Insights · AI Governance · Agentic

The AI Just Got a Keyboard. Your Governance Wasn't Written for That.

Frontier models now operate real interfaces, and the vendors themselves tier capability by authority. Five questions decide whether an AI-influenced action is defensible.

By Matthew Bertram · President of ModalPoint, CEO of EWR Digital · September 2026

For three years, every AI governance conversation I've had with an executive team has really been about one question: what did the model say? Was the answer accurate, was it biased, did it leak something, can we put it in front of a customer. Whole policies, whole vendor categories, whole compliance binders got built around the AI as a thing that talks.

This month made that framing obsolete. Frontier models now operate real interfaces. A terminal. A browser. A keyboard and a mouse. OpenAI's Astra was designated Critical for cybersecurity under its own Preparedness Framework, the first model at that level, and OpenAI's description is worth reading slowly: with the right tools and access it can find previously unknown security flaws and develop exploits "without a person guiding each step." Access to its most advanced capabilities is gated to approved defensive users. Anthropic, in the same season, split its frontier model into two products: one generally available with additional safety measures, one trusted-access for approved organizations.

Think about what that means for a minute. The vendors themselves are now tiering capability by authority. Which means the question your records have to answer is no longer just which model you used. It's which authority that model held when it acted for you.

An employee, not an oracle

The AI in your company is becoming a digital employee. Not metaphorically. It reads the inbox, opens the CRM, runs the script, edits the page, sends the message. And the moment an AI can act on enterprise information rather than merely read it, governance stops being mostly about what the AI said and becomes five questions:

  1. What was it authorized to see?
  2. What was it authorized to decide?
  3. What was it authorized to do?
  4. Who approved that authority?
  5. And can we reconstruct exactly what happened afterward?

Notice these are exactly the questions you'd ask about a human employee who did something consequential. That's the point. We have a century of management practice for delegated human authority: job descriptions, approval chains, access badges, audit trails. Almost none of it has been extended to the agents, and the agents are already working.

We failed our own test, which is how I know the bar is real

Here's the part I'm not proud of, and it's exactly why I trust the framing.

This summer, my own agency discovered that 59% of our website's analytics sessions over a thirty-day window, 2,857 of 4,825, were our own AI audit agents. Headless browsers our tooling launched, over and over, for ten weeks. They executed JavaScript, loaded our analytics tag, and reported themselves as ordinary Chrome users, because that's what they were: browsers, operated by software instead of a person. Our traffic looked like brand strength. Dozens of pages read as engagement disasters. Every journey analysis for a quarter inherited the skew, and the platform has no way to remove it retroactively.

Now run that little incident through the five questions. What were our agents authorized to see? Everything, nobody had written it down. Authorized to do? Load any page, any number of times, visible to any measurement system, because nobody had decided otherwise. Who approved that? Nobody, which is the honest answer at most companies. Could we reconstruct what happened? Eventually, yes, from forensics, not from a record that existed on purpose. That's what a governance gap looks like in practice: not a rogue model, just delegated capability with no delegated accountability, compounding quietly at a couple hundred sessions a day.

Ours cost us a clean dataset. The same gap, pointed at customer data or an outbound mailbox or a production config, costs more.

The record has to run one step further

If you already run a decision-governance discipline, the good news is that nothing about it gets thrown away. The five questions map cleanly onto the four pillars of Digital Information Governance®: provenance covers what the agent could see, traceability covers what it could decide and who granted that, representation integrity covers what it could do in the company's name, and audit readiness covers whether the whole thing can be replayed. The pillars hold. The record simply has to run one step further, from the decision to the act: tool calls, commands, page loads, approvals, end to end.

If you don't run any of this yet, don't start with a framework. Start with an inventory, this week, of every place software acts on your systems with borrowed authority: the AI assistants with mailbox access, the audit tooling, the schedulers, the agents your vendors run against you. For each one, try to answer the five questions from records you already have. Where you can't, you've found the work. When we did this exercise honestly, the list was longer than anyone in the room expected, and the answers were thinner.

Regulators, for what it's worth, are moving on their own clock. Under the EU AI Act, event logging and human oversight are already legal duties for high-risk systems, and even with the 2026 Omnibus pushing the main high-risk deadlines to late 2027 and 2028, a deferred deadline is not a deferred risk. Agents are being deployed now. The record either exists when the question comes, or it doesn't.

The AI got a keyboard. Give it a personnel file.

The reference version of this framework, including the five-questions mapping and an agent-incident register, lives at digitalinformationgovernance.com. The full forensic write-up of our analytics incident is publishing separately.

Statutory and regulatory text is the controlling authority; nothing on this page is legal advice. Consult qualified counsel for any specific compliance question.

Related reading

This thinking is also a keynote.

Matthew brings this to mainstage keynotes and closed-door board briefings. matthewbertram.com/speaking  ·  More insights

Book a keynote →