Langlotz.AI
Governance

AI Has Control Planes. It Still Does Not Have a GAAP.

· 1101 words

AI governance has a fast-growing enforcement layer and no agreed standard to enforce. We are building the auditors before we have written the rules.

The enforcement layer is real and impressive: a new category of AI control planes that monitor agents in real time, capture evidence as decisions happen, and apply rules at runtime. The direction is right. Governance does eventually have to live in the execution path.

But watch what these systems actually enforce, and a quieter problem appears. Each one applies whatever definition of "governed" its builder or its customer brings. We are building the machinery to enforce standards faster than we are agreeing on what the standards are.

In accounting, we would never accept that. You do not run an audit without GAAP.

We are not starting from nothing

To be fair, AI governance is not a blank page. We have serious work already in place. ISO 42001 gives organizations a management-system standard. The NIST AI Risk Management Framework offers a thoughtful structure for identifying and managing risk. The EU AI Act puts real obligations behind high-risk uses. I am glad these exist. They are genuine progress, and anyone working in this field should build on them rather than around them.

But it helps to be honest about where on the maturity curve they sit. They are largely principles and frameworks: what to consider, what good practice looks like, which risks to weigh. What they do not yet provide is the thing GAAP provides for accounting: a detailed, operational standard precise enough that two institutions, applying it to the same situation, reach comparable answers.

That gap matters most exactly where AI is heading: autonomous agents that make and shape decisions. Ask a simple question across three banks today, what counts as adequate evidence that an agent's decision was sound, and who is accountable when it was not, and you will get three reasonable answers. None of them wrong. None of them comparable. In the years I spent putting AI into production inside a regulated function, the recurring blocker was never the model. It was the absence of a shared, defensible answer to exactly those questions.

A control plane is only as good as the standard beneath it

This is not an argument against the control planes. It is an argument about what they stand on. Give a control plane a mature, shared standard and it becomes genuinely powerful: it enforces something defensible, and a board or a regulator can compare one institution to another. Give it only each organization's own interpretation, and you get governance that is internally consistent but not comparable, which is precisely what oversight cannot rely on.

The risk is easy to miss, because it does not look like failure. The dashboards are green. The evidence is captured. The system looks governed. But underneath, the definition of "governed" is improvised, and improvisation does not survive a regulator's question or a bad outcome examined after the fact.

How accounting actually solved this

The accounting analogy is worth taking seriously, because accounting solved this exact problem, and it did not solve it overnight. Before GAAP, companies kept books by their own conventions. Audits existed, but an audit only means something once there is an agreed standard of what "correct" is. GAAP did not arrive fully formed. It matured over decades, from broad principles into the detailed, enforceable, comparable system we now take for granted. The enforcement ecosystem grew on top of the standard, not before it.

AI governance is early on that same journey. We have the first principles in ISO 42001, NIST, and the EU AI Act. We have an enforcement layer arriving fast in the control planes. What we do not yet have is the mature middle: the operational, citable standard that makes enforcement mean the same thing everywhere.

What closing the gap actually looks like

It would not take another high-level framework. It would take something more concrete and frankly more boring: agreed, citable answers to the questions practitioners actually face. What constitutes adequate evidence for an agent's decision. Who holds accountability when an autonomous system acts. What "human oversight" means in operational terms when no human can review every action. How to make one institution's governance comparable to another's, so that "we are governed" becomes a claim that can be checked rather than asserted.

This is unglamorous work. It is also the work that turns a field of opinions into a discipline.

And it has to be neutral. GAAP is not written by the companies it governs or the vendors who sell into them, because a standard that serves a particular interest stops being a standard. The same will hold here. A definition of "governed" that comes from a tooling vendor will, however unintentionally, describe that vendor's tool. A definition that comes from gut feel cannot be cited or compared. The maturity we are missing is not just detail. It is independent, citable detail that everyone can point to.

This makes the field faster, not slower

The fair objection is that this sounds slow, and AI is not slow. The opposite is true. A shared standard is what lets a field move fast without fragmenting. When consultancies, internal teams, regulators, and the control planes all work against the same reference, no one has to reinvent the meaning of "governed" for every engagement. Governance builds trust, trust builds speed. The standard is not the brake. It is what lets everyone accelerate in the same direction.

The question worth asking

So if you sit on a board, run a function, or write the rules, the question is not "do we have an AI governance tool." It is "what standard is that tool enforcing, and could another institution check our answer against it." If the honest reply is "our own," you have just found the maturity gap inside your own house. More tooling will not close it. A shared, defensible standard will.

This is the gap that pulled me into a new project. Partha Roarke came to me with a simple observation: the hard part of AI was never the technology, it was giving the people with real accountability something solid to stand on. That became Fourth Order Labs, an independent effort to help mature the reference layer that the control planes, and the boards above them, can point to. Some of that is definitional, what "governed" actually means for an agent. Some is practical, a living map of how the standards we already have apply in real situations, so teams work from something current instead of reading principles and guessing at implementation. We are early, and there are gaps in our own thinking too.

So I will end where the field actually is. We have started building the auditors. It is time we finished writing the GAAP. I would genuinely welcome your hardest questions on how.