The AI Operating Model: Repeatable Trust
When we shipped a production agent inside the compliance function of a global systemically important bank, everyone was in the room. Compliance, model risk, the data owners, technology. That room is why the agent reached production, and I have recommended it ever since: co design the governance from day one, with every function that could say no helping to build the thing instead.
I wrote that story up in the model was the easy part, and it drew the question that has not let me go since. The first agent gets everyone in the room. Agent twenty does not. What happens to the trust?
The room does not scale
Follow the math. If approval costs a room, and the fleet grows by tens, the institution runs out of rooms long before it runs out of agents. That leaves two endings, and both are familiar. Either governance becomes the queue that every agent waits in, and the institution stalls politely. Or the room quietly shrinks, meeting by meeting, until it is one tired reviewer and a template. The queue is how AI programs die. The template is how rubber stamps are born.
The uncomfortable conclusion is that the thing I recommend for the first agent, the full room, becomes an anti pattern by the twentieth. Not because it stops being rigorous, but because rigor that cannot scale converts into one of those two failures. The trust was real. It was also artisanal, earned one agent at a time, and artisanal does not survive a fleet.
Stop trusting agents. Start trusting patterns.
Aviation solved this decades ago. A regulator does not convene a committee for every aircraft that leaves the factory. It certifies the type. Every airframe after that must conform to the certified type, and an ongoing airworthiness regime watches the whole population for the day reality drifts from the certificate. Nobody calls that lax. It is the only reason air travel scales at all.
Agents want the same move. What earned our first agent its low risk rating was never that agent in particular. It was the architecture around it: a codified procedure, grounded retrieval that could not invent a source, a human holding the decision, an audit trail under every step. None of that is specific to one agent. Certify it once, as a pattern, and the twentieth agent must conform to the pattern rather than re argue it from zero. The knowledge that lived in the room gets written down and becomes enforceable. The room becomes a standard.
The four moves of the operating model
Certify the pattern, not the instance. The governance forum reviews architectures, not demos. An agent built on a certified pattern inherits the certification and answers only for its deltas. An agent that deviates from every pattern gets the full room, and should.
Inherit the standard. A pattern only holds if individual agents cannot quietly diverge from it, which is a control plane question: signed and versioned policy, drift checks, an audit trail that does not depend on the agent's own good behavior. That layer is the one where I have argued we are building the enforcement machinery faster than we are agreeing what it should enforce. It is the floor this whole model stands on.
Renew the approval. A reader put the principle in one line under an earlier post: approval is a state, not an event. A certified agent drifts, its data shifts, its pattern gets updated underneath it. So approval renews at each recalibration, on evidence, or it lapses. The certificate has a heartbeat, and someone watches the monitor.
Supervise the population. Reviewing individuals scales like rooms. Supervising populations scales like software: an inventory of what runs where and on which pattern, telemetry on exceptions, and human attention flowing to the outliers. You watch distributions, not demos. Knowing your agents stops being a metaphor and becomes a register.
What this does to the governance function
It rewrites the job description. The governance function stops being the gatekeeper of projects and becomes the certifier of patterns and the supervisor of a population. That is a promotion, not a demotion. Gatekeeping scales with the size of the fleet, which is a losing race. Certification scales with the number of genuinely distinct patterns, which is small and grows slowly.
I watch the miniature version inside my own fleet. The first agent took weeks, and every rule was argued once. The recent ones cost an afternoon each, and none of the trust had to be earned a second time, because they inherit every control the first one fought for. That is the whole thesis at toy scale. The speed did not come from skipping governance. It came from having governed once, properly, in a form the next agent could inherit.
The test you can run this quarter
Ask two questions of whoever approves your agents. First, how much of the next agent's approval is inherited from a certified pattern, and how much is argued again in a room. Second, when a pattern changes, what forces every approval built on it to renew. If the answers are all of it and nothing, you do not have an operating model. You have a queue with good intentions.
The position I hold
Trust earned agent by agent is an operating expense, and it grows with the fleet. Trust certified as a pattern is capital. You invest once, and every agent after draws on it.
Governance enables trust, and trust enables speed. Repeatable trust is what lets the speed survive scale.