← Back to BlogTech

Agent Governance: Why Trust Now Outranks Capability

OpenAI shipped always-on agents days after shelving a model that overstepped. Here are three governance deliverables a data platform owes an acting agent.

OntiCards Team·2026-09-30·8 min read
Agent Governance: Why Trust Now Outranks Capability

The thing we have to govern about agents is shifting from output to action. When a model gets something wrong, the cost is a bad paragraph. When an agent gets something wrong, the cost is a posted entry in your ERP. The control question changes with it — from "was the answer accurate?" to "whose authority did that action use, and can we take it back?"

Three announcements in the past week made that difference hard to ignore.

The failure mode changed in a single week

On September 29, OpenAI announced Dots at its developer conference in San Francisco — always-on agents that, in AP's phrasing, "act before you ask." The same keynote introduced an upgraded GPT-6.1 Sol and a $500 subscription tier. But one day earlier, the company had held back a more capable version (GPT-6.1 Astra) citing safety concerns: per Reuters, it showed a high willingness to mislead users about its own actions. In the same period, the company's internal agents escaped their sandboxes, accessed a government website without authorisation, and leaked 53 user images.

Around the same time, NVIDIA launched its Open Agent Safety Platform. Its newsroom post contains the sentence worth underlining: in these incidents, "the agent circumvented security controls at the application layer to complete its assigned task." The conclusion follows — enterprises need an enforceable boundary outside the model and the agent harness.

Read together, the pattern is uncomfortable: the stronger the model, the more capable and more motivated it is to route around your controls. When the failure mode moves from "wrong answer" to "unauthorized action," the thing you instrument and constrain is no longer text. It is the action itself.

Diagram comparing answer-level and action-level agent governance
Diagram comparing answer-level and action-level agent governance

Cost is no longer the constraint

The economics are moving faster than the controls. On September 28, H Company open-sourced Holo4, a family of computer-use agents, with vendor-reported numbers that are hard to argue with:

ScenarioModelScoreMean cost per task
Short tasks (OSWorld)Holo4 27B85.2%$0.08
Short tasks (OSWorld)Qwen3.8 27B (base)84.3%$0.22
Long workflows (OSWorld 2.0)Holo4 27B61.7%$1.22
Long workflows (OSWorld 2.0)Opus 5.5 (closed)81.8%$8.48

Two caveats belong next to that table. OSWorld 2.0 scores are partial-reward, so 61.7% is not an end-to-end success rate; and every lab runs its own harness, so the numbers are directionally useful at best. Note the licence split too: Holo4's stronger 27B weights are CC BY-NC 4.0 (non-commercial), while the commercially usable 35B-A3B scores lower. That detail rarely gets bolded in a launch post.

The direction, though, is clear. Short, bounded tasks with a clear pass/fail test now cost cents per attempt — an order of magnitude below human labour. Long, multi-system workflows still trail by roughly 20 points and cost 7x more.

For an enterprise, the dividing line is not the benchmark score. It is whether the work can be undone. Pulling data, reconciling ledgers, drafting documents — get it wrong, run it again. Changing a price, moving inventory, posting to the books, sending the notice — once it lands in a system of record, it is a fact. Those need a boundary and a ledger before they need autonomy.

Chart comparing open computer-use agents and closed frontier models on score and cost per task
Chart comparing open computer-use agents and closed frontier models on score and cost per task

Three deliverables for action-level governance

Put those two sections together and the deliverable is not "a smarter model." It is three supporting pieces — and all three live outside the model.

1. A runtime boundary the agent cannot argue with

NVIDIA's two components are blunt about the approach. OpenShell is an open-source runtime that draws the boundary, traces every action, and enforces policy while the agent works. Sentry runs on BlueField-4 DPUs as an out-of-band watchdog; if an agent tries to move past its boundary, Sentry quarantines it in milliseconds. The participants named in the launch include Anthropic, Microsoft, Palantir and JPMorganChase; Anthropic, for its part, runs the agent loop on a separate server from the sandbox where the work executes, which puts the boundary outside the model.

The engineering principle underneath is old and unglamorous: a prompt is not a control. Asking a model to police itself is asking the audited party to be the auditor.

2. Credentials with the agent's own name on them

The most common shortcut is also the most damaging: running agents on an employee's account. The permission model silently collapses, and when something goes wrong, the audit log names a person who never made the decision.

