A remarkable convergence happened this year. Regulators published notes on agentic AI and data protection; consultancies built governance, risk, and control frameworks for agents; research journals proposed governance profiles for agentic systems. Different vocabularies, one conclusion: as agents gain authority, governance becomes the primary constraint. We think that conclusion is exactly right, and the work behind it — profiles, frameworks, regulatory groundwork — is the field doing what it should.
We reached the same conclusion from our own premise — governance owns the concerns, never the model — and giving agents authority only sharpens what that premise already implied: if concerns must stay owned and disposed of by governance, then as the pace of action rises, governance has to keep pace with it.
It also opens a question that the whole field, ourselves included, now has to answer: governance how, at what tempo?
An old principle, newly urgent
Cybernetics settled one thing long ago: a regulator can only regulate what it can match. Ashby’s law of requisite variety says the controller must have at least as much variety as the disturbances it faces — and tempo is part of variety. Human institutions honored this law for human-tempo action: boards, reviews, audits, and policies are regulation instruments matched to actors who decide at the speed of meetings.
Agents change the tempo, not the principle. An agent fleet acts, redeploys, and compounds decisions at machine speed; instruments that evaluate quarterly now face disturbances that arrive per second. This is not a criticism of any framework — it is a structural fact every governance approach must now reckon with, and the most interesting current work is, one way or another, a response to it.
Our response condenses to one sentence: governance must run at the tempo of the governed — which for agentic organizations means governance must execute.
Four commitments we arrived at
When we tried to honor that sentence in a working stack, four design commitments emerged. We offer them as findings — each is implemented, so each is checkable.
- Obligations as evaluable definitions. For governance to execute, the obligation itself must be machine-evaluable — not a translation of a policy, the policy. In GSM a Directive opens the governance scope and Norms operationalize it as measurable assertions, so nothing is lost between the intent and the check.
- Verdicts that are deterministic and reproducible. If a verdict cannot be replayed, delegation cannot be defended. The Operator evaluates Norms in a sandboxed runtime with no ambient authority: the same definitions and inputs always yield the same verdict.
- Execution rights as governed facts. What an agent may trigger should itself be a versioned, approved statement in the model — only lifecycle-activated definitions run, and only where the model wires them — rather than a property of some server’s configuration.
- Concerns owned by humans. Speed changes who checks, not who answers. Concerns remain owned by stakeholders and carried by governance — the position we hold across the stack — with deterministic disposition where the matter is decidable and human disposition where accountability requires it.
A distinction that helped us
Working on this, we found it clarifying to separate two problems that share the name. Conduct is what an agent may do, step by step, inside a process — in our stack the province of the agentic harness, which checks and journals every step from persisted state. Consequence is what the systems agents act on must remain true, whatever touched them — the province of the governed model, evaluated continuously. The two need different instruments at different tempos; they stay coherent when both draw on the same governed definitions.
Model governance — cards, capability evaluations, conformance — is a third, complementary layer: it governs the model as an artifact. Conduct and consequence govern actions in your systems, and our experience is that this is where agentic governance is ultimately decided.
The optimistic reading
“Governance becomes the primary constraint” can sound like the agentic era hitting a wall. We read it the other way. Authority can be delegated exactly as far as it can be checked — that has always been true of human delegation too. So every increment of governance that executes at agent tempo is an increment of autonomy that can be responsibly granted. The constraint, honored well, is the license.