The Governance Lag
11 August 2026 · Jamie Cruie
Every major AI governance framework in force today was finalised before the capability it now has to govern existed at scale. This is not a documentation oversight - it is a structural, repeating pattern.
Governance Is Fragmenting, Not Converging
AI governance is not settling toward one global standard. Independent analyses converge on the same finding: the landscape is splitting into distinct regional approaches, each reflecting the regulatory identity that jurisdiction already had before AI arrived - the EU prioritising fundamental-rights protection, the United States favouring innovation and voluntary standards, China emphasising state and content control.
The divergence runs deeper than emphasis. It is structural: top-down and risk-based in the EU; coordinated across existing federal, state, and city enforcement bodies in the US; centralised in appearance but regionally competitive in practice in China. Over 72 countries have launched more than 1,000 separate AI policy initiatives, moving along the same regulatory spectrum at different speeds and in different directions.
Where Convergence Does Exist
Technical and procedural scaffolding - Singapore's AI Verify toolkit, ISO/IEC 42001, the NIST AI RMF's Govern-Map-Measure-Manage structure - is converging as shared plumbing even where the values sitting on top of it diverge sharply.
Where It Doesn't
What counts as an acceptable risk to impose on a population in exchange for AI's benefits remains a values question, answered differently and, so far, irreconcilably by each major jurisdiction.
None of the Major Frameworks Name "Agentic"
The clearest, most current evidence of reactive-lag governance is sitting in plain sight.
The Frameworks Predate the Risk
The NIST AI RMF (January 2023) and ISO/IEC 42001 (December 2023) do not directly name multi-agent systems, persistent memory, or tool-using agents. Current frontier safety policies, the RMF, ISO 42001, and the EU AI Act contain no reference to "agent" or "agentic" AI at all.
Deployment Outran Governance
Computer Use, Operator, and Claude Code all reached general or commercial availability between October 2024 and May 2025 - each preceding any binding, agent-specific governance standard. Claude Code reportedly reached $1B in annualised revenue within months of launch, still ungoverned by anything built for it.
The Deficit Is Already Measurable
79% of businesses plan to or are already using agentic AI. Only 48% have any framework in place to govern or limit its autonomy - a near-even split between deployment and governed deployment, in production, today.
The South Australian AI Royal Commission
South Australia announced a $3 million Royal Commission into AI in August 2026, expected to commence in October 2026 and report by 1 July 2027 - a multi-year public inquiry into a technology already deployed at national economic scale.
| Framework | Finalised | Agentic AI Coverage |
|---|---|---|
| NIST AI RMF 1.0 | January 2023 | None named; agentic profile extension in development Reactive |
| ISO/IEC 42001 | December 2023 | No dedicated agent controls; behaviours mapped onto existing clauses Reactive |
| EU AI Act | Regulation 2024/1689 | No reference to agentic systems in binding text Reactive |
| SA AI Royal Commission | Announced August 2026 | Terms of reference not yet public; inquiry begins after deployment, not before Pending |
Whatever the Commission's eventual findings, its timing is itself evidence for the pattern this piece describes - a major jurisdiction convening a formal inquiry into a capability only after it is already embedded in the economy it now has to be examined against.
Reactive Coverage vs. Anticipatory Design
The market and policy gap is not "no governance exists." It is that governance is structurally reactive - built to formalise risks only once they are already observed at deployment scale.
Anticipatory Gap Detection
A standing mechanism for flagging emerging risk categories as they appear in a system's observed behaviour, rather than only auditing against a fixed checklist that is, by construction, always one generation behind current capability.
Source-Neutral Technical Layer
A shared evidentiary and risk-assessment layer that sits underneath jurisdiction-specific values choices - compatible with the convergence already happening around ISO 42001 and NIST's process structure, rather than competing with it.
Values vs. Fact Separation
A structural distinction between a jurisdiction's legitimate values choice (expected to vary) and a jurisdiction's factual claim about what a system actually does (which should not vary, and where divergence signals distortion rather than legitimate difference).
Where This Leaves Policy-Makers and Practitioners
For organisations and inquiries examining AI governance today, including the South Australian Royal Commission, the practical takeaway is specific rather than general.
The absence of agentic-specific coverage in NIST, ISO 42001, and the EU AI Act is not a hypothetical future risk - it is a present, measurable, and independently documented gap. Any governance response built now has the opportunity to be anticipatory rather than reactive for the first time in this technology's regulatory history - but only if it is designed around detecting emerging capability, not only auditing capability that has already arrived.
Related reading
This is Part II of a three-part series. See also: Why Capability Doesn't Self-Correct and The Reactive Gap, and the related piece on The Missing Layer in AI Governance.