← All Articles

Governance

The Governance Lag

11 August 2026 · Jamie Cruie

Every major AI governance framework in force today was finalised before the capability it now has to govern existed at scale. This is not a documentation oversight - it is a structural, repeating pattern.

01 - No Global Convergence

Governance Is Fragmenting, Not Converging

AI governance is not settling toward one global standard. Independent analyses converge on the same finding: the landscape is splitting into distinct regional approaches, each reflecting the regulatory identity that jurisdiction already had before AI arrived - the EU prioritising fundamental-rights protection, the United States favouring innovation and voluntary standards, China emphasising state and content control.

The divergence runs deeper than emphasis. It is structural: top-down and risk-based in the EU; coordinated across existing federal, state, and city enforcement bodies in the US; centralised in appearance but regionally competitive in practice in China. Over 72 countries have launched more than 1,000 separate AI policy initiatives, moving along the same regulatory spectrum at different speeds and in different directions.

Where Convergence Does Exist

Technical and procedural scaffolding - Singapore's AI Verify toolkit, ISO/IEC 42001, the NIST AI RMF's Govern-Map-Measure-Manage structure - is converging as shared plumbing even where the values sitting on top of it diverge sharply.

Where It Doesn't

What counts as an acceptable risk to impose on a population in exchange for AI's benefits remains a values question, answered differently and, so far, irreconcilably by each major jurisdiction.

02 - The Live Gap

None of the Major Frameworks Name "Agentic"

The clearest, most current evidence of reactive-lag governance is sitting in plain sight.

The Frameworks Predate the Risk

The NIST AI RMF (January 2023) and ISO/IEC 42001 (December 2023) do not directly name multi-agent systems, persistent memory, or tool-using agents. Current frontier safety policies, the RMF, ISO 42001, and the EU AI Act contain no reference to "agent" or "agentic" AI at all.

Deployment Outran Governance

Computer Use, Operator, and Claude Code all reached general or commercial availability between October 2024 and May 2025 - each preceding any binding, agent-specific governance standard. Claude Code reportedly reached $1B in annualised revenue within months of launch, still ungoverned by anything built for it.

The Deficit Is Already Measurable

79% of businesses plan to or are already using agentic AI. Only 48% have any framework in place to govern or limit its autonomy - a near-even split between deployment and governed deployment, in production, today.

Even the standards bodies concede it Industry frameworks themselves state plainly that no single existing standard is complete, and that organisations should expect to supplement current guidance as formal standards mature - the challenge is not the absence of frameworks, but the discipline to apply them to a technology changing faster than any framework can track.
03 - A Live Case

The South Australian AI Royal Commission

South Australia announced a $3 million Royal Commission into AI in August 2026, expected to commence in October 2026 and report by 1 July 2027 - a multi-year public inquiry into a technology already deployed at national economic scale.

Framework Finalised Agentic AI Coverage
NIST AI RMF 1.0 January 2023 None named; agentic profile extension in development Reactive
ISO/IEC 42001 December 2023 No dedicated agent controls; behaviours mapped onto existing clauses Reactive
EU AI Act Regulation 2024/1689 No reference to agentic systems in binding text Reactive
SA AI Royal Commission Announced August 2026 Terms of reference not yet public; inquiry begins after deployment, not before Pending

Whatever the Commission's eventual findings, its timing is itself evidence for the pattern this piece describes - a major jurisdiction convening a formal inquiry into a capability only after it is already embedded in the economy it now has to be examined against.

04 - The Structural Fix

Reactive Coverage vs. Anticipatory Design

The market and policy gap is not "no governance exists." It is that governance is structurally reactive - built to formalise risks only once they are already observed at deployment scale.

DPI-08

Anticipatory Gap Detection

A standing mechanism for flagging emerging risk categories as they appear in a system's observed behaviour, rather than only auditing against a fixed checklist that is, by construction, always one generation behind current capability.

DPI-09

Source-Neutral Technical Layer

A shared evidentiary and risk-assessment layer that sits underneath jurisdiction-specific values choices - compatible with the convergence already happening around ISO 42001 and NIST's process structure, rather than competing with it.

DPI-10

Values vs. Fact Separation

A structural distinction between a jurisdiction's legitimate values choice (expected to vary) and a jurisdiction's factual claim about what a system actually does (which should not vary, and where divergence signals distortion rather than legitimate difference).

The fundable claim isn't "governance should be uniform." It's that the evidentiary layer should converge even where the values layer legitimately doesn't. Every major framework examined here confirms the same lag, independently. The opportunity is not to replace them, but to close the gap they've each already acknowledged.
05 - Implications

Where This Leaves Policy-Makers and Practitioners

For organisations and inquiries examining AI governance today, including the South Australian Royal Commission, the practical takeaway is specific rather than general.

The absence of agentic-specific coverage in NIST, ISO 42001, and the EU AI Act is not a hypothetical future risk - it is a present, measurable, and independently documented gap. Any governance response built now has the opportunity to be anticipatory rather than reactive for the first time in this technology's regulatory history - but only if it is designed around detecting emerging capability, not only auditing capability that has already arrived.

Related reading

This is Part II of a three-part series. See also: Why Capability Doesn't Self-Correct and The Reactive Gap, and the related piece on The Missing Layer in AI Governance.