Blog

You Cannot Govern an Actor

Written by Katie Bowen | Sep 15, 2026, 9:03:24 PM

Gartner published its first Magic Quadrant for AI Governance Platforms in June and a Hype Cycle for AI Governance Technologies in August. Both are rigorous. Both answer the question they set out to answer. Our argument is with the title, "AI Governance," not the research under it.

Curve shape and phase structure follow the standard hype cycle form. Innovation names and placements are referenced from Hype Cycle for AI Governance Technologies, 2026 and Magic Quadrant for AI Governance Platforms, 2026, both Gartner, Inc. This is an original Prediction Guard illustration and is not a Gartner graphic. Gartner does not endorse any vendor, product, or service depicted here.

Start with what the research gets right, because it is a lot. The placements are defensible. The market definition, which we will come back to, is sharper than anything the vendor community has produced.

Now trace the hype curve to its end. Past the Innovation Trigger, past the Peak of Inflated Expectations, down through the Trough, up the Slope of Enlightenment. What sits alone on the Plateau of Productivity?

Privacy Management Tools. The only thing behind it on the Slope is Metadata Management Solutions.

That is not a flaw in the analysis. It is the honest terminus of a governance chart. More than thirty innovations enter the curve, and where a governance curve matures is in the durable machinery of privacy and metadata. Read it on its own terms and it is telling the truth.

Which is exactly the problem. A word that terminates in a privacy tool and a metadata catalog is not the word for what a regulated enterprise is trying to do with three hundred agents in production. Governance is not being under delivered. Governance is being asked to mean something it has never meant.

Governance is a word with no unit

Ask ten people in a regulated enterprise what it means to say "we have AI governance in place." You will get ten answers. A steering committee. An acceptable use policy. A model inventory. A risk scoring rubric. An approval workflow. A quarterly attestation. An audit trail. Someone in legal who signs off.

Every one of those is a reasonable answer, which is the tell. Governance is an intention, and intentions do not have units. There is no number that tells you whether you have it. There is no event that proves it happened. There is no test that fails.

Now ask a different question. "Yesterday, how many agent calls were blocked, and why?"

That question has an answer. It has a number, a timestamp, a policy that is fired, and an operator who can act on it. It is the same subject matter, asked in a way that produces evidence instead of assurance.

The vocabulary is not cosmetic. Vendors build to the word. Call the category a governance platform and the natural product is a system of record: a place where policies live, risks are scored, and evidence is collected. Call it operational control and the natural product is a system of action: something in the path of every call that permits, blocks, redacts, reroutes, or escalates. The market shipped registries because we asked it for governance.

Models are artifacts. Agents are actors.

Here is why the word is failing now rather than three years ago.

Governance vocabulary was built for models, and a model is an artifact. Artifacts hold still. You can register one, version it, document its training data, review its bias metrics, put it through an approval gate, and record the decision. Every verb in the governance dictionary works on an object that sits there while you inspect it.

An agent does not hold still. An agent is not a thing you own, it is a sequence of decisions and actions taken on your behalf, most of which nobody anticipated when the approval was signed. There is no artifact to register, because the risk is not in the agent. The risk is in what it decided to do at 2:14pm this afternoon with a customer record and a tool it had access to.

You govern artifacts. You control actors. Those are different disciplines with different instruments, and the industry is trying to run the second one with the vocabulary of the first. That is the actual gap the charts reveal, and it is why the nearest innovations to agent reality, Agent Orchestration and AI Agent Action Rollback, sit at the Innovation Trigger with five to ten years to plateau. Those assessments look right to us. It is early. That is not a reason to wait, it is a reason to stop buying documentation and start buying control.

Operational control, in things you can count

Operational control of agents is a narrower claim than governance and a much more useful one, because every part of it produces a number.

Which actions an agent may take. Not a documented policy. An enforced allowlist of tools and scopes, evaluated per call. The number is how many action attempts fell outside it.

Which data it may reach. Per call, per identity, at the moment of retrieval. The number is how many reaches were narrowed or denied.

Which model serves the call, and where that model physically runs. The number is what percentage of your inference stayed inside your boundary.

What happens when a policy is violated. Block, redact, reroute, or require a human. The number is how many of each, yesterday.

Whether every one of those decisions is reconstructable afterward. Not a log of what the system saw. A record of what the system did about it.

Underneath all five sits one principle, and security already has the name for its predecessor. Least privilege gives every identity the minimum access required. Agents need the successor, and the currency is not access but agency. Least agency means every agent operates with the narrowest set of actions, tools, models, and data reach its task requires, enforced at the moment of the call rather than reviewed in a quarterly attestation. We've written about what this looks like operationally: scoping task boundaries precisely, enumerating every tool and API an agent can reach, and enforcing it at the moment of the call rather than in a policy document.

Least agency is what makes hundreds of agents per operator survivable. Nobody supervises three hundred agents by watching them. You supervise three hundred agents by constraining what any of them can possibly do, and by having every one of those constraints hold in the inference path instead of in a policy document.

That is also the honest answer to the question the governance frame cannot ask: how does one person safely run hundreds of agents? Not one agent in a sandbox. Hundreds, in production, touching regulated data, taking actions with consequences, on behalf of a team that still has a remit to deliver. That is the transformation the budget was approved for, and it is a control problem, not a governance problem.

The best definition in the market already describes control

This is where the research is most useful and most underread.

The Magic Quadrant defines an AI governance platform as "a centralized governance plane, uniquely providing real-time observability, dynamic risk scoring and runtime enforcement to monitor and intervene if policy violations occur." It explicitly separates that from traditional GRC tools, which it describes as "largely static repositories" that "function more like cloud-based spreadsheets."

