The Rules for AI Agents Have Arrived. They Skip the First Question
Something shifted in the first half of 2026. For years, governing AI meant governing what a model says. Now it means governing what a system does.
In January, Singapore’s IMDA launched the world’s first governance framework built specifically for AI agents. This August, the EU gains real enforcement powers over the most capable general-purpose models. Standards bodies are racing to define what a “governed” AI agent even is.
The question everyone is now asking is: how do we keep autonomous agents under control?
It’s the right question. It just isn’t the first one.
The question underneath the question
When a system ranks the job applicants, flags the transactions, drafts the judge’s summary, or decides whose case moves to the top of the queue — a human still signs. But the decision has already been shaped, often before any person sees it. The power to decide didn’t vanish. It moved. It moved into the layer that quietly decides what gets seen, trusted, prioritised, and executed.
I’ve called this condition synthocracy: a world where humans remain formally in charge while the real work of deciding increasingly runs through AI. The new agent rules govern how a system behaves once it is already acting. They under-govern the moment that matters most — the moment a system is let in, and granted the authority to shape a real decision about real people.
Where even the best rules stop
This isn’t a complaint that the frameworks are weak. Singapore’s is genuinely strong: least-privilege access, agent identity, human checkpoints before high-stakes actions. But it deliberately avoids mapping itself onto any jurisdiction’s law. The EU AI Act governs categories of system, not the specific decision to admit one into a specific decision. And for agents in particular, security researchers have flagged what they call an attribution gap — an agent’s authority is often granted at runtime, by its own planning module, with no durable record of why.
So we now have detailed rules for how an agent should behave, and almost nothing governing the decision to let it act at all — recorded, reviewable, reversible.
A question you can use on Monday
You don’t need a framework to start. You need one distinction and a short list.
The distinction: is this system assisting, or co-deciding? A tool that drafts an email is assisting. The same tool ranking loan applications is co-deciding — even if a human signs at the end. Assistance becomes co-decision the moment a system shapes what people see, trust, approve, or never review.
Then, of any system that co-decides, ask:
- Is there a record of why it was allowed to act here?
- Can the decision be explained?
- Can it be appealed?
- Who can override it — and who can switch it off?
If a system is co-deciding and there is no answer to the first question — no record of why it was admitted — the governance failure already exists, independent of outcome. We put it plainly: no record, no standing.
Why we lead with admissibility
This is why the Synthocracy Institute’s first published method isn’t about making AI safer. It’s about what comes before safety.
We call it admissibility: the decision to admit a system to act — made before it acts, on an explicit evidentiary record, open to review and reversal. Safety asks whether a system is good enough. Admissibility asks whether it should have been allowed to act at all: here, with these powers, on what evidence.
We named this pattern before the rulebooks arrived. The 2026 frameworks, in their very gaps, are confirming it: the field is learning to govern the agent — and still skipping the decision to let it in.
That decision is where power actually lives now. Making it visible is what we built the Institute to do.
Read the full method — “Admissibility: The Decision That Comes Before Safety” — at synthocracyinstitute.com.
And if you build, regulate, or study these systems: test it, try to break it, and tell us where it fails. That’s how it earns the right to be used.
— Martin Novak, Founder, Synthocracy Institute