A governor sets how much authority the next action carries. It does that by applying a bound it did not write to a number it did not produce. Ask how accurate it is and the question has landed on a different component.
Two things stand in front of a governed action. One estimates. The other bounds.
They are usually sold as one product and evaluated as one number, and the number that gets quoted belongs to the estimator.
Two kinds of wrong.
A detector makes a claim about the world. This traffic is an intrusion. This actuator command is out of family. This transaction does not resemble the account's history. A claim about the world can be false, so a detector has an error rate, and the error rate is the honest way to describe it.
A governor makes no claim about the world. It receives an estimate, it reads a bound that was declared before the run, and it sets the authority of the action in front of it. Whether it did that correctly is answerable by inspection. Was it on the path the action had to take. Did it produce a grant before the action ran rather than a verdict after. Given the estimate and the bound it was handed, did it grant the amount the rule specifies.
Those are different kinds of question. The first is statistical and has to be measured on data nobody has all of. The second is structural and is settled by reading the construction. A detector is scored. A governor is checked.
The number that gets quoted.
When a governance product is asked how accurate it is, the figure that comes back is a detection figure. It was measured on a corpus. It describes how well one estimator separated one kind of abnormal from one kind of normal, in one domain, at one operating point.
That figure is real and it is worth having. It also does not travel the way the procurement conversation implies. An estimator fit on a process plant's normal operation says nothing about a payments queue. An estimator trained on the failure classes someone had labels for degrades on the classes nobody had labels for yet, which is the open-set case, and the open-set case is the one that arrives in production. The closed-set figure is the one that gets quoted, because it is the one that was measured.
So a buyer comparing accuracy figures across governance vendors is comparing detectors and calling it a comparison of governors. The properties that decide whether the bound actually holds do not appear in that number anywhere.
What the governor does not know.
The governor does not know what a process plant is. A payment, an intrusion, a grip force, and a flow rate arrive at it in the same shape. A scalar estimate of how far realized behavior sits from what the system was assured to do, and a declared envelope holding limits the governor did not write.
That ignorance is deliberate, and it is what makes the component portable. The same governor stands in front of an aircraft's control surface, a robot arm's grip, and a plant's valve. What differs between those deployments is the declared envelope and the estimator feeding it. The logic that turns an estimate into an authority grant does not differ, because there is nothing domain-specific inside it to differ.
Which is the same reason it carries no accuracy figure. A component with no model of the domain cannot be wrong about the domain. It can only be wrong about the rule, and the rule is short enough to read in full.
The grant is not the estimate.
The two components stay separate at runtime, and the plainest evidence is that their outputs move independently. The estimate is a reading of the present. The grant is a decision about the next action, and the governor sets it on where behavior is heading rather than only on how clean the action looks right now.
So the governor can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence before the outcome landed. No detector produces that result. A detector reports the reading it has. Pulling authority back ahead of the reading is a control decision, and it belongs to the component that owns the bound.
That is also why the two cannot be collapsed into a single score. A number that is both the estimate and the grant is an estimate, and it will move the way estimates move. The authority an action carries has to be settable against something the run cannot argue with.
What is left to verify.
Dropping the accuracy question does not drop the burden of proof. It moves the burden onto questions with harder and cleaner answers.
Is the governor on the only path to the effect, or is it standing beside the log.
Does a grant exist before the action runs, and what does the action carry on the occasion when no grant arrives.
When the input is uncertain, does the governor grant less or more.
Can a grant it has already set be widened by the system it is governing.
Is the envelope it grades against declared outside the run, by the party accountable for the outcome.
Each of those is answered by reading the build. None of them is a percentage. All of them decide what happens on the day the thing goes wrong, which is the day the control was installed for.
There is an institutional wrinkle underneath this. Model risk practice is built to validate estimators, and it is good at that work. SR 26-2 took effect on April 17, 2026 as the revised interagency guidance on model risk management in United States banking, and it placed generative and agentic AI outside its scope while pointing institutions at their existing practice. Existing practice knows how to challenge a number a model produced. A control whose correctness is structural rather than statistical does not fit that template, and the mismatch surfaces as a validator asking a component for a performance figure it was never built to have.
What we are building.
Wayfinder Systems Group builds the runtime governor. It sits above the control system and below the intelligence that decides. On every action it reads how far realized behavior has diverged from what the system was assured to do, sets the authority that action carries against a safety envelope declared before the run, and enforces that grant on the path the action has to take to reach an effect. The domain lives in the envelope and in the estimator. The governor is the same component in every deployment, and it signs the decision it made. We call her Velma.
Thirty minutes. Architecture, not sales.
A conversation about which component in your agent stack is actually holding the bound, and what you would have to read to satisfy yourself that it holds.
JonathanLuethke@WayfinderSystemsGroup.com
