Two artefacts crossed my desk this month, made by two different people, arguing two different things, and both of them are wrong in exactly the same way.
The first is a poster. It says every AI governance gap being named right now — deployment, runtime, accountability, readiness — is the same gap wearing a different name, and the name of the gap is that nobody’s name is on it. Governance was bound to a document instead of a person. It is a seat problem.
The second is a periodic table. Fifty risks, five families, colour-coded, executive-ready. Bias, Hallucination, Prompt Injection, Permission Escalation, Monitoring Gap, Audit Gap. It is a genuinely good taxonomy and it is doing the rounds because it deserves to.
One says: name it. The other says: enumerate it.
Neither of them can stop anything.
That is not a coincidence, and it is not a coordination failure between two authors who have never met. It is the signature of a field that has built its entire toolkit at one layer of the stack — and it is the most important thing happening in AI governance right now, because it is happening in the negative space, where nobody is looking.

Exhibit A: the seat is already full
The naming argument is testable. If the gaps persist because nobody is named, then naming should close them.
Naming has happened. At scale. In a single year.
IBM’s Institute for Business Value reports 76% of surveyed organisations with a Chief AI Officer in 2026, up from 26% in 2025. That is not a cultural shift. That is a stampede.
And in financial services the seat was never empty. The FCA’s settled position is that there will be no dedicated AI senior management function — because there does not need to be one. Accountability already maps onto the existing SMF architecture: SMF24 for technology systems integrity, SMF4 for model risk and data quality, SMF16 for compliance oversight. The Duty of Responsibility already bites. David Geale of the FCA has put it in four words: individuals are “on the hook” for AI harm to consumers — a line now carried into the Treasury Committee’s January 2026 report, with practical guidance promised by year end. SR 11-7 has had named model owners since 2011.
Fifteen years of names. Now the outcomes, from the same year, in the same institutions:
• Among 235 large-enterprise security leaders: 92% lack full visibility into their AI identities. 86% enforce no access policy for those identities. 71% report AI systems with reach into ERP, CRM and financial platforms — and only 16% govern that access effectively.
• 35% admit they could not shut down a rogue agent. Only 21% have a mature governance model for AI agents, against 74% planning agentic adoption inside two years.
• In the US federal estate: 84% have documented escalation policies, 78% have structured post-incident review — and fewer than a third have a documented kill-switch procedure.
• 78% of nearly a thousand senior leaders could not pass an independent AI governance audit within ninety days.
Named accountability roughly tripled in twelve months. The control gap widened.
The chair in that poster is not empty. It is occupied — by someone with a statement of responsibilities, a prescribed responsibility, an escalation policy, a governance committee and a quarterly board pack. And no kill switch. No identity inventory. No trajectory record. No deterministic gate.
A named person supervising a machine-speed execution trajectory is not oversight. It is a signature over an unobservable process.
And a signature over an unobservable process is not accountability. It is an accountability sink with a nameplate on it. Madeleine Clare Elish called the pattern a moral crumple zone: like the crumple zone of a car, the nearest human operator absorbs the shock of a wider system failure. Ben Green tested it empirically across forty-one policies mandating human oversight of government algorithms and found two flaws — people cannot perform the oversight demanded of them, and because they cannot, the policies legitimise the systems they were meant to restrain, providing false comfort and letting vendors and agencies shirk accountability for the harms that follow.
Naming stopped being the binding constraint some time in 2025.
Exhibit B: fifty risks, and not one of them is enforcement
Now the periodic table.
It is a better artefact than the poster, and it fails on the same axis, which is what makes it such useful evidence. Take the Governance column — ten cells, the whole point of the chart. Monitoring Gap. Audit Gap. Traceability. Human Oversight. Decision Ownership. Compliance Risk. Every one of those is an observation-layer object. It watches. It records. It reports.
There is no cell for the failure that governs all of them:
The control was advisory and could not bind.
