The best AI governance control I ever shipped was also the least clever one I had. A person had to read what the model wrote before it reached a client record. There was no scoring threshold, no confidence band, no policy engine evaluating whether this particular output looked risky enough to warrant attention. A human being read the text, and until that happened the write did not land.

I have been thinking about that control again this week, reading the argument that AI governance is moving from observability to provable control. The claim is that knowing what an agent did is no longer sufficient, and that enterprises now have to demonstrate what the agent was authorized to do and whether that authority held as the work moved across systems. The line that stayed with me was that when an agent hands work to another agent, the authority should shrink and not leak.

The problem is old and the tempo is new

Here is where I keep landing. That problem did not arrive with agents, and I do not think we do ourselves any favors pretending it did. Anyone who has run enterprise integration for any length of time has already met it in a dozen forms: the batch job running under a service account with broader rights than any human in the chain, the downstream system that trusts the caller because the caller is internal, the entitlement model that was correct at the point of entry and close to meaningless three hops later. We have been leaking authority across boundaries for twenty years, and we have mostly been fine, which is a different thing from being correct.

What agents changed is the tempo. The leak used to happen once a night, on a schedule somebody owned, into a window somebody watched, with a morning after in which a person could look at what had happened and decide whether it mattered. Now it happens continuously, and the slack that let us live with the structural problem is gone. The design flaw is identical. The margin for absorbing it is what disappeared.

I want to be precise about why that distinction matters, because it changes what you should go build. If the problem were genuinely new, the right move would be new governance primitives invented for agents specifically, and a great deal of current attention assumes exactly that. If the problem is old and the tempo is new, the right move is to take the authority model you already have, the one that was always approximately right and never enforced continuously, and make it enforceable at the speed the work now moves. Those are not the same project, and the second one is less exciting to fund and considerably more likely to hold.

The part of my own experience that maps onto this most closely was not AI work at all. When we brought our platform under continuous SaaS posture management, the entire point was to make configuration and access posture visible and enforceable rather than something we audited periodically and hoped had not drifted since the last look. The interesting property was not the coverage. It was that the check ran continuously and was not something anyone had to remember to do. Same distinction, years before anyone was calling it AI governance.

In the path, or beside it

That is also why the advisor review held. It was never clever and it did not need to be. It sat in the execution path and could not be routed around, which is a property you can demonstrate to an auditor rather than describe to one.

The difference between demonstrating and describing is the whole argument, so it is worth slowing down on. When a control sits in the path, you do not have to argue that it was followed, because the work does not complete without it. You remove the reviewer and nothing reaches the client record. You can show that by trying, in front of someone, and the system will refuse you. The claim being made is not a claim about anyone's diligence or anyone's memory or anyone's training, and it therefore does not degrade under pressure, turnover or a bad quarter. It is a claim about structure, and structure is checkable.

A policy is a different kind of object. A policy says that outputs of this type are reviewed before they reach client records, and the accurate version of that statement is always longer: outputs of this type are reviewed when the person handling them is following the process, and there is no path by which they reach the record otherwise that anybody has found yet. The second clause is doing enormous work and is never written down. An auditor reading the policy is being asked to accept a description of intended behavior as evidence of actual behavior, and the honest reason we let that pass for years is that nobody had a cheaper option.

So the taxonomy I now use is simple. Governance you can prove sits in the execution path. Governance you can observe sits beside it. Everything beside the path is telemetry, and telemetry is what you read after the thing you were worried about has already happened. That is not an argument against telemetry. I want the logs and I want the traces and I want to be able to reconstruct what an agent did at three in the morning six weeks ago. But I have watched organizations build excellent observability and then describe it as control, and those are different claims with different failure modes, and conflating them is how you end up surprised.

The test I would apply to any agent governance investment is narrow. Can you remove the control and have the work still complete? If yes, you have telemetry, and you should be honest with yourself about that and value it accordingly. If no, you have a control, and you can prove it by demonstration rather than narration.

The part I have not solved

Which leaves me with the honest problem, and I would rather state it than finesse it.

A human in the path does not survive agent-to-agent volume. The advisor review was the right control for one capability with a defined blast radius and a rate of work a person could actually absorb. It will not hold for a hundred capabilities running against each other, handing work sideways, each handoff a place where authority should narrow and currently does not. The property that made the control trustworthy, that a person had to look, is the same property that makes it impossible to multiply.

I do not have the replacement. I have a specification for it, which is not the same thing: whatever sits in the path instead of the person has to be in the path, has to be unroutable, and has to narrow the authority it passes forward rather than forwarding what it received. Those three properties are what the advisor review had, and a control that keeps all three without requiring a human to read every output is the thing the field is actually short of.

What I would push back on is the suggestion that this is a tooling gap waiting on a vendor. The reason authority leaks across boundaries in most enterprises is not that nobody sold us an enforcement layer. It is that the authority model was never written down precisely enough to enforce, because nobody had to be precise while the tempo was slow enough to catch the mistakes by hand. That work is ours, it is unglamorous, and it is upstream of every tool anyone will sell us. The tempo took away our ability to defer it, which is the one genuinely new thing about this moment.