who answers for it

Nobody is asking for an agent that never fails. They're asking who answers when it does.

Everything on the previous page is an engineering account. This isn't one.

Two forces are converging on the same demand, from opposite directions and on different clocks. One is financial and already in effect. The other is regulatory and still approaching. Neither is asking for a perfect agent. Both are asking a question the field, as currently built, cannot answer.

01

The clock isn't technical anymore. It's financial, and it's regulatory.

The insurers aren't waiting for legislation. Major carriers (AIG, Great American, WR Berkley) have filed exclusions with state regulators that carve AI risk out of standard policies; one proposed bar sweeps in "any actual or alleged use" of AI. And unlike a statute, an exclusion needs no phase-in. It takes effect at your next renewal. The standardized forms went live at the start of 2026. The coverage is being pulled now, before a single regulator acts.

The regulators are moving the same way, on a longer clock. The EU AI Act's transparency rules take effect in August 2026, but its high-risk requirements, the ones that demand you show why an autonomous system did what it did, governing the very uses a financial institution lives on (credit scoring, insurance pricing, employment decisions), were deferred under the 2026 Omnibus agreement to December 2027, with product-embedded systems following in 2028. The date moved. The requirement didn't.

Notice what neither pressure is actually demanding. They aren't asking for an agent that never fails. Everyone knows that's not on offer; agents will sometimes act on rules no one declared. They're asking a different question: when something happens, who answers for it? The provider? The vendor who embedded the agent? The enterprise that deployed it? That question has no answer without a factual record of what the agent did and what it was authorized to do, and a record assembled from probabilistic estimates is not a record anyone can stand on.

The field has named what's missing: not a perfect gate, but a verifiable account. It just hasn't built it.

That demand is already shaping behavior, before a single penalty is issued. Across industries, organizations that want what agentic AI offers are holding back, not because the technology can't help them, but because they cannot answer for it. The cost of the accountability gap isn't only a future fine. It's the value left on the table today by every business that can't safely say yes.

02

A guess is not something two parties can settle.

Consider how a credit card charge gets resolved. A charge in New York and another in Seattle an hour apart is not a matter of opinion. It happened or it didn't, and both sides can see the same record. That binary certainty is not a detail of the credit system. It is the thing the entire system is built on. Imagine the alternative: you dispute a charge, and the answer comes back, "our model has determined this was you, the balance stands." No one would carry the card. The market exists because the record is fact, not estimate, and because a fact is something two parties can actually stand across a table and settle.

Agent behavior has no such record. When an agent runs through the weekend and returns a bill for fifty thousand dollars of tokens on work a person would have done for two, the enterprise has no factual account to point to. Not whether the actions were authorized, which they may well have been, but what was actually done, step by step, at what cost. There is only the vendor's own tally and the customer's own anger. You signed the agreement, so you are on the hook. The friction has no floor to land on. This is not hypothetical. Companies are already moving to cap agent spending after autonomous tools ran through budgets no one had modeled.

A complete, deterministic record changes what is possible, not by judging the agent, but by making the facts real. It records every action the agent took, the way a transaction log records every use of the card: not the intent, not whether it was wise, just what happened, the same every time, open to inspection. Whether an action was out of bounds, or in bounds but wasteful, or looping without ever arriving, becomes a question that can be examined against a record both sides trust, rather than a guess neither can verify.

That is the precondition for every conversation the field now says it needs. Whether standards, contracts, or resolution frameworks for agent behavior turn out to be feasible, beneficial, or required is a discussion worth having. But it is a discussion that cannot even begin on a foundation of reconstruction. It begins on a record. The field has been trying to hold the conversation without building the floor to hold it on.

03

It is the same accountability you already demand from everyone else.

Strip away the specific regulation, the specific auditor, the specific board question, and they all reduce to one requirement: a complete, faithful account of what every agent did, and why each action was permitted.

This is not a new or exotic standard. It is the same accountability you already expect everywhere else in your organization. You expect it from your executives, who must answer for their decisions. You expect it from your employees, whose work is reviewable. You expect it from your vendors, who are held to their contracts. No one in your organization gets to say "I can't tell you exactly what I did, but it was probably fine" and keep their seat.

Yet that is precisely what the current approach to AI governance asks you to accept. A record assembled from estimates, scores, and a model's own narration of its reasoning is exactly that answer: a best guess about what likely happened. AI has become the only actor in your organization held to a lower standard of accountability than the people and partners around it, not because anyone chose that, but because the tools built to govern it can only estimate, never account.

Two roots, and only one of them is ours to solve.

The first is that these systems are probabilistic. That is not going away, and nobody serious is claiming otherwise. An agent will sometimes act on a rule no one declared. We are not selling a fix for that, and you should be wary of anyone who is.

The second is that when it happens, nothing can be settled. Not attributed, not priced, not defended, not disputed. Whether the failure belonged to the model, the architecture, or the operator is a question with no available answer, because the record required to answer it was never kept.

Every pressure named across these two pages reduces to the same requirement. The carrier writing the exclusion, the regulator drafting the rule, the auditor asking the question, the board member who has to sign, and you, sitting with a bill you can't characterize. None of them need a perfect agent. All of them need certainty about what was done, and proof it was allowed.

That is the one thing the field's entire approach structurally cannot produce.

We built it.