When AI agents arrived, most enterprises responded the way enterprises respond to anything consequential. They formed a committee. An AI governance board, a cross functional working group, a framework, a policy document, a quarterly review cadence. Roles were assigned, a RACI chart was drawn, a charter was written. Everyone felt, correctly, that agents needed governance, and everyone reached for the tool they know: a deliberative body that meets, reviews, and decides.
This is the wrong tool, and not by a little. A governance committee, however well run, does not govern a single thing an agent does. It cannot, because governance as most enterprises practise it is a human paced deliberative process, and an agent is not a human paced thing. The committee that meets monthly to oversee AI is overseeing a world that produced tens of millions of ungoverned agent actions between its meetings. The governance exists. It just does not touch the actions, which is the only place governance was ever supposed to matter.
This piece is about why the committee model of governance fails for agents, what it is actually producing that misses the target, and what governance has to become to govern something that acts a thousand times a minute and does not wait for the room.
What Governance Has Always Been
To see why the committee fails, be precise about what governance has actually been, because the failure is not incompetence, it is a mismatch between a mechanism and its target.
Governance, in practice, is a deliberative process operating at human pace. Something governable comes up, a new vendor, a policy change, a system launch, a risky decision, and a body of people convenes, reviews it, weighs it, and decides. The decision is documented. Approval is granted or withheld. Periodically, an audit checks that things went as decided. This is the shape of governance everywhere, from corporate boards to change advisory boards to ethics committees, and it has worked for a long time.
It worked because of a property of the things being governed that nobody had to think about, because it was always true. The governable events were infrequent, and they could tolerate latency. A new vendor does not need approval in the next fifty milliseconds. A policy change can wait for the Tuesday meeting. A system launch is a scheduled event that the governance process is built into. The entire model assumes that the rate of governable events is low enough that a deliberative body can consider each one, and that each one can wait for deliberation without harm. Governance as a process is latency tolerant by design, because the things it governed were latency tolerant by nature.
That assumption, invisible because it was never violated, is exactly what agents violate.
Why Agents Break the Model
An agent produces governable events at a rate no deliberative process can approach, and it produces them continuously, and each one cannot wait.
Every action an agent takes is a governable event. Should it send this message, move this money, delete this record, share this data, call this system. These are precisely the questions a governance body exists to weigh, and an agent generates them not a few times a quarter but thousands of times a minute, every minute, forever. The rate of governable events did not increase incrementally. It went from a handful a quarter to millions a day, a change of many orders of magnitude, and it changed the nature of the problem entirely.
A deliberative process cannot govern events at that rate. It cannot decide on them, because a committee that meets monthly considers twelve moments a year and the agent produced tens of millions. It cannot even observe them, because there is no human reading of an action stream flowing at machine speed. The committee is not slow relative to the agent in the way a careful person is slower than a hasty one. It is slow by a factor so large that the two are not operating in the same regime at all. By the time the governance body convenes to discuss whether the agent is behaving appropriately, the agent has taken more actions than the body will review in its entire existence.
And each action cannot wait. The whole reason to deploy an agent is that its actions happen now, at the speed of the work, without a human in the path. An action that had to wait for a committee is not an agent action, it is a request for approval, and an agent whose every action waited for approval would be useless, which is why nobody builds one. So the actions do not wait, the committee is not present, and the governance the committee represents applies to none of them.
| Traditional governed event | Agent action |
|---|---|
| A few per quarter | Thousands per minute |
| Can wait days for a decision | Happens in milliseconds, cannot wait |
| A body convenes and deliberates | No body is present or could be |
| Reviewed individually | Never individually reviewed at all |
| Governance fits in the latency | Governance latency exceeds the event by orders of magnitude |
Read the two columns and the mismatch is not a matter of degree. The left column describes what deliberative governance was built for. The right column describes something that shares none of its properties, and a mechanism built for the left governs the right in name only.
What the Committee Actually Produces
It helps to look at what a governance committee actually outputs, because both of its products miss the agent, in instructive ways.
A committee produces a policy. A document stating what should and should not happen, what is allowed, what requires approval, what is forbidden. This is real work and it can be good work. But a policy is a document, and a document governs nothing on its own. It governs only to the extent that something enforces it, that some mechanism turns the words into a constraint on actual behaviour. For human employees, that mechanism is the human, who reads the policy, internalises it, and mostly follows it. Agents do not read the policy, do not internalise it, and do not follow it. The policy document that governs the agent is enforced by nothing, which makes it not a control but an aspiration, a statement of what the enterprise wishes were true about actions it is not actually constraining.
A committee also produces an audit. A periodic review, after the fact, of what happened, whether things went as intended, what should change. Auditing is genuinely useful and genuinely necessary. But an audit reviews the past. It examines actions that have already executed, harm that has already landed, decisions that are already irreversible. It is a detective control at best, and for agents it is a detective control running at quarterly cadence against events happening at machine speed, which means it reviews a vanishingly thin and heavily delayed sample of a firehose. The audit tells you, months late, about a tiny fraction of what the agent did. It does not govern the doing.
Between the aspirational policy and the retrospective audit there is a gap, and the gap is the actual actions, happening now, touched by neither. The policy says what should happen but enforces nothing. The audit reviews what happened but prevents nothing. And in the space between, where the agent is actually acting, thousands of times a minute, the committee's governance is simply not present. It bracketed the actions on both sides, before with a document and after with a review, and left the actions themselves ungoverned.
Between Two Meetings
Make the gap concrete by looking at what happens in the ordinary interval between two governance meetings.
A company stands up an AI governance committee to oversee its new agents. It is a good committee. It meets monthly, it has produced a thoughtful policy on what agents may and may not do, it has a review process, and it takes its remit seriously. In January it reviews the agent deployment, finds the policy sound, notes a few items to revisit, and adjourns until February.
