September 4, 2026 · Artificial Intelligence · AI Governance · AI Security · AI Safety · Agentic AI · Cybersecurity · Responsible AI

When AI Can Act, Governance Must Move to Runtime

I watched the steering wheel turn, but there was no one sitting behind it.

Last week, while attending AWS PartnerEquip: Live in San Francisco, I spent three days immersed in conversations about how enterprises are moving AI from experimentation into real-world applications.

Then I stepped outside my hotel for a walk and watched that transition take physical form in the traffic around me.

A Waymo autonomous vehicle approached, turned through the intersection, and continued on its way.

But what caught my attention was not merely the empty driver’s seat. It was where decision authority had moved:

From human hands to software.

The system was not generating a recommendation for someone to review. It was sensing its environment, interpreting conditions, making decisions, and executing them in real time.

That changes the governance question.

When an AI system produces a draft or recommendation, a human may still have the opportunity to review it before action is taken.

But when AI can execute code, initiate transactions, change infrastructure, communicate with other systems, or navigate the physical world, governance cannot stop at policies, risk assessments, and pre-deployment reviews.

It has to operate at runtime.

Organizations must be able to answer:

What constrains the system when conditions are uncertain? Where does meaningful human oversight reside when no one approves every individual action? Can its decisions be reconstructed after the fact? And what evidence demonstrates that its controls worked during execution, rather than simply that they existed by design?

This is the shift enterprises must prepare for as agentic AI moves from assisting humans to acting on their behalf.

Perhaps what stayed with me most was how ordinary it all looked.

One autonomous vehicle passed.

Then another.

The extraordinary was becoming routine.

And that may be when governance matters most: not while autonomy is still novel, but when we trust it enough to stop noticing it.

The closer AI gets to action, the closer governance has to get to runtime.

All of this leaves us with two broader questions:

What happens when decision authority moves from human hands to software?

And as organizations delegate more decision authority to AI, what evidence should they require to demonstrate that runtime controls are actually working?

#AIGovernance #AISecurity #AISafety #AgenticAI #Cybersecurity #ResponsibleAI

Originally published on LinkedIn on September 4, 2026.

View the conversation on LinkedIn

Back to Insights →