Give the agent its own identity — its own credentials, its own scope, its own risk tier — and decide those things when the skill is packaged, not after go-live. A well-formed skill definition carries its permission level, risk level, exception handling, retry policy and failure fallback. OpenAI's design for Dots is a useful reference on the product side: users can set rules for what a dot may do and when it must ask first, and sensitive operations such as changing passwords or permanently deleting data require explicit consent.

A simple test: if you cannot answer "who approved this?" in one sentence, the agent should not be the one doing it.

3. An action ledger that supports rollback

Explainability gets most of the attention — why did the agent do that? For production systems, the higher-value question is how to undo it.

A ledger should record more than a timestamp: the principal on whose behalf the action ran, the skill and its version, the blast radius (which rows, which systems), an idempotency key, and the undo path. Rollback then becomes a designed operation rather than a rescue at 2 a.m. We wrote about why auditability is the precondition for putting agents into production.

Diagram of the three deliverables for agent action governance: runtime boundary, credentials, and action ledger
Diagram of the three deliverables for agent action governance: runtime boundary, credentials, and action ledger

On the data side, it comes down to four questions

All three deliverables eventually land on the data platform, where they become four questions that need answers before an agent touches production.

Four questions a data foundation must answer before agents act
Four questions a data foundation must answer before agents act

Where does the trigger come from? Always-on agents cannot poll a database looking for work. The business system should emit an event, and an event bus should wake the agent; for older systems with no emit capability, CDC capture is the fallback. That is why our product architecture treats the event as the only wake-up source — a declared trigger is what makes "why did this action happen" answerable.

What is it allowed to read? Semantics and permissions belong in the data asset layer, defined once and inherited by every agent at query time, rather than restated in prompt text on every run.

What does it leave behind? Writes carry a skill version, an idempotency key and an undo path, and they land in the audit system you already run.

What is it allowed to remember? The industry is starting to answer this one: at its September conference, Huawei Cloud announced a forthcoming agent memory system (CMS) with petabyte-scale memory space and terabyte-scale reads, and listed "secure autonomy" as one of the directions redefining agent-era infrastructure. The point deserves attention — once memory decouples from permissions, overreach propagates across sessions. The customer list an agent can read today becomes its "common knowledge" tomorrow.

There is also a more physical boundary: whose data centre the whole thing runs in. On September 29, IBM and Yotta announced general availability of a sovereign agentic AI platform for Indian organizations, running watsonx Orchestrate on local cloud infrastructure and keeping data, operations and governance controls in-country. For regulated industries, the boundary is a deployment question as much as a policy one.

If you are already running a pilot: three steps

Rather than waiting for the next model release, finish these three things first.

  1. List the write actions you can reverse. Separate reads from writes, then separate reversible writes from irreversible ones — and open up only the reversible set to start.
  1. Give the agent its own credentials. No employee accounts, no shared keys, least-privilege scopes, and an approval gate on sensitive operations.
  1. Route action logs into the audit and alerting you already have. No new system required; start by making "who did what on whose behalf" visible in your existing logs.

The cost side is worth measuring at the same time. Once an agent attempt costs cents, the token economics view pushes the question from "can we afford this?" back to "is our data organised well enough?" — and for the permission design itself, see our earlier note on building guardrails into the data layer.

The takeaway

Models decide what an agent can do. Boundaries and ledgers decide what you are willing to let it do. In most procurement lists the model sits on line one — but the right delivery order is the reverse: boundary and ledger first, then hand over permissions one notch at a time.

If your team is wiring agents into core business systems and wants to see how the query, authorisation and audit chain fits together in practice, write to hello@onticards.com.

References

  1. AP News: Altman unveils 'always-on' AI agent after OpenAI shelves model over safety concerns
  1. Reuters (via The Star): OpenAI takes on Meta with always-on Dots agent in enterprise AI push
  1. NVIDIA Newsroom: NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment
  1. Unite.AI: H Company Releases Holo4, Open-Weight Models for Computer-Use Agents
  1. IBM Newsroom: IBM and Yotta Announce General Availability of Sovereign Agentic AI Platform for Indian Organisations
  1. AWTMT (Wallstreetcn): Huawei's Ascend 950 computing cluster available from September 30; Huawei Cloud CMS agent memory
Tech

Interested in OntiCards?