In the four weeks between those meetings, the agents run. They take, across the deployment, on the order of tens of millions of actions, each one a governable event, each one a moment where the policy the committee wrote was supposed to apply. The committee is not present for any of them, because it is a committee and it meets in February. The policy is present only as a document, which enforces nothing on its own. So every one of those tens of millions of actions executes without the policy ever being applied to it, and if one of them is the harmful one, the manipulated payment or the leaked record, it happens in week two and is discovered, if at all, in the February review, as a past event to be discussed.
The committee did everything right and governed none of it. Not because the people were careless or the policy was weak, but because the entire apparatus operates on a monthly cadence against events that occur on a millisecond cadence, and a governance model with that mismatch does not govern slowly, it governs nothing. The February meeting will review a month in which the policy it wrote applied to zero actions, and it will do so believing itself to be the enterprise's AI governance, which is the most dangerous part, because the belief that governance is present is exactly what stops anyone from building the thing that would make it present.
A Program Is Not a Mechanism
The deeper error is a category confusion between a governance program and a governance mechanism, and it is worth naming because it is the thing to fix.
A governance program is people and process. Committees, frameworks, charters, review boards, roles, cadences. It is the human apparatus of deciding what should be governed and how. A governance mechanism is a control that actually constrains behaviour, a thing that sits in the path of an action and enforces the decision. The program decides. The mechanism enforces. They are different, and healthy governance has always had both, but for humans the mechanism could be thin because humans are their own enforcement. You govern people largely by telling them the rules, because a person who knows the rule mostly follows it, and you back that with occasional audit. The program does the deciding and the human does the enforcing, and it works well enough.
Agents remove the human that was doing the enforcing. An agent that knows the rule does not thereby follow it, because it does not internalise rules the way a person does, and it can be manipulated into violating them by the data it reads. The enforcement that used to live inside the governed party is simply gone. And most enterprises, reaching for the governance tool they know, have built a bigger, better program, more committees, richer frameworks, more detailed policies, and left the mechanism exactly as thin as it was when the human was providing the enforcement for free. They scaled the deciding and forgot that the enforcing had disappeared.
This is why the AI governance committee can be excellent and govern nothing. It is a program, and programs were always paired with an enforcer. The enforcer used to be the human. For agents, there is no human in the path, so unless the program is paired with an actual mechanism, a control that enforces the policy on the actions, the program decides rules that reach nothing. A magnificent program attached to no mechanism is a group of people deciding, in careful detail, what an agent that cannot hear them will not do.
What Governance Has to Become
The fix is not to abolish the committee. The committee is essential, because someone has to decide what is allowed, and that deciding is human work that requires judgment, context, and accountability. The fix is to change what the committee's decision becomes, so that it stops being a document nobody enforces and starts being a control that runs on every action.
Governance for agents has to split cleanly into two layers. The first layer is deliberation, and it stays human, in the room, at human pace. The committee meets, weighs, and decides what the policy should be, exactly as it always has. This layer is latency tolerant, because deciding the policy is an infrequent, considered act that can absolutely wait for the Tuesday meeting. Nothing about agents changes the value of human deliberation over what the rules ought to be.
The second layer is enforcement, and it cannot be human, cannot be in the room, and cannot be at human pace. It has to be a mechanism that takes the policy the committee decided and applies it to every single action the agent attempts, automatically, at machine speed, in the path of the action, before it executes. This is the layer that was missing, the enforcer that used to be the human and now has to be a control. The committee's decision flows into it as executable policy, and it does the thing the committee cannot: it touches every action.
the model that governs nothing the model that governs
committee ─► policy document committee ─► executable policy
│ │
▼ ▼
(hope) enforced on every action,
automatically, in the path,
audit ◄── after the fact before each one executes
│
the actions run ungoverned ▼
in between audit ◄── of enforced decisions
The committee's output changes from a document to a control. Instead of writing a policy that describes what should happen and trusting a human to enforce it, the committee decides a policy that is compiled into an enforcement mechanism and runs on every action. The deliberation is unchanged, still human, still careful, still accountable. What changes is that the decision no longer stops at the edge of a document. It becomes the thing that evaluates each action and allows, blocks, or escalates it, which is the only form in which a governance decision actually governs an agent.
This is authorisation at the action, and it is what turns a governance program into a governed system. The committee still meets. It still decides. But its decision now has hands, a mechanism that enforces it on the millions of actions the committee will never see, so that the governance is not a statement of intent bracketing an ungoverned firehose, but an actual constraint on each thing the agent does.
The Test for Real Governance
The reframing gives a clean test, and it is uncomfortable for most current AI governance efforts.
Stop measuring your agent governance by whether you have a committee, a framework, a policy, a review cadence. Those measure the program, and the program was never the thing in doubt. Measure it by a single question: does a control run on every action the agent takes. If the honest answer is that a committee meets, a policy exists, and an audit happens quarterly, but nothing evaluates the individual actions as they occur, then you have a governance program and no governance, an apparatus of deciding attached to nothing that enforces, and the agent is acting, right now, entirely outside all of it.
Governance for agents cannot live only in a room, because the thing being governed is not in the room and does not wait for the room. The committee still matters, deciding what is allowed is real and human work, but its decision has to leave the room and become a control that runs on every action, or it governs nothing at all. A governance that is only a meeting is not governance. It is a well documented record of intentions the agent never received, produced by people deciding carefully what a system that cannot hear them is, at this very moment, not doing.
Xybern is the authorisation layer for enterprise AI agents. Every agent action is enforced, audited, and governed before it executes. Learn more at xybern.com or read the technical documentation at docs.xybern.com.
Xybern
