On the Seam: Working Drafts · August 2026
Governance Is the Capability Nobody Staffs
Everyone shipped the control plane. Nobody shipped the governor. Why governance — not model capability — is the binding constraint on enterprise agent adoption, and the seat almost no organization has staffed.
I've written my way to the edge of this conclusion three times now, from three different directions, and stopped just short each time. This is the piece where I stop stopping.
In "The Eighth R," I argued that the transformation question that actually matters lives above the technology stack — at Layer 8, the business, the people — where an organization decides what it wants to become. I ended by saying someone has to carry that answer across the seam between what the technology can do and what the business can legitimately let it do. I did not say who.
Writing about McKinsey's Rewired, I argued that a legacy software company becoming agentic needs a capability the playbook never supplies: platform governance, a function with the standing to challenge programs that are not on a credible path. I gave it one paragraph and moved on.
And underneath both sits my own research, which kept telling me the same thing in different words. What drives people to adopt an AI system is not how capable it is. It is whether they trust the conditions around it enough to stake their name on what it does.
Three roads, one destination. It is time to name the thing at the end of them. The capability that every enterprise deploying agents is missing — the one almost nobody is staffing — is governance. And the reason it goes unstaffed is that we are still filing it under the wrong heading.
Governance has been misfiled
For thirty years, governance meant the brake. It was what risk and legal did to you after the interesting work was finished: a review gate, a compliance checkbox, the tax you paid to ship. Useful, necessary, and universally understood as a cost center. Nobody staffs a cost center ahead of demand. You staff it grudgingly, late, and only enough to satisfy the auditor.
That filing was survivable for exactly as long as a human sat between the software and the consequence. When the AI only suggested and a person decided, the person was the governance. Their judgment was the review gate, applied at the moment of every decision. You did not need a dedicated capability for it, because it was diffused into every individual user and paid for invisibly inside their salaries.
Autonomy takes the person out of that spot. Remove them and the governance that used to live in their judgment does not vanish. It becomes something you have to build somewhere else, on purpose, or go without. This is the shift almost everyone is missing. Governance did not become more important under autonomy. It became relocated: from something a thousand humans did implicitly to something the organization has to do explicitly. Most organizations have not yet noticed the bill came due.
Governance is a capability, not a constraint
So here is the reframe, stated plainly. Under autonomy, governance is not a constraint. It is a capability, the same category of thing as engineering, or data, or design. A muscle the organization either has or does not, whose presence or absence decides what you are able to do, not merely how fast you are permitted to do it.
The distinction is not semantic, because you treat the two oppositely. A constraint is something you minimize: negotiate down, route around, satisfy as cheaply as possible. A capability is something you invest in ahead of need, because it cannot be conjured in the moment you finally require it. Every organization treating agent governance as a constraint is busy minimizing the exact thing it should be building. They are haggling down the capability that determines whether their agents ever reach production.
And absent it, they will not. Not because the technology fails — the technology increasingly works — but because an agent that cannot be governed cannot be trusted to act, and an agent that cannot be trusted to act stays in the pilot forever.
Look at the two curves. KPMG has enterprise agent deployment going from 11% in the first quarter of 2025 to 42% by the third [2]. Google's enterprise research this year found 97% of organizations exploring agentic AI and 49% describing their own capabilities as advanced or expert, against 36% with a centralized approach to agent governance and 12% running any platform to control agent sprawl [3]. Half the market believes it is expert. A third has an approach.
That gap is not a compliance statistic. It is an adoption ceiling. Most enterprises are about to learn that the binding constraint on their agentic ambitions was never model capability. It was the governance capability they declined to build because they were still calling it overhead.
Why governance is the capability that gates autonomy
There is a reason governance specifically decides whether autonomy works, and it runs straight through my research.
When a system only advises, distrust is cheap: you check its work and move on. When a system acts on its own, distrust becomes the live and rational question of what it will do when no one is watching. That question is not answered by making the agent more capable. A more capable unwatched actor is more alarming, not less. It is answered by making the agent's authority bounded, its actions observable, its decisions reversible, and its verdicts owned by someone accountable. Every one of those is a governance property. Governance is not adjacent to trust under autonomy. It is the machinery by which an organization earns the confidence to let an agent act at all.
Which means governance does the one thing a cost center never does: it produces the precondition for value rather than subtracting from it. The audit trail is not for the auditor. It is what lets the operations lead sign off on running the agent unsupervised. The reversibility is not for the regulator. It is what makes the first failure survivable enough that a second attempt is allowed. Strip the governance out and you have not saved cost. You have removed the thing that made the agent adoptable.
