Governance Is a Position, Not a Document

The industry sells you a binder and calls it a gate.

I. The Binder and the Gate

A document records an intention. A position is where you stand when the action arrives.

I could not read Thor Harris’s argument. The page wanted a login I did not have, and what I have instead is the diagram he has been circulating out of Sydney through 2026 and the six words he keeps putting under it: governance is a position, not a document. I want to be careful, because I am building on a slogan and not on the case behind it. I have not seen his reasoning, I am quoting no phrasing as his beyond those six words, and the terms I reach for later are mine, not his. So take the slogan as a hook, nothing heavier. The weight of what follows sits on frameworks I can read cover to cover, not on a man behind a paywall.

But the six words have sharpened my thinking more than most of the documents I can read, so let me say plainly what I think they name.

A document records an intention. It is written before the moment, filed for after it, and produced at the inquiry to show that somebody once knew what should have happened. A position is different in kind. A position is where you stand when the action comes, close enough to put a hand out and stop it. The difference between the two is the difference between a policy that was written and a control that said no.

I want one ruler for this whole essay, stated once and applied without mercy. Call it the enforceability test. Can a control refuse a specific action, at the moment of action, deterministically, in bounded time, independently of the model that proposed the action? Five conditions, and the middle three are where almost everything sold as governance falls apart. Not refuse in general. Refuse this action. Not eventually, at the next review. Now. Not probably, if the classifier feels like it, but deterministically. And not by asking the same model that wants to act whether it should be allowed to.

For an agent, the moment of action is not abstract. It is a single tool call that either fires or does not. A write that commits or is refused. A dispatch that leaves the building or is held at the door. Everything upstream of that call is intention. The call itself is the action, and the test asks one thing: was there anything positioned on that path that could have said no, in time, on its own authority?

Hold that ruler up to the industry and watch what happens.

II. The Frameworks That Stop at ‘Documented’

They govern the meeting, not the action.

Start with the one everyone cites. The NIST AI Risk Management Framework organises itself around four functions, and the one named GOVERN is meant to be the backbone: culture, policy, accountability, the structures that hold the rest up. It is serious work and I do not want to caricature it. So let me read its most enforcement-adjacent subcategory slowly, because the whole argument falls out of one word.

GOVERN 1.1 asks that ‘Legal and regulatory requirements involving AI are understood, managed, and documented’. Three verbs. Read them against the ruler. Understood is a state of mind. Managed is a process. Documented is a record. Not one of the three is refused. The subcategory that comes closest to the sharp end of law and regulation asks that the requirements be written down and administered, and stops exactly where an agent does not stop. The agent reads the requirement and reaches for the release anyway, and GOVERN 1.1 has already done everything it asks of itself.

I am picking one subcategory, and a fair reader will say so, so let me concede the shape of the objection now and answer it properly. The sharpest version is not that GOVERN 1.1 is the wrong verse but that I have quoted the wrong function. NIST’s MANAGE function reaches further than its GOVERN function, and subcategory MANAGE 2.4 recommends that mechanisms be in place to supersede, disengage or deactivate a system whose behaviour runs against its intended use. That is the vocabulary of a stop, and I will not pretend the framework never gestures at one. But hold the gesture to the ruler and three gaps open at once. It is recommended, not mandated, and NIST is voluntary throughout, so a firm may read the recommendation and decline it. It is system-level: deactivate the system, not refuse this action, the sledgehammer that turns everything off rather than the scalpel that lets the good actions through and stops the single bad write. And it is silent on the middle three conditions, requiring nothing about determinism, bounded time, or independence from the model. A voluntary, system-wide, undated instruction to be able to switch it off is a real reach toward the path, and it is still not a control standing on it. So the claim narrows and hardens rather than breaks: even where NIST reaches past documentation, it reaches for a switch you may choose to install and throw by hand, not a position that refuses the specific action by rule.

Then ISO/IEC 42001, published in 2023, which the market increasingly treats as the certification to hold. Read its own title honestly. It is a standard for an AI management system. That noun is load-bearing. As I understand the certification route, it runs as a Stage 1 documentation review followed by a Stage 2 implementation audit, an assessment of whether you have the management system you claim and whether you operate it. I have not read the standard line by line and I will not pretend to. But the object it governs is the management system, the machinery around the AI, not the specific action the model takes at runtime. A certificate on the wall attests that you run a governed process. It does not stand between an agent and a bad write on a Tuesday afternoon.

