This insight summarizes The Governance Harness, a technical white paper (v1.0, August 2026) from Verified Digital Agents (Rawson Consulting B.V., Amsterdam) aimed at boards, CISOs, CTOs and AI platform leads.
The gap is accountability, not capability. Deloitte's April 2026 survey of 3,235 leaders found only 21% have a mature governance model for agentic AI. Gartner predicts 40% of enterprises will demote or decommission autonomous agents by 2027 over governance gaps discovered after production incidents. Less than 2% of the $2.59 trillion 2026 AI spend goes to AI cybersecurity.
Deferred is not cancelled. Regulation (EU) 2026/1744 pushed the EU AI Act's high-risk regime to 2 December 2027 for Annex III systems and 2 August 2028 for embedded ones — but Article 12 (automatic event logging), Article 14 (effective human oversight) and Article 26(6) (six-month log retention) are unchanged. Article 50 transparency obligations are live now. Fines cap at €35m or 7% of worldwide turnover, with a separate tier for supplying misleading information to regulators.
Travel already has precedent. Moffatt v. Air Canada (2024) rejected the argument that a chatbot is a separate legal entity — the deployer is liable. That doctrine now applies to systems that act, not merely speak.
What the framework adds. Every agent harness has three empty slots — rules, events, and authority. The paper's answer is C2MD (machine-evaluable controls), ACP (governance-as-code signed bundles), HITL (authority, not a rubber-stamp button) and Witness — an Ed25519-signed, hash-chained record externally anchored to Sigstore Rekor so evidence is provable even against the operator.
Board takeaway. Do not ask "do we govern our agents?" Ask "show me one sealed decision, and show me an outside party verifying it without our help."