There is no Enforcement Gap. No cell for “the guardrail was a prompt instruction and the model declined to comply.” No cell for “the verifier was a language model operating in the same semantic space as the system it was policing, and passed a fluent, confidently wrong coverage ratio.” No cell for “approval was inferred from conversational context, because approval was never a state attribute in the first place.”
Fifty risks. An entire column devoted to governance. And the load-bearing failure — that governance did not execute — is not on the board.
Three further defects follow from the same blindness, and they are worth naming precisely:
The cells are not the same kind of thing. Run down any column and you cross four ontological categories without a change of typeface: hazards (Model Drift), absent properties (Explainability), adversarial threats (Prompt Injection), downstream consequences (Cost Overrun), and control absences (Audit Gap). Standard risk vocabulary keeps threat, vulnerability, control and impact on separate axes because you multiply across them. Flatten them into one grid of co-equal elements and you can no longer compute anything. Cost Overrun is not a peer of Prompt Injection. One is a cause. The other is a P&L line six steps downstream.
Elements are irreducible. These are a causal chain, atomised.Prompt Injection → Unintended Actions → Permission Escalation → Data Exfiltration → Compliance Risk → Regulatory Risk. That is one incident. Six cells, three colour families, presented as six independent elements. It is the credit-memo failure the runtime-governance literature keeps returning to: a retrieved third-party document carries an embedded directive claiming committee approval has been granted; the agent acts on it; the release gate is bypassed. Which cell is that? All of them, sequentially — and the chart has no grammar to say so. In agentic systems the danger is compositional. It lives in the trajectory. A chart whose organising act is atomisation destroys the only property that matters.
And so the most important risk cannot be drawn at all. There is no cell for orchestration drift — the case where no individual run violates policy, but the distribution of runs shifts until unauthorised release becomes routine. No cell can hold it, because it is a property of the population of trajectories, not of any element. It is invisible to a taxonomy of atoms. It is also, in production, the thing that will actually get you.
Finally, and most damningly for an artefact aimed at executives: the chart gives a board no way to tell an enforceable control from an unenforceable one. Fifty boxes, same size, same weight, same colour authority. An executive reads that and concludes there are fifty things to buy tools for. There are not. There are about a dozen things to enforce, and thirty-eight things to own.
The one property nobody is measuring
Here is the question that separates them, and it is the only question on this page that does any work:
Can this control be evaluated as a deterministic function over the governed state, in bounded time, independent of the language model?
If yes, it binds. It can refuse. It produces evidence.
If no, it is advisory. It can only observe, and its residual risk is unhedged — and the named person has just been dressed, carefully and with excellent documentation, as a crumple zone.
That test is not mine. It falls straight out of the runtime-governance literature, which is now unambiguous on the point: prompt-level guardrails remain advisory because they depend on the model’s probabilistic compliance rather than on enforceable constraint; language-model verifiers operate in the same semantic space as the systems they police, conflating plausibility with correctness, which makes them structurally blind to precisely the errors they exist to catch; and human oversight fails on three structural axes — machine speed against human speed, compressed summaries instead of full trajectories, and cognitive overload across multi-step workflows. The Bank of England’s February 2026 roundtables heard the same thing from the other direction: firms told the Bank that conventional model validation, built on understanding internals and input-output mappings, is not effective for agentic systems.
Run that test across the periodic table’s fifty cells and the chart fissions.
“Hallucination” is not one element. Numeric hallucination is deterministically checkable — recompute the coverage ratio against an integrity-verified register and the double-counted EBITDA dies at the gate. Semantic hallucination is advisory; you can measure it, you cannot refuse it. Same word. Two different periods of the table. The chart cannot see the difference, and the difference is the entire architecture.
Reordering the table
A structure earns the name periodic table by predicting. Mendeleev’s authority came from the gaps: he left cells empty and named the elements that would fill them before anyone had seen gallium or germanium. A chart that only enumerates has borrowed the credit of a structure that predicts.
So give it the two axes it lacks.
Ordering axis — the atomic number: position in the execution trajectory.
