Agent Governance Has to Run Before the Agent Does
Most AI agent governance arrives as a policy document that never keeps pace with deployment. A more durable model treats governance as an operating discipline compiled into the agent from the first interaction: an executable constitution the agent reads every time, hash-signed skills, and a three-lines control structure that maps to ISO/IEC 42001, the NIST AI RMF, and the EU AI Act. Here is how a regulated security team is putting it into practice.