← All articles

June 22, 2026

Training Time Is Too Early

Why the controls that ship before an agent runs cannot govern the decisions it makes once it does.

By Jonathan Luethke

Most AI governance acts before the agent runs. Alignment. Red-team evaluation. Guardrail tuning. The review that clears the build. All of it calibrated against a model frozen at release, against inputs the live run will not resemble.

Training time sets the model's disposition. Inference time is where the decision happens. A control fixed at the first does not bind the second.

Two places a control can stand.

A governance control acts at one of two moments. Before deployment, while the model is being shaped. Or in the decision path, while the model is acting.

Training-time controls are everything that happens before the model carries traffic. Alignment. Fine-tuning. Evaluation suites. Guardrail thresholds. The sign-off that clears the build. They shape what the model tends to do.

Inference-time controls act when a specific request arrives. They read the actual decision, score it against the policy in force, and intervene before the next step fires. They govern what the model is doing right now.

What ships today stands at training time.

SR 26-2 took effect on April 17, 2026 and placed generative and agentic AI outside its scope, pointing institutions back at their own risk practices. Those practices were written around a model you validate once and monitor on a cycle. The validation happens before the model carries a single live decision.

The vendor layer mirrors that shape. The governance features shipping this spring concentrate on the moments around deployment. Pre-release evaluation. Static guardrail configuration. Observability that records calls after they complete. Each one is useful. Each one stands either before the decision or after it. None of them stands inside it.

The agent moves after the control is set.

A static model scores an input and returns a number. The behavior you evaluated at release is the behavior you get in production, because nothing between the two changed.

An agent does not hold still. It assembles context the release never saw, calls a tool, reads the result, and chooses its next step on what came back. The disposition fixed at training time still exists. It no longer decides the outcome on its own.

This is why a clean pre-deployment evaluation does not transfer. You certified the model against a battery of inputs. The run composed an input that was not in the battery, then acted on a tool result that did not exist when you certified. The control that passed the model is reading a snapshot the decision already moved past.

What the control has to do at inference.

A control that governs the live decision has to sit in the path and do five things in order. Observe the decision as it forms. Assess it against the policy in force. Modulate the behavior when it drifts toward the edge. Enforce the boundary when it crosses. Sign the record of what happened. All of it before the next inference fires.

The standing objection to in-path control is latency. A governor every decision waits on is a governor in the critical path. We built the runtime and measured it. The cost of standing in the path is real and it is small. The cost of standing outside it is a decision no control ever read.

The control has to stand where the decision is made, not where the model was built.

What the examiner reads.

The insurance market is building this question into its examinations. A standardized evaluation tool for insurer AI governance is in a multistate pilot running through September 2026, with a decision on wider adoption due at the fall national meeting. An examiner working from a structured tool does not grade the model in the abstract. The examiner pulls one decision that affected a policyholder and asks what governed it.

A training-time record answers a different question. It shows the model was sound when it shipped. It does not show what the control did when the agent denied this claim, on this day, on the tool results in front of it. The decision is what gets examined.

Training time is too early. The decision happens later, and the control has to be there when it does.

What we are building.

Wayfinder Systems Group builds the control that stands in the decision path. It observes every decision, assesses it against the policy in force, modulates and enforces when the agent drifts past the boundary, and signs the record onto a tamper-evident chain at the moment it happens. It does not retrain the model or redesign the autonomy stack. It sits above control and below intelligence, and it acts when the decision does. Patents held in The Wayfinder Trust. We call her Velma.

Next step

Thirty minutes. Architecture, not sales.

A conversation about which of your AI controls act before the agent runs, which act inside the decision, and where the gap between the two sits in your stack.

JonathanLuethke@WayfinderSystemsGroup.com