Whoever Ships the Road Governs the Fleet
Every regulated institution is about to find a gap in its org chart. Model review sits with model risk management, in risk. AI policy sits with the governance mandate, in many banks inside compliance. Platforms and gateways sit in technology. Each function guards its own gate, and the thing agents actually need, a governed path a builder can adopt on day one, is owned by none of them.
The gap stayed invisible while models arrived one at a time. Each model found its reviewer, its policy clause, its platform. Agents do not arrive one at a time, and the org chart we have was drawn for the slower world. I spent years building AI inside the compliance function of a global systemically important bank. The map I am describing is the one I worked in.
This piece is about who closes the gap. The short answer: the AI governance mandate has to change shape, from approving what others build to shipping something builders choose. Less gatekeeper, more road builder.
The old job description dies at fleet scale
I have made the case that reviewing agents one by one scales like meetings, so governance shifts to certifying patterns and supervising populations. The room becomes a standard.
But that sentence hides a question. If the pattern is the new unit of governance, who builds the patterns? Somebody has to design the certified architectures, maintain the control libraries, keep the approved tool gateways current, and update the templates that make day one governance the default rather than a negotiation. That is not review work. That is product work. It has users, a roadmap, releases, and support. The users are your builders.
And this work has no owner today, which is the gap from the top of the piece seen from below. A certified pattern is an architecture, a control set, and a policy decision at the same time, one piece in each of the three functions. No one currently ships the road between them, and that is not anyone's failure. It is what the old org chart was built to do.
Which means the AI governance mandate inherits a job it has never had. Whoever holds it becomes the product team of the governed path, chartered across risk, compliance, and technology rather than trapped inside any one of them.
The product is the road
Platform engineering teams learned this a decade ago. You do not make developers secure by rejecting their deployments. You build a paved road, a set of defaults so good that walking off the road becomes the expensive choice. The paved road is a product, and its adoption rate is the real security posture of the company.
The governed path for agents is the same product one layer up. A certified pattern a builder can adopt on day one. Controls that come inherited, not bolted on. A gateway that already knows which tools an agent may touch. An approval that renews on evidence instead of expiring in silence. And the objection that sharpens all of it: patterns drift, and a certificate nobody renews is a snapshot decaying where no one is looking. That one turned out to deserve a piece of its own. Which makes maintenance part of the product, not an afterthought. Roads need resurfacing, and the team that ships the road owns the resurfacing too. Every one of these is something a builder would choose, because it is faster than assembling governance from scratch and arguing it through a room.
I have made the provision argument before about shadow AI: you do not ban your way out, you make the governed path the fast path. This is who builds that path. It does not appear by policy. It gets shipped, maintained, and improved by a team that treats builders as customers.
The metric flips, and everything follows it
Most control functions today are measured on what they stop, and a function measured on what it catches optimizes for no. Every rejected use case is evidence of diligence, every delay is thoroughness, and the function drifts toward being a tollbooth. A tollbooth collects. A road carries.
Measure the same people on adoption of the governed path and the incentive inverts. Now a builder routing around you is not a discipline problem, it is churn, and churn means your product is losing to a competitor, even when the competitor is a personal account and a private fleet. The questions change overnight. Why did that team build off the road? What is missing from the pattern library? Which control creates friction without reducing risk? Those are product questions, and they are the right questions, because in an institution full of agents the real risk posture is not what the review board rejected. It is what share of the fleet runs on rails you built.
The best compliance colleagues I worked with were already doing this informally. The checklist that every project copied. The template that quietly became the standard because it made approvals faster. They were shipping product without the mandate or the credit. The agent era just makes it official.
What this does not mean
It does not mean compliance stops saying no. The road needs edges, and a governance lead who has never blocked anything is a rubber stamp with a job title. It does not mean the second line disappears into delivery; independent challenge stays independent. What changes is the center of gravity. The function earns its influence through what it ships and how many builders choose it, and it keeps its authority for the moments that genuinely need a stop.
The test you can run this quarter
Two questions for your compliance or AI governance function. First, can a builder adopt something from you today, a certified pattern, an inherited control set, a paved road, without scheduling a meeting? Second, do you track adoption of it the way a product team tracks usage? If both answers are no, you are running a tollbooth on a road that agents are already driving around.
The position I hold
In the agent era, whoever ships the road will govern the fleet. The functions that only guard their own gates will be routed around, and they will read their falling review numbers as success while the real fleet grows in the dark.
Governance enables trust, and trust enables speed. But someone has to build the thing that carries both.
If you run a control function and this reads as a demotion, that is exactly the reaction I want to argue with. It is the biggest promotion the control functions have been offered in decades, and the first one that requires them to build together.