Read the verbs. Enforce. Monitor. Intervene. That is not a governance definition wearing a governance label. That is a definition of operational control that the industry's vocabulary forced into a governance category. The analysts got the substance right and inherited the wrong noun, the same way the rest of us did.

Then look at the vendor landscape assessed against it. Per Gartner, the leaders are IBM, ServiceNow, and Truyo. The Visionaries include Airia, Credo AI, ModelOp, Monitaur, and OneTrust. SAP sits among the Niche Players. An ITSM platform. An ERP vendor. A privacy compliance company. A consent management firm.

This is not a scoring error. It is an accurate inventory of who exists today, measured against a definition that describes where the category is going. The definition is the roadmap. The vendor list is the current stock. The distance between them is the opportunity, and buyers should read it that way rather than assuming the quadrant is the ceiling.

The hype cycle makes the same point from another direction. The control plane in that definition does not appear as one innovation. It appears across at least five: AI Gateways, AI Usage Control, AI Runtime Defense, Agentic AI Security, and Small Language Models for Sovereign AI. Charting them separately is reasonable, since each matures on its own clock. Nobody operates them separately. In production they are one enforcement layer holding one policy, and buyers who procure them as five line items end up with five things that were never designed to agree with each other.

The lock in tax

Near the peak of the curve, alongside AI Governance Platforms, sits Microsoft 365 Governance Tools. In the Leaders quadrant sit IBM and ServiceNow. They are ecosystem products with governance attached, and the governance is the argument for consolidating on the ecosystem. You get to govern your AI by agreeing to run your AI where they tell you.

For a regulated enterprise that is a real trade, and it is almost never priced. You gain a governance story you can show an auditor. You give up the ability to change your model strategy without changing your control plane. When a new open weight model outperforms next year, when a residency requirement changes, when a business unit acquires a company running a different stack, your control layer is welded to a vendor whose commercial interest is that you do not move.

Architectural independence is not a technology, so no hype cycle will ever have a dot for it. It is a procurement decision, which means the only place it gets priced is in your own evaluation criteria.

Every framework says governance and measures control

The standards bodies arrived at this before the vendor market did. They still use the word, but look at what they actually grade.

NIST AI RMF does not stop at Govern and Map. The Manage function asks whether identified risks are acted on in operation, not whether they are catalogued.

OWASP named the failure mode early and named it precisely. Excessive Agency is LLM03 in the 2026 Top 10 for LLM Applications, and the 2026 Top 10 for Agentic Applications extends it across autonomous systems. Unconstrained agency has been a top ten security risk for longer than most governance programs have had a control for it.

The EU AI Act requires human oversight, robustness, and automatic logging in operation, not on paper. The Digital Omnibus deal pushed Annex III high risk obligations from 2 August 2026 out to 2 December 2027, while Article 50 transparency obligations took effect on schedule. Read that deferral correctly. It did not reduce the risk. It removed the deadline pressure that was, for many organizations, the only forcing function. Fifteen extra months spent producing documentation is fifteen months not spent building control.

AIUC-1, built with more than a hundred Fortune 500 CISOs and technical contributors from MITRE, Cisco, OWASP, Stanford, Microsoft, and Google Cloud, is the clearest signal. Its six domains, data and privacy, security, safety, reliability, accountability, and society, include input and output policies, data access limits, adversarial robustness, and tool call restrictions. It grades whether a safeguard holds under independent evaluation rather than whether a management system exists.

Four frameworks, one requirement: show that the control fired. None of them can be satisfied with an intention. Every one of them can be satisfied with an event log of enforcement decisions. That is not a coincidence, it is what happens when people who have to certify something reach for the only version of the concept that is testable.

Name the thing you actually buy

Operational control of agents is the discipline. The product category underneath it is the sovereign AI control plane: one enforcement layer in the inference path, applying a single policy across every model, agent, and data reach, running inside a boundary the enterprise owns.

Its operating expression is governed agent orchestration, and the hype cycle shows why that phrase is needed. Agent Orchestration sits at the Innovation Trigger. AI Governance Platforms sits near the peak. Two innovations, two timelines, two buying centers. Both assessments are fair. But the intersection of them is where every enterprise agent program actually lives, and an intersection is not something a hype cycle can plot.

Orchestration without control is how a pilot becomes an incident. Control without orchestration is how a governance program becomes a spreadsheet.

Four questions that separate control from governance

1. Does it enforce, or does it observe?

When a policy is violated, does the product stop the call or write a row? The published definition of the category says intervene. Hold vendors to it.

2. Does it run inside your boundary?

Self hosted, air gapped, no data egress, your keys. If control requires shipping prompts and outputs to a vendor cloud, your control layer just became your largest data exposure.

3. Is it one policy across every model and agent, or one policy per tool?

If adding a model means adding an integration, you do not have a control plane. You have a collection.

4. What does it cost per call, in milliseconds and in dollars?

Control that adds meaningful latency gets switched off in production, quietly, by an engineer under deadline. Ungoverned AI usually began as governed AI that was too slow.

Notice that all four have answers. That is the whole argument for the change in language. A governance question invites a narrative. A control question returns a value.

The trough is when the serious buyers move

The organizations that come out of the next eighteen months ahead will be the ones that spent them building the unglamorous layer. One control plane. Enforced at runtime. Inside their own boundary. Cheap enough to leave on. Not because it is on a chart, but because it is what makes agent scale survivable, and agent scale is the outcome the budget was approved for.

The governance curve ends where a governance curve should end. The control curve ends somewhere else: a hundred agents per person, running safely, in your building, with a number next to every decision they were not allowed to make.

Prediction Guard builds the sovereign AI control plane for regulated and public sector organizations: enforcement in the path of every call, across every model and agent, deployed inside your boundary for total operational control and visibility into your AI agents.