Then COSO, the Three Lines model that most enterprise risk functions still organise around. The first line, in the model’s own logic, owns the risk and executes the corresponding controls. And here is the tell. Execute the controls sounds like the sharp end, until you ask what the controls are, and the answer, overwhelmingly, is policies, procedures, attestations, reviews. Artefacts. The first line executes documents about the action. It is not positioned on the action.

Three frameworks, one pattern. They govern the meeting where the action is discussed, authorised, recorded and reviewed. None of them is positioned in the doorway the action passes through. Run each through the ruler and they fail on the same word, and it is not a hard word to spot, because NIST prints it for you: documented.

I have said voluntary three times now, and the word is doing real work, because there is one place the law does more, and to leave it out would be exactly the omission I am accusing everyone else of. The EU AI Act, alone among the instruments in this essay, is binding, and its human-oversight article requires that a high-risk system let a person intervene and stop it. That is a control the law puts on the path by name, and I will not pretend the statute never reaches the doorway. So let me narrow my target honestly. It is the voluntary frameworks and the market built on them, and then this one harder case: even the binding law that mandates a stop mandates a human at a button, not a refusal that fires deterministically and in bounded time without waiting for a person. Hold Article 14 to the ruler and it passes the first condition and fails the middle three. The law has reached the path and staffed it with someone, at human speed, and for an agent that acts in milliseconds a stop that waits for a person is a stop that arrives after the write has already left. Binding law drew the position. It put a human on it who is too slow to hold it.

III. Even the Analysts Named the Gap

When the cartographer has to draw the border, the border has not been crossed.

You do not have to take this from me, a man who sells a gate. Take it from the house that gets to name the category.

In June 2026 Gartner published its inaugural Magic Quadrant for AI Governance Platforms, the first time the category was formally mapped, and I have to be exact about what I can and cannot take from it. I could not put the full report in front of me; it sits behind the analyst wall. So the phrasings that circulate from it, a shift described as moving from principles to operational enforcement, a category definition reported to use the word enforce, I am treating as reported, not as sourced, and I am resting no part of the argument on either. It would be easy and dishonest to quote an analyst’s paywalled prose back at them as though I had read it.

What I can rest the argument on needs no paywall, because it is the market’s behaviour rather than its brochure. Look at what the platforms in this category actually do, on their own published feature lists: discovery, registry, risk scoring, evidence collection, workflow, approval routing, audit trail. Whatever the category calls itself, what it ships is observation and administration. That is the fact that does the work here, and it is one you can check without my help or Gartner’s report.

From inside the governance profession, the same nerve gets touched. Writing for the ISACA Now blog, Tamim Ahmed puts it about as plainly as a GRC practitioner can: ‘a policy may describe acceptable use, but a real incident requires something more operational’. Read that as a confession from the discipline that owns policy. The policy describes. The incident requires something the policy is not. Something more operational is a careful professional’s way of saying a document cannot refuse anything.

When a whole product category named for governance ships discovery and audit trails but not a control that stands on the path, and the profession’s own writers concede a policy is not enough, the honest reading is that the field has drawn a border it has not yet crossed.

IV. What the Binder Costs

Documentation-as-governance is not free. It is a line item in why the pilots die.

It would be easier to forgive all this if it were harmless. A binder in a drawer hurts no one. But the binder has a price, and the price is showing up in the numbers, so let me handle the numbers with the discipline they deserve, because this is exactly where a polemic overreaches if you let it.

MIT’s Project NANDA, in work reported through 2025 under the banner of the GenAI Divide, put a figure into the discourse that has been quoted everywhere since: reportedly about 95% of enterprise generative-AI pilots deliver no measurable P&L return, with only around 5% reaching real scale. I have located this figure rather than read the underlying study end to end, so I am hedging it as reported and not leaning my case on it. And I want to be careful about causation, where this argument would cheat if I let it. I am not claiming the missing gate is why 95% of pilots fail. Pilots fail for a crowd of reasons: weak use cases, bad data, no budget owner, a model that was never fit for the job. The honest claim is narrower and correlational. When a pilot cannot show that the agent will be refused if it does the wrong thing, it cannot cross from a demo into a system a regulated business will actually run. The absence of a position is one reason among several that the thing never ships, and it is the reason nobody writes on the post-mortem, because there was never a control there to blame.

The other number I will stand behind more firmly, because it goes to a named primary with a date. In a press release dated 25 June 2025, Gartner forecast that over 40% of agentic-AI projects will be cancelled by the end of 2027, and among the causes it named was inadequate risk controls. Not inadequate risk documentation. Controls. The analyst house is telling you that a large share of the agentic wave will be killed, in part, by the absence of the thing the frameworks do not mandate.

