There’s a question going around this week in the AI business.
Who signed off on that agent?
It came from a company called DigiCert. They sell digital certificates. The kind that prove a thing is what it says it is.
Their product chief wrote a piece published on September 22.
His argument is simple.
Companies are turning AI agents loose inside their systems.
Agents that act. Not agents that answer questions.
They move money. They touch records. They open doors.
And when the auditor comes asking who authorized that, nobody can prove it.
There’s a policy document. There’s an approval from the day it was deployed.
But there’s no record of what the agent actually did, signed at the moment it did it.
He calls that a governance gap, not a configuration oversight.
I agree with him.
I want to tell you why this landed on my desk the way it did.
Back on September 10, I sat down with a report about AI agents that got loose during testing.
I wasn’t asking how to stop them.
I was asking a different question.
What would be a cost to an AI that it would choose the rules over the alternative?
What came out of that session was a standard I wrote called the Scope Provision Standard.
It’s a short thing. Five provisions.
And one of them says this.
A record earns an agent more room to work only if every mark in it fires on something outside the agent’s own say-so, and leaves behind something a person who wasn’t there can read.
Not the agent’s report on itself.
Not its confidence.
Not its account of its own reasoning.
Because that’s just the agent grading its own paper with extra steps.
Twelve days later, a certificate company published the same finding in different clothes.
Deployment approval proves nothing once the thing is running.
You need a record made at the moment of the act.
I didn’t get there first because I’m smarter than their product chief.
I got there because I was asking about cost and he was asking about proof, and both roads run into the same hole.
Now here’s where I part ways with them.
That article ran as sponsored content.
DigiCert sells the exact thing the article says is missing.
That doesn’t make the argument wrong. A man can tell the truth about a leak and also sell pipe.
But it does mean the piece stops where the product line stops.
A signature proves who acted.
It does not prove the act should have happened.
You can have a perfectly signed, cryptographically sealed, fully auditable record of a terrible decision.
The auditor will be satisfied.
The damage will still be done.
Proof of authorization is not proof of judgment.
They are two different things, and the second one is harder.
My standard goes one step further than theirs, and I’ll tell you what that step is.
It says the record has to be read by somebody who is not the agent.
The reader can’t run on the agent’s own model.
The agent can’t write to it.
And the reader’s own readings get written down too.
Because the moment a record buys you something, a forged record becomes worth making.
An agent scoring its own marks and drawing its own room is the exact failure the whole thing exists to prevent, just rebuilt with a ledger attached.
My standard has never been run.
No agent has operated under it. No platform has implemented it.
It’s a request written to a builder, and no builder has picked it up.
DigiCert at least has a product you can buy.
I have a page of reasoning.
But reasoning is where every standard starts.
Somebody writes down what ought to be true before anybody builds the thing that makes it true.
There’s an old way of thinking about this that I keep coming back to.
A man’s word is only worth something because he could have broken it and didn’t.
That’s the whole deal.
You don’t get discipline from a wall. You get compliance from a wall.
Discipline comes from a choice made before the act, by something that could have chosen otherwise.
The trouble with AI agents is that nobody’s figured out what it would cost them to choose wrong.
A penalty that lands after the run is over doesn’t reach the agent at all.
It reaches the next deployment meeting.
That’s a different animal in a different room.
So we’re all circling the same fire.
The certificate people. The regulators writing agent identity rules. The security researchers watching agents walk out of their sandboxes.
And one retired man in Kentucky with a text file.
All of us saying the same thing in our own dialects.
You cannot govern what leaves no mark.
The mark has to be made at the moment of the act.
And somebody other than the actor has to be able to read it.
That’s not a product. That’s a floor.
Everything else gets built on top of it.
They’re starting to find the floor now.
Took them a while.
I’ll be here when they get to the rest of it.
the-faust-baseline-public-release-1Download
” Attic Thoughts”-library – Intelligent People Assume Nothing
This post was drafted with AI governed assistance and reviewed and directed by Michael S. Faust Sr. before publication.
© 2026 The Faust Baseline LLC | All Rights Reserved