Everyone shipped the control plane
You could object that nobody is ignoring agent governance. The opposite is true. It has been the dominant enterprise product story of the past year.
AWS has built Agent Core into a control plane for agents: a policy gateway, portable workload identity, an agent registry that classifies agents by risk, context snapshotting for audit. Its public sector arm publishes a governance framework organized around a scope-based model of agent autonomy [4]. Google spent Cloud Next positioning the Gemini Enterprise Agent Platform as a governance layer on four pillars — a unified agent registry for visibility, agent identity and gateways for access, a security framework and audit trails for compliance, operational oversight for the rest [5]. Anthropic ships Claude Enterprise with audit logs, role-based access, a compliance API, and authorization and observability controls for deployed agents [6]. Below the vendors, the Cloud Security Alliance is drafting agent standards on top of NIST [7], and ISO 42001 practitioners are writing supplementary controls for tool authorization and delegation-chain integrity, because the standard was never built for systems that act [8].
Look at what all of that is. Instrumentation. Registry, identity, policy gateway, audit trail, observability. Every one of these products supplies the apparatus of governance and not one supplies the governor. AWS will give you an immaculate audit trail. It will not give you the person who reads it and signs. Google will give you an agent registry. It will not give you the person with the standing to deny a registration when a product team wants it live by Friday.
That is not a knock on the vendors. You cannot buy a decision-maker as a managed service. But it explains how a company can spend heavily on agent governance and still not have any. The market has answered the tooling question three times over and has not answered the accountability question once.
Public policy is in roughly the same position. The frameworks everyone cites — the EU AI Act, whose broad provisions and penalty regime took effect this month even as its heaviest high-risk obligations were deferred to late 2027, NIST's AI RMF, ISO 42001 — were none of them designed for systems that act autonomously. They govern AI systems, and they are being retrofitted [8]. The one government instrument written specifically for agentic AI is Singapore's Model AI Governance Framework, released at Davos in January [9]. I do not think it is the last word, and its risk taxonomy is thinner than the EU's. But look where it lands. Of its four dimensions for governing agentic AI, the second is not a technical control. It is "make humans meaningfully accountable." A policy body reasoning from law rather than from adoption research arrived where I did. It also refuses agents any form of legal personhood, a live proposal in the academic literature, so that accountability has nowhere to escape to [1].
The verification community has the same shape of blind spot. There is real work being done on certification for agents, frameworks that assess one and return a graduated verdict on whether it is safe to deploy. The good ones are rigorous. But nearly all of them assume something they do not supply: a qualified person on the receiving end, with the authority to act on the verdict and the credibility to read it. The certificate presumes a recipient. In most organizations the recipient does not exist. We have gotten very good at producing verdicts and have not staffed the seat they are meant to be handed to.
The scholarship repeats it. A systematic review of agentic AI governance published this July surveys the field's whole cast of stakeholders: the OECD, the UN, regulators, policymakers, developers, deployers, researchers, end users [1]. It is a careful map of who governs agentic AI in the world. There is no corresponding map of who governs it inside a company. The literature has established that governance is somebody's job. It has not asked whose desk that job sits on.
Two ways I could be wrong
The first objection comes from the legal side, and it is a real argument. Under the principal-agent framing that dominates the field, heavy liability for a misbehaving agent sits upstream with the developer, the manufacturer of the thing [10]. If the vendor carries the risk, a rational CFO can ask why the deploying enterprise should staff a seat for exposure it does not own. Buy the indemnity, skip the headcount.
Liability and adoption are different problems, and only one of them is yours. Indemnification pays for harm after it happens. It does not produce the confidence to act before it happens. Even with a perfectly indemnified vendor, somebody in your building still has to decide to turn the agent loose on your customers. No contract makes that decision for them. And the harms that kill agent programs are rarely the compensable kind. They are the customer you cannot un-anger, the decision you cannot un-make, the internal credibility you cannot buy back. You can transfer the liability. You cannot transfer the signature.
The second objection is sharper, and partly right. One strand of work argues that governance can be built into the agent rather than staffed around it: design agents to follow the law directly and refuse illegal instructions even from their own principal [11], or appoint oversight agents, models supervising models, to police the workflow at runtime [12]. If the agent governs itself, the seat is redundant.