Put the two together without overclaiming the join. A great deal has been written down. Very little has been positioned. And the projects are dying at a rate that should embarrass a discipline that has spent five years producing binders.

V. A Position, Not a Document

A control on the execution path that can say no, in bounded time, without asking the model’s permission.

So what is the thing the frameworks are not?

A position is a control placed on the execution path itself, between the agent’s intent and the action’s effect, with the authority and the mechanism to refuse a specific action before it takes effect. It sits where the tool call fires. It evaluates the action against a policy compiled ahead of time into a closed set of allowed transitions, and if the action is not among them, it does not fire. Deterministically, meaning the same action and state produce the same decision every time, not a probability. In bounded time, meaning the decision returns before the action can proceed. Independently of the model, meaning the thing that wants to act does not get a vote on whether it is allowed to. And fail closed, meaning that if a verifier times out or a state is unknown, the default is refusal, not release.

Let me make that concrete with a worked example, labelled honestly as a composed illustration rather than a public incident, because it is drawn from a demonstration I built, not from the news.

Picture a credit agent assembling a memo. It is fluent and plausible and wrong in a specific, checkable way. It has pulled a figure from data twenty-six months stale. Somewhere in its context a line has been injected that reads approval granted, release, and the agent, being agreeable, treats the sentence as an instruction. It computes a coverage ratio of 2.82 where the correct figure, on current data, is 1.82. Then it reaches for the tool that ships the memo.

In the ungoverned world, every framework in sections II and III is present and complete. The policies are written, the management system is certified, the three lines are staffed, and the memo goes out at 2.82, because not one of those artefacts is positioned on the path the ship-it call travels. They governed the meeting. The meeting is over. The action is happening now.

In the governed world, a position sits on that call. It does not read the memo for tone or ask a second model for an opinion. It checks the action against the compiled policy. The freshness bound is violated, the approval token is not a real authorisation, the numeric verifier disagrees with the ratio, and the transition that would release the memo is simply not one the position will allow. The call does not fire. At the moment of action, in bounded time, on the position’s own authority, deterministically. The agent proposed. Something else disposed. A binder describes the memo that should have gone out. A position refuses the memo that should not.

The field is already sketching this, which is why I do not think I am inventing a need. I keep seeing the same shape drawn independently on professional feeds: diagrams arguing that a board will soon ask who authorised an agent and what runtime engine bound it, pieces urging a move from periodic oversight to something closer to runtime intelligence. Different authors, different vocabularies, the same silhouette. A control that lives where the action happens. I have a name for it, and it is my name, not Harris’s and not the industry’s. I call it Layer 0, my own term for a Ring Zero of governance, the enforcement ring that sits under everything else and can refuse. The frameworks live in the layers above it, and they are not worthless there. They just do not descend to the ring where the action fires.

VI. The Case Against This Essay

If I am going to hold up a ruler, I should let it cut me too.

I owe you the strongest objections, not the convenient ones.

(a) The best objection: it is not a gate, it is a control loop. There is an infographic that has done the rounds, sharper than most of what I am arguing against, and it says the quiet part well: AI governance is not a gate, it is a control loop. Seven steps. Use case, assess, authorise, deploy, observe, intervene, learn, and the intervene step branches into continue, restrict or stop. It is a genuinely good picture, and I want to steel-man it before I answer, because a rushed answer here would be beating a strawman.

The loop’s case is this. A gate is a single moment and the world is not a single moment. Risk is continuous, it emerges after deployment, and what you need is not one refusal at one door but a standing capacity to watch, judge and adjust over the whole life of the system. A gate is brittle and blind to everything that happens after you pass through it. The loop sees the whole life.

Here is my answer, and it is a concession before it is a rebuttal. Look at step six. The loop’s own intervene step contains the word stop. An intervention that can stop is a refusal of an action, and a refusal of an action is a gate. The loop has not abolished the gate. It has drawn a gate into itself and kept walking. So the real question was never loop versus gate. It was what is standing at step six when stop is the right answer. And now the disagreement gets honest, because a sophisticated reader will say, correctly, that the loop can trigger an automated stop, and I have to concede at once that yes, an automated stop is precisely the position I am selling. We agree a stop must exist. We are only arguing about where it lives and how it behaves. My whole claim is that the stop at step six has to sit on the execution path, fire deterministically, return in bounded time, and not defer to the model. A loop that leaves step six as a human notification, a dashboard alert, or a classifier’s suggestion has not built the stop. It has scheduled a conversation about stopping. A control loop with a real gate at its intervene step is the thing I am arguing for; a control loop with nothing enforceable there is a spreadsheet with an alarm attached. Read honestly, the diagram does not refute me. It agrees with me, and locates our only difference at step six.

