Note · 2026-08
Agents are leaving the lab. The check has to run first.
A slide deck is not proof that you can stop a high-impact step. Security and Risk want a check that runs before the system is touched.
If an agent can change a record, send money, or fire a notice, it is already in the perimeter. Calling it a chatbot does not change that. Access control and a policy PDF are not the same as a decision at the moment of the call.
“The model said so” is not enough on a credit file, a payment, or a clinical order. Someone named has to be able to stop it. You need a record of yes and no, including the actions that never ran.
Watch in shadow mode. Pick one workflow. Keep a file Risk and Compliance can reconstruct. Do not rip out core systems to get there.