of different size.
The claim a conventional case makes about an autonomous system is broad. This system will not leave its envelope. The subject of that claim is large, it moves, and the evidence behind it is a sample of behavior collected under conditions the evaluator chose. Nothing in the sample binds a run that has not happened yet.
A governor in the action path supports a narrower claim. No action carrying authority outside the declared envelope reaches the actuator. The subject of that claim is a control that sits in one place, adds no intelligence of its own, and does not learn. The size of the claim is the whole difference. One is a promise about a system that changes. The other is a property of a path, and a property of a path is established by inspecting the path.
The narrow claim does not cover less ground. It covers the same hazards through a smaller object.
What the governor makes arguable.
The governor sets, for each action, how much authority that action carries. It reads a bound declared before the run and outside it. It starts from withheld and grants only what it can assure. When its forward look reads a coming divergence between where the system is heading and what it was assured to do, it grants less. It can grant less on an action whose present trust reads higher, because the pullback is set on where the action is going rather than on how clean it looks right now.
Each of those is a statement about the governor. Each is answerable by inspection rather than by measurement. Is the enforcement point on the only path to a durable effect. What does an action carry when no grant arrives. Which direction does an uncertain forward look round. Can a grant already set be widened from inside the run.
Those four answers are fixed at build time. They do not move when the governed system learns. The case argues over them once and they stay argued.
What the case still owes.
A governor does not make the envelope right. Declaring the bound is a separate act with a separate owner, and the case still has to argue that the declared bound corresponds to the hazards it identified. A governor holding a wrong envelope holds it exactly.
Coverage is the second debt. The forward look reads particular channels, and a hazard that perturbs nothing the governor measures produces a clean reading and a full grant. Naming the measurement that carries evidence of each hazard belongs in the declared envelope beside the bounds, and a hazard with no measurement behind it is a stated gap that starts from a lower grant.
Placement is the third. A governor beside the actuator instead of in front of it returns the whole argument to a promise, since the agent retains a path to the effect that no grant crossed. That is a question about the build, and a reviewer who cannot trace the path has not seen the case.
Where the regulators are.
SR 26-2 took effect on April 17, 2026 and placed generative and agentic AI outside its scope, with the interagency request for information on both still pending. EU AI Act high-risk obligations, Article 9 risk management among them, fall on December 2, 2027 for standalone systems and August 2, 2028 for AI embedded as a safety component of a regulated product. The embedded date is the one that lands on functional safety practice, and the products it reaches already ship with an argument in a binder.
Article 9 asks for a risk management system that runs across the lifecycle, iterative and kept current. Read against a fixed artifact, that means periodic re-review. Read against a system that changes between reviews, the version that closes is the one where a control in the path holds the bound continuously and the periodic review examines the control.
The reviewer who has to accept the argument in 2028 is reading for the same thing either way. What was this action allowed to do, and what stopped it from doing more.
What we are building.
Wayfinder Systems Group builds a runtime governor. It sits above control and below intelligence. It observes the run, assesses how far realized behavior has moved from the assured trajectory, modulates the authority of the next action against a declared envelope, and enforces that grant on the only path to the actuator. It does not retrain the model or redesign the autonomy stack. Every grant it issues is signed onto a tamper-evident chain, which is the evidence the operational half of a safety case has to produce. We call her Velma.
Thirty minutes. Architecture, not sales.
A conversation about what a runtime governor lets a safety case claim, which parts of the argument stay with the system, and where the enforcement point has to sit for the claim to hold.
JonathanLuethke@WayfinderSystemsGroup.com