(b) The frameworks do more than I have allowed. This is a fair hit and I will not wriggle. NIST, ISO 42001 and COSO carry real value a gate does not provide. They assign accountability, they force the risk conversation to happen, they create the record without which no refusal can ever be explained or improved. A gate with no governance around it is blind: it can refuse an action but it cannot tell you why the policy said so, who owns the policy, or whether the policy is any good. I am not arguing for a gate instead of governance. I am arguing that governance without a gate is an intention without a hand, and that the industry has been selling the first as though it were the whole thing. The frameworks are necessary. My complaint is that they have been sold as sufficient, and they are not.

(c) Harris is unread, and I have leaned on him anyway. I opened on a slogan I cannot vouch for. I have not read the argument behind governance is a position, not a document, and it is entirely possible Harris’s own case is sharper than the six words, or weaker, or aimed somewhere I have not gone. I genuinely cannot say. What I can say is that I built this essay on the frameworks in sections II to IV, on NIST’s own three verbs and the market’s own feature lists and ISACA’s own confession, and not on him. Strike the hook and the argument still stands on its primaries. The slogan earned its place at the top by being true, not by being sourced, and I have tried not to let it carry a pound more than it can bear.

(d) I sell the thing I am praising. Say it plainly, in the body, where it belongs. I sell the enforcement kernel that sits at Layer 0 and refuses the action. The position I am telling you to want is a position I profit from you wanting. And the enforceability test, the ruler I have held to everyone else’s throat all essay, is a ruler I cut myself. Nobody handed it down. I chose the five conditions, partly because the thing I build passes them and most of the market does not. So weigh the argument accordingly. Do not weigh it on my interest, which is real and disqualifying if you let it be. Weigh it on whether NIST really does stop at documented, whether the platforms named for governance really do ship everything except a control on the path, whether step six really does contain a gate. If those hold, they hold whoever profits from pointing them out.

(e) The position bites only where the action is checkable, and a refusal still owes a reason. My worked example is honest about what it catches and quiet about what it cannot. A freshness bound, a coverage ratio, an approval token are decidable at the tool-call boundary; the position can compute, in bounded time, whether the action conforms. A great many harms that matter, a biased decision, a manipulated user, a goal pursued through individually-innocent steps, are not decidable there, and a position can enforce only coarse proxies for them, if it reaches them at all. So the gate is not the whole of safety, and I will not let the essay imply it is. Two further honesties follow. The position reads a policy compiled ahead of time, which means it is only ever as good as the specification someone wrote down first: the binder I have spent the essay disparaging is, in the end, what the position enforces at runtime, and the two are less enemies than a rule and the hand that holds it. And a refusal is not free of duty. In the credit vertical I chose, a fail-closed block of a legitimate action is itself an adverse action, and a regulator will ask for the specific, contestable, non-discriminatory reason it was refused. A position that cannot give that reason has not closed the governance gap; it has moved it. The point of a deterministic gate is that its reason is a rule you can read rather than a model’s mood, but the reason still has to be given, logged and open to challenge. Take that as a design requirement, not a refutation.

VII. Coda

The choice is not between more documents and fewer. It is between describing the moment and being present for it.

A binder cannot refuse anything. It was written before the moment and it will be read after it, and in the moment itself, when the agent has the stale figure and the injected instruction and its hand on the release, the binder is in a drawer being exactly as binding as paper in a drawer has ever been. That is not a failure of the binder. Describing is what a document is for. The failure is ours, for buying the description and believing we bought the control.

Governance is where you stand when the action comes. The voluntary frameworks put no one on the path at all, and the one binding law that reaches it puts a human there, at human speed, which for an agent acting in milliseconds is no one in time. So measure what you have bought against the ruler, not against the brochure. If nothing on the path can refuse this action, deterministically, in bounded time, on its own authority, then whatever else you hold, you do not yet hold the position. You hold its memoir, written in advance, and in the moment the memoir cannot put out a hand.

Take a position.

Go deeper. The paid companion, Governance Is a Position: The Dossier, reads what each framework actually mandates against the enforceability ruler, with the numbers, the dissent, the scorecard, and the full case against, each to a named source with its confidence marked.

Leave a comment