A great deal of what a governance function does today should be automated and will be. But this confuses enforcement with accountability. An oversight agent can apply a rule with more consistency and less fatigue than any human reviewer. It cannot own the consequence of the rule being wrong. Automate the checking. You cannot automate the signing. And notice what the proposal actually does: the oversight agent is itself an agent, with its own authority and its own failure modes, needing to be bounded and observed like any other. Who governs the governor? You have moved the seat up a level. You have not removed it.
A third difficulty I will concede without an answer. The field cannot agree on what an agent even is. One recent paper argues the term has been diluted past the point of usefulness, drawing the comparison to privacy scholarship's long stretch as a "concept in disarray" [13]. It is hard to write a job description for governing a category nobody can define. That is a real problem, and not a reason to wait. The agents are shipping under the ambiguous definition regardless.
What staffing it actually means
So what does it mean to fill that seat?
Not hiring a compliance officer, and not standing up a board that meets monthly to bless things after the fact. The seat is a specific and unusual combination: enough technical credibility to read a verification report and understand what a conditional verdict is telling you; enough authority to accept or reject a production deployment on the strength of that reading; and a standing mandate that does not evaporate the moment a product team is under pressure to ship. Technical depth, real decision rights, and durable independence, in one role. That combination is rare, which is precisely why the seat sits empty. It is hard to staff, and an organization that has not recognized governance as a capability has no reason to go looking for it.
The seat is the emblem of the whole thing. You can tell whether an organization has built the governance capability with a single question: when an agent's behavior is in doubt, who decides whether it ships? If the answer is a name — a person with the credibility to judge and the authority to act — the capability exists. If the answer is a shrug, a committee, or "legal, I think," it does not, and no framework, however rigorous, will save the deployment. The judgment has nowhere to land.
The capstone
This is the seam I have been circling from the start. The Eighth R found the gap between what the technology can do and what the business can decide. Rewired found the missing capability the playbook could not supply. My research found the mechanism: that trust in an acting system is built from the conditions around it, not the capability inside it. All three were pointing at the same empty seat.
The organizations that win the agentic transition will not be the ones with the most capable agents. They will be the ones that built the governance capability before they needed it, that treated it as a muscle to develop rather than a cost to minimize, and so had somewhere for the judgment to land when the moment came to let an agent act.
Someone has to carry it across the seam. Someone has to be there to sign. Build the seat.
That is the working draft of where my thinking is. Offered, not finished.
Sources
- Mubarak Raji and Masooda Bashir, "Towards Agentic AI Governance: A Preliminary Assessment," arXiv:2607.07612, July 2026. arxiv.org
- KPMG, "Agent Deployment Accelerates as Organizations Build Confidence Through Early Wins," AI Pulse Q3 2025. kpmg.com
- "Google made agentic AI governance a product. Enterprises still have to catch up," AI News, Google Cloud Next 2026 coverage. www.artificialintelligence-news.com
- Amazon Web Services, "A governance framework for building trustworthy agentic AI for public sector and regulated organizations," AWS Public Sector Blog. aws.amazon.com
- Google Cloud, "Govern your agents," Gemini Enterprise Agent Platform documentation. docs.cloud.google.com
- Anthropic, Claude Enterprise. www.anthropic.com
- Cloud Security Alliance, "Agentic AI Governance: NIST Standards for Autonomous Systems," March 2026. labs.cloudsecurityalliance.org
- "AI Governance Frameworks Compared: NIST vs ISO 42001 vs EU AI Act," NeuralTrust. neuraltrust.ai
- Infocomm Media Development Authority, Model AI Governance Framework for Agentic AI, Singapore, January 2026. www.imda.gov.sg
- Anat Lior, "AI Entities as AI Agents: Artificial Intelligence Liability and the AI Respondeat Superior Analogy," Mitchell Hamline Law Review 46, no. 5 (2020).
- Cullen O'Keefe et al., "Law-Following AI: Designing AI Agents to Obey Human Laws," Fordham Law Review 94, no. 1 (2025): 57–129.
- Iqbal Nasim, "Governance in Agentic Workflows: Leveraging LLMs as Oversight Agents," AAAI 2025 Workshop on AI Governance.
- Brinnae Bent, "The Term 'Agent' Has Been Diluted Beyond Utility and Requires Redefinition," Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society 8, no. 1 (2025): 403–413.
Dr. Trey Harper writes on trust, legitimacy, and the architecture of the agentic enterprise at treyharper.com and in the LinkedIn newsletter On the Seam: Working Drafts. The views expressed here are entirely my own and do not represent the policy or position of my employer or any customer.