Two governance questions, both necessary
Model governance asks important questions about approved providers, evaluation, security, privacy, bias, reliability, and intended use. Work-loop governance starts one level closer to operations. It asks: what customer or organizational need started this work, how was it interpreted, what specification was accepted, what context did the agent receive, who authorized execution, what proof returned, and what did the organization learn after the result?
The agent may be intelligent and still be wrong about the work
Agents do more than automate keystrokes. They can infer, plan, compare approaches, generate implementation, and revise from feedback. That intelligence increases their value and the importance of context. An agent can reason impressively from an incomplete premise. It can produce a coherent solution to a customer need the organization misunderstood before the agent ever began.
Human sensemaking is therefore not a polite review added after execution. It shapes what the system is trying to accomplish. Customers interpret their own experience. Product owners make tradeoffs. Teams contribute technical and operational judgment. Leaders decide which risks and outcomes matter. Agents can strengthen these loops when their work remains connected to those interpretations.
Four common forms of drift
| Drift | What changes unnoticed | Control that helps |
|---|---|---|
| Customer drift | A lived concern becomes a technical shorthand that solves a different problem | Keep source story and storyteller interpretation attached to the accepted spec |
| Context drift | The agent uses stale, excessive, or contradictory material | Versioned context snapshot with provenance, scope, expiry, and exclusions |
| Spec drift | A plausible draft is treated as accepted intent or execution targets a superseded version | Distinct proposed and accepted states, version pinning, and stale-approval checks |
| Proof drift | Tests pass while the intended outcome or an important limitation remains unverified | Proof profile, independent QA, human acceptance, and outcome review |
Design a loop of loops
- The sensemaking loop gathers customer and team experience, interprets patterns, and frames what deserves attention.
- The definition loop turns that meaning into a proposed and then accepted specification.
- The execution loop turns the accepted spec into an approved plan and bounded agent action.
- The verification loop tests the result, records limits, and returns decisions to humans.
- The learning loop compares the delivered result with customer, process, delivery, and leadership outcomes.
These loops are not a waterfall. New evidence can return a plan to definition. QA can expose a missing customer condition. An outcome review can change a governance profile. The point is not linear compliance. It is preserving the relationships that let people correct course before speed turns a small misunderstanding into a large consequence.
What leaders should ask to see
- The human need and evidence that began the work.
- The accepted specification and who accepted it.
- The context snapshot, provider, profile, and plan used by the agent.
- The approvals, exceptions, connector calls, cost, and stop decisions.
- Independent proof, known limitations, and the person who accepted the outcome.
- The later evidence that shows whether the intended experience or result changed.
Key terms
- Model governance
- Controls over AI systems and providers, including approval, evaluation, security, privacy, reliability, and intended use.
- Work-loop governance
- Controls that keep meaning, decisions, context, agent action, proof, and learning connected within actual work.
- Drift
- A material change in meaning, context, specification, or proof that occurs without an explicit decision.
Sources and standards context
- NIST AI Risk Management Framework CoreNIST describes governance as a continuous, cross-cutting function and calls for documented human oversight, roles, testing, and accountability across the AI lifecycle.
- ISO/IEC 42001:2023 AI management systemsISO describes an organization-wide management system for policies, objectives, processes, risk, transparency, and continual improvement in the responsible use of AI.
