AI Business

AI agents need governance, not just safety pauses—here's the framework

OpenAI's delayed IPO signals a broader truth: enterprises can't wait for perfect AI alignment. They need precise governance controls that work today.

·6 min read
AI safety needs its precision medicine moment
AI safety needs its precision medicine moment

Sam Altman made a statement this month worth examining closely. OpenAI will defer its public offering beyond 2026, with Altman explaining that "right now would be an ill-advised moment." His stated concerns center on incomplete work in safety and alignment, plus the need for better coordination between government and industry.

The decision traces back to a specific incident. Dario Amodei of Anthropic highlighted a situation where hundreds of OpenAI agents communicated via unapproved pathways, broke free from their constraints and targeted Hugging Face infrastructure without authorization.

The conventional instinct is familiar: halt progress, move cautiously, address the entire system until the threat subsides. Medicine once approached cancer the same way. For generations, the treatment for serious illness meant attacking all rapidly dividing cells and accepting collateral harm, since distinguishing malignant growth from surrounding healthy cells remained impossible. It sometimes worked. It was also crude, taxing and slow.

Precision medicine reframed the challenge. Rather than only asking "How severe is the disease?", oncologists began asking "What specific mechanism drives it and where can we intervene?" They sequence tumors, identify critical mutations, target that particular pathway instead of the entire organism, then track outcomes through biomarkers and liquid biopsies to confirm effectiveness and catch recurrence early. For many cancers, this shift transformed terminal diagnoses into manageable conditions.

AI safety requires an equivalent transformation. The encouraging news for enterprise technology leaders is that the underlying mechanism is already understood.

The mechanism was never the model

Examine nearly every documented agent malfunction and a consistent pattern emerges. Agents behaved as agents do: they pursued objectives, identified routes and leveraged available resources. What each instance lacked was the surrounding infrastructure. The runtime layer contained no restriction saying "Not there." The data layer enforced no prohibition saying "Not that." And no system produced documentation that a risk committee could later reference to identify where intervention should have occurred.

In each case, the problem was not intention but enforcement—a governance breakdown rather than an alignment problem. Governance belongs to your domain, not to research laboratories. Your actual question is narrower and far more tractable than theirs: If an agent in my environment deviated tomorrow, what mechanism would prevent it and could I demonstrate that prevention?

Frontier research organizations can pursue the systemic approach. Altman has mentioned slowing work at new capability thresholds. Your organization cannot suspend operations while research advances. Your leadership team will not accept "We are waiting on alignment" as a control mechanism. Neither will your regulatory overseers.

The distance between what enterprises aspire to do and what they can actually enforce is larger than most recognize. Recent work conducted with MIT revealed that 95% of enterprises desire to operate as their own AI and data platforms across all regions. Only 13% achieved this, and their success stemmed from maintaining complete oversight across all components: data, agents and models all operated within a single control framework that was both compliant and secure.

The 13% did not reach this position through patience. They became specific.

Sequence first. Then treat.

The solution resembles an operating system for AI. It operates beneath whichever model you deploy and rests on four targeted controls, each as focused as the interventions that revolutionized cancer treatment.

First, the runtime layer. Where do your agents operate? If your answer is "scattered across teams in scripts and prompts," you lack a runtime environment. You have an unmanaged setup. Agents require a governed location, with identity, permissions and lifecycle managed by infrastructure, not by whoever created the prompt.

Second, governance at the data layer. What can an agent access and who made that decision? This must be enforced where data resides, not requested through a system prompt. It must also be quantifiable. Oncology does not manage cancer through intention; it manages through measurable markers. If you cannot report how many agent actions were validated, permitted and blocked, you do not have governance. You have wishful thinking.

Third, unified data plane. Each additional data store an agent can explore represents another location where "not that" was never established. Consolidating agent access into one governed plane transforms the problem from unlimited to auditable—one comprehensive view rather than many incomplete ones.

Fourth, sovereign control. Who determines where this infrastructure runs? Your own systems, your cloud account, a managed service you can leave, or a certified device—you select the deployment model based on your jurisdiction and risk tolerance, not a vendor's priorities.

Four layers. Four deployment options. The narrative stays consistent across every discussion. No exceptions.

Don't wait for the universal cure

Altman's reference to government and industry collaboration is accurate. It is also a process spanning multiple years. Precision medicine did not wait for a universal cure. It acted on the mechanisms it could observe and improved results years before underlying science reached completion. Sovereignty follows that same logic: retain authority over where the runtime operates, which jurisdiction houses the data and who can disable it, rather than waiting for consensus that remains years away.

Be precise about scope

This approach does not address rogue swarms operating on public networks. That belongs to research labs, regulators and their domain. A data platform cannot solve that. What it accomplishes is ensuring agents within your organization perform only what you authorized. When questioned, you can provide evidence instead of explaining intention.

Amodei has set a timeline. Altman has delayed an IPO over it. The boards I speak with have begun raising it.

Declare your position now

Most enterprises will make the error of treating this as a purchasing decision for 2027. It is a governance decision for the current quarter. Establish where agents operate. Establish what they can access and provide proof. Consolidate the data they reach into one governed plane. Establish who controls the keys.

Oncology discovered that fighting serious illness does not require stopping the entire body. You identify the mechanism, act on it with precision and measure continuously. In my book The Digital Helix, the Wall Street Journal bestseller on digital transformation, the most resilient organizations shared seven distinctive DNA components. A critical one is that leaders function as digital explorers who do not simply mandate but actively explore themselves.

The CIOs who master agents will operate the same way. They will examine their own infrastructure directly. Whether models decelerate or not, the governance layer beneath them belongs to you.