A governor sets how much authority the next action carries. It sets that at one instant, on what it can read at that instant. The action then takes time to complete. Everything that happens between the grant and the effect is covered by a reading that is already behind.
An action is not a point.
Per-action governance carries an assumption that usually goes unstated. The action is treated as an event with no width, decided at one moment and finished at the same moment. Some actions are close enough to that. A message emitted. An authorization returned. A single write to a row.
Many are not. A funds transfer settles across an interval. A batch job runs against a remote system for minutes. A physical maneuver holds continuous actuation for seconds. An agent tool call opens a connection, negotiates, waits, and returns when it returns.
For those, the grant is issued at one time and the effect lands at another. What the governor asserted was that this action sat inside the declared envelope. The assertion leaves open when it was true. At the instant of the grant, or across the whole interval the action occupies.
The forward look has a horizon.
A governor can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence coming before the outcome landed. That result is the reason to put a governor in the path at all, and it is a forecast. A forecast reaches a certain distance ahead and no further.
The horizon of the forward look and the duration of the action are the same quantity. A forecast that reaches one second, applied to an action that runs for ten, covers the first second. The remaining nine are covered by nothing the governor produced. The grant stays in force across all ten, because a grant does not know how long the thing it granted takes.
Forecast quality also falls with horizon. That is a property of forecasting rather than a defect in any one implementation. The cost of a long action gets paid twice. The interval is longer, and the estimate covering it is worse.
Closing the interval.
Three moves close it. They are not interchangeable.
Shorten the action. Decompose it into steps short enough that each one gets its own assessment and its own grant, so the exposed interval never exceeds a single step. This requires the action to be decomposable, and a settlement or a maneuver often is not.
Shorten the grant. Attach an expiry and let authority lapse while the action is still running. This requires the enforcement point to be able to take authority back from work already in progress, which is a capability most integrations do not have.
Widen the margin. Grant less than the forward look would support, so that drift accumulated over the interval still lands inside the envelope. This asks nothing of the actuator. It costs capability on every action, including the ones that would have been fine.
Only the third is always available. Which of the first two is available is a property of the system being governed, not of the governor.
Withdrawal is a different operation from refusal.
Refusal happens before the action starts and leaves nothing behind. Withdrawal happens to an action already underway and leaves a partial effect that something has to own. Half a settlement. A maneuver stopped mid-arc. A batch that wrote some of its rows.
An enforcement point built to refuse has exactly one moment of leverage, the moment before the action starts. Attaching an expiry to a grant does not manufacture a second one. It produces a note that the first moment has passed, and a note is not a control.
An action that cannot be stopped once it starts has to be granted on a forward look that covers its whole length, or not granted. No third option is honest. The grant is a claim about an interval, and when the governor cannot reach the end of that interval, the claim covers less ground than the action does.
What the operator has to declare.
The envelope carries bounds. It also has to carry, for each class of action, how long that class runs and whether authority can be taken back once it has started. Those are facts about the plant and about the integration. The model has no view on either, and neither does the governor until someone writes them down.
Failsafe direction follows the same rule that governs an uncertain forward look. An action class with no stated duration is treated as the longest the envelope admits. An action class with no stated interruptibility is treated as uninterruptible. Both round toward a smaller grant.
The resulting check is structural and settled at build time. For each action the governor can grant, name the maximum interval between the grant and the effect, and name whether the enforcement point can act inside that interval. Two answers per action class, both fixed before the run, both readable by someone who did not build the system.
Where the regulators are.
SR 26-2 took effect on April 17, 2026 and placed generative and agentic AI outside its scope, with the interagency request for information still pending. EU AI Act high-risk obligations, Article 9 risk management among them, fall on December 2, 2027 for standalone systems and August 2, 2028 for AI embedded as a safety component. Article 9 asks for a risk management system that runs continuously across the lifecycle, and continuous is a statement about intervals rather than about instants.
The NAIC Model Bulletin has been adopted in more than half the states, and the NAIC AI Systems Evaluation Tool pilot runs through September 2026 across twelve states, giving market conduct examiners a structured frame for insurer AI governance. What each of these instruments asks about is the decision. Whether it was authorized, whether it was reviewed, whether it was monitored after.
None of them asks how long the authorization was good for. Every deployment already answers that question, written implicitly by whoever chose where the enforcement point sits and what it is able to do once an action is moving.
What we are building.
Wayfinder Systems Group builds a runtime governor. It sits above control and below intelligence. It observes the run, assesses how far realized behavior has moved from the assured trajectory, modulates the authority of the next action against a declared envelope, and enforces that grant on the only path to the actuator. It does not retrain the model or redesign the autonomy stack. The grant it issues carries a stated interval, and the enforcement point is built to hold the bound for the length of that interval rather than for the instant the reading was taken. We call her Velma.
Thirty minutes. Architecture, not sales.
A conversation about how long your grants stay in force, which of your action classes can be interrupted once they start, and where the enforcement point has to sit for a grant to cover the whole interval it authorizes.
JonathanLuethke@WayfinderSystemsGroup.com
