Your CTO just sent you a governance framework for AI agents.

It covers autonomous systems — the kind that draft communications, run queries, route tickets, call APIs, and execute instructions without waiting for a human to approve every step. The document looks thorough. There are definitions, approval standards, and escalation paths.

The gap is not the policy.

The gap is that the policy assumes the organization has already built the controls needed to enforce it. Most have not.

Subscribe now

The Infrastructure Gap

Arcade.dev raised $60 million this week — with Morgan Stanley and Wipro as strategic investors — to build what governance frameworks quietly assume exists: authorization controls and audit trails for AI agents.

That matters because “AI governance” sounds like a policy problem. In practice, agentic AI quickly becomes an infrastructure problem. If an AI agent can act inside a production system, the useful questions are not abstract:

What is the agent allowed to do?

Who approved that authority?

Can the organization reconstruct what the agent actually did?

Can the agent’s permissions be limited before it acts, or only reviewed after something goes wrong?

Those are not questions a governance memo can answer by itself. They require systems: access controls, logging, approval workflows, permission boundaries, and vendor contracts that account for agent-initiated activity.

That is why the Arcade funding is a useful signal. Strategic investors do not put enterprise-scale money behind imaginary gaps. They bet on problems they are seeing in client deployments.

Lawyers Have Seen This Movie Before

This is not the first time organizations have confused a written policy with an operational control.

A harassment policy is not much of a defense if there is no training, no reporting channel, no record of enforcement, and no evidence anyone followed it. The policy shows intent. The controls show whether the intent meant anything.

That logic shows up in fraud prevention, data retention, cybersecurity, export compliance, and privacy programs. The written framework matters, but it is not self-executing. The question becomes concrete: did the organization build a system that could prevent, detect, or document the problem?

AI agent governance is walking into the same trap.

A policy that says “agents must operate within approved parameters” only matters if the parameters are technically enforceable. A policy that says “humans remain accountable” only matters if someone can identify which human approved the agent’s authority. A policy that says “agent activity must be auditable” only matters if the logs exist before litigation begins.

Otherwise, the governance framework is not a control. It is a document describing controls the company wishes it had.

What to Ask Before Legal Signs Off

  1. Authorization: What pre-approval controls exist before an agent acts?
    It is not enough to say the agent is “supervised.” The question is whether the system limits what the agent can do before it does it.

  2. Auditability: Can you reconstruct what the agent did and who approved it?
    If an agent modifies a record, sends a message, triggers a workflow, or queries sensitive data, the organization needs a record that survives the incident.

  3. Contract coverage: Do the vendor agreements address agent-initiated actions?

    Many existing contracts assume software responds to human instructions. Agentic systems blur that line. If the agent acts through an integration, calls a third-party system, or initiates a transaction, the contract needs to say who is responsible for that action.

These questions are not theoretical. They are the difference between a policy and a system.

The Point

The hard part of AI governance is no longer writing down what agents are allowed to do. The hard part is proving the organization had the controls to make that promise real.

A governance framework for AI agents without an authorization layer is the same mistake lawyers have seen in other compliance failures: the policy existed, but the enforcement infrastructure did not.

The AI policy is not the protection. The controls are.

Share

Go Deeper: Full briefing on AI Agentic Governance — recent developments, sourced: lawsnap.com/tracker/legal-intelligence/tag/ai-agentic-governance/