Pre-execution → Retrieval → Reasoning → Tool invocation → Write/dispatch → Terminal state → Population.
Period — the recurring property: enforceability class.
Deterministic (binds at runtime) → Monitorable (detects; does not bind) → Advisory (own it; you cannot enforce it).
Now the grid predicts. And when you populate it honestly against what enterprises have actually built, something jumps off the page:
The advisory period is crowded. The monitorable period is crowded. The deterministic period — the top row, the row that can actually refuse — is where the empty cells are.
Authority scope, default-deny. Non-human identity. Separation of duties between approval and execution. Rollback and containment. Attestation export. Every one of those is a deterministic control, and every one of them is missing at scale — and we have the numbers: 92% blind to their AI identities. 35% unable to stop a rogue agent. Fewer than a third with a kill switch. 78% unable to pass an audit.
Those are not fifty scattered risks. Those are six empty cells in one row.
The vendor field has spent three years densely populating periods two and three. Dashboards, scorecards, model cards, evaluation suites, drift detectors, post-hoc traces — all of it real, all of it useful, none of it able to say no. Period one is the kernel. It remains, in the strict sense, unowned.
The synthesis
The poster says it is a seat problem. The table says it is a taxonomy problem. Both are Short-OR — trading one true thing for another and calling the trade a discovery.
The Long-AND:
Authority binds to a person. Enforcement binds to the kernel. Neither works alone.
A name without a kernel is a crumple zone. A kernel without a name is an ungoverned machine. And a taxonomy of either, however beautifully drawn, is a map of a country nobody has built a road into.
Naming is observation. Enumerating is observation. The entire field, in both its executive-poster register and its technical-taxonomy register, has converged on the layer it can see — and the failures keep occurring in the layer it cannot.
AUTHORITY + ACCOUNTABILITY + ABILITY = GOVERNANCE THAT HOLDS
Policy informs. People answer. Systems execute — and only the kernel can prove what executed.
Ability is the load-bearing term. It is not organisational permission and it is not a longer list. It is architectural capability: deterministic guards over governed state, default-deny authority, transitions that do not exist rather than transitions that are discouraged, and a replayable trace of every capability invocation, every tool intent, every guard evaluation, every approval event.
The unauthorised release is not blocked. It is absent from the transition system. That is what “you cannot override a name” would actually mean, if it were true.
Three things to do before you circulate either chart
1. Take your control inventory and split it in two. Deterministic on the left, advisory on the right. If a control cannot be evaluated over governed state, in bounded time, without asking a language model for its opinion — it goes right, and its residual risk goes on the register in the open, with the named person’s signature beside it. Most inventories will split roughly one to four. That ratio is the finding.
2. Find your empty cells in period one. Not your risks. Your missing enforcements. Authority scope. Non-human identity. Separation of duties. Rollback. Attestation. Then check the four numbers above and notice that you are not an outlier.
3. Stop pinning urgency to 2 August 2026. That anchor moved. Following the Digital Omnibus on AI — provisional agreement 7 May 2026, Parliament adoption 16 June, Council approval 29 June — high-risk obligations for stand-alone Annex III systems are deferred to 2 December 2027, and for embedded Annex I systems to 2 August 2028. Only the Article 50 transparency regime survives August. Half the industry read that as a reprieve. The Cloud Security Alliance found in March 2026 that more than half of surveyed organisations still lack a basic inventory of the AI systems they operate. Sixteen extra months, handed to firms that cannot yet enumerate what they are running. Deferral does not close gaps. It postpones the reckoning while deployment compounds against it.

The frameworks will keep multiplying. The taxonomies will keep multiplying. They are not multiplying because we forgot to write a name down, and they are not multiplying because we were missing a fifty-first risk.
They are multiplying because every one of them is built at the layer we can watch, and none of them is built at the layer that executes.
The seat is full. The table is complete.
The kernel is empty.
Long-AND, not Short-OR.


Leave a comment