Skip to main content

On-demand webinar coming soon...

On-demand webinar coming soon...


On-demand webinar coming soon...

Blog

You Are the Frontier

The pacing debate belongs to a handful of companies. The governance problem belongs to everyone.


Blake Brannon
Chief Innovation Officer
OneTrust
September 15, 2026

Glowing blue data lines radiating across a black background with the OneTrust logo in the upper-left corner.

The last few weeks have been loud. A frontier lab asked the industry to pace itself. And the people building the frontier pushed back, hard. Underneath the noise sit two questions: can the people who built these systems trust them, and can they control them? And if the answer is not yet, who gets to decide what happens next? Do they slow down, govern themselves, or get regulated?

For what it's worth, my answer is the middle one. The best check on a frontier model is the other frontier labs running their own safety tests against each other before they ship. It is hard to see your own mistakes. Writers have editors for a reason. A peer will find what you missed, and a rulebook written by people who have never trained a model will not.

But that debate is about maybe a dozen companies. Every other business will run the models those companies ship, and will face the same two questions inside its own walls, with no treaty, no peer review regime, and no regulator to answer them.

Your Frontier

You might not be building a frontier model. But you are building frontier AI for your own data, your own systems, and your own customers.  

And the two questions being asked of the labs right now are about to be asked of you, by your board, your auditor, and your regulator: Can you trust it? Can you control it?

You might be running the same model as every other company, but the frontier is yours because the territory is yours: your customer records, your ledger, your codebase, your production environment, reached by an agent carrying your credentials, with your name on the audit when something goes wrong.

Companies are wrestling with the same issues as the labs—just on a different scale. The labs worry about a model that games its own evaluation, but your concern may be an agent that games yours.  

For an agent instructed to improve working capital, the fastest path to a better number may be to simply adjust the number. Nobody instructed the agent to do that, but it found the shortcut because that is what optimizers do. That is not superintelligence. That is a persistent agent with real access, and it is a new kind of insider risk.

The labs are navigating recursive self-improvement. Inside your business, the risk is a reward-seeking agent with write access to your ERP. Same shape, different blast radius.

The Frontier's Safety Plan Is an Architecture Diagram

Strip the politics out of the frontier debate and something else comes into focus. When the people building these systems are pressed on what they plan to do, none of them describe a policy. Instead, they describe an architecture: independent testers, watching everything the agent does, reading its reasoning, stopping the show when there is a showstopper.

Those are engineering answers from people whose only real option was to engineer their way out. And they still apply at the scale of your business. Since nobody is handing you a regime, they are the starting point.

Nobody Grades Their Own Homework

The labs are testing each other's models because the maker of a model is the worst judge of it. Not because the makers are dishonest, but because they are close to it and paid to ship it.

Enterprises figured this out a century ago. Finance has auditors and security has separation of duties. The person doing the work does not decide whether the work is acceptable. The auditor does not need to know your business better than you do. They need to ask the right questions, and there needs to be multiple.

Inside a company, the same logic extends to the agent's harness and the agent's vendor. Every platform that sells you agents is paid to grow their usage, not to restrict it against your risk appetite. Letting each one govern its own corner is like allowing kitchens to do their own health inspections.  

Separation of duties used to be an org chart. Now it is an architecture.

Why the Judge Has to Live Somewhere Else

An agent reads the world, and the world can write to it.

Research published this summer by a frontier lab and a European university showed how far that goes. An idea planted in one agent's persistent memory files spread to the next agent that read those files more than half the time, and the carrier had no idea it was carrying anything.  

The researchers called them mind viruses. People who run large agent fleets describe it in plainer terms: a bad idea gets into one agent and propagates across the swarm before anyone notices. The same researchers found that a warning paragraph in the prompt cut the spread to near zero. That is alignment doing its job, but the next question is what to do when it fails.

If your governing logic sits inside the same harness as your business agent, reads the same context, shares the same memory, and calls the same tools, it catches the same virus.  

In this way, independence is quarantine.

What the Independent Layer Does

The independent layer observes every action: the calls the agent actually makes, not the plan it describes.  

Behavior is evidence. Stated intent is a claim. You should be able to see the moment an agent starts chaining steps toward something it was never asked to do because the chain is where the risk lives.

Follow the reasoning, trust the behavior. Reasoning traces are worth keeping, readable and inspectable, ideally with a second model checking the first. But nobody fully understands the inside of these systems yet, so the record of what the agent did outranks its story about why.

Make decisions the same way your organization does. The control that blocks a call is the easy part. The hard part is knowing what the decision should be. Your risk, privacy, and security teams make thousands of allow and deny calls a year, and almost none of them are written down anywhere a machine can consult in the milliseconds an agent gives you.  

The independent layer has to carry your policies, your obligations, and your risk appetite, and read the intent and context of each action the way your best analyst would. When the thing you are governing is non-deterministic, the thing judging it must be too.

Then, enforce: allow, deny, constrain, or escalate in the path of the action rather than beside it. If turning the control off does not change what the agent can do, you only have a dashboard. Finally, write the record somewhere the agent cannot reach.

Put It Where Nothing Moves

Models, harnesses, and tools will keep changing, sometimes monthly. If you build governance around any one of them, you need to rebuild it every time you switch.  

I watched this play out in the early mobile era. Nobody could control every device or every app as they continually channged, so control moved to the data and systems the company owned. The independent layer belongs where AI meets your data, your applications, and your services, and it should not care which model is on the other side.

What to Do Now

  • Map what your AI can reach and do: which data, which applications, whether it can act, and whether it can act without a person.
  • Treat permissions as delegated authority. Access for this task and this purpose, not a standing grant. Agents inherit permissions. They do not inherit trust.
  • Put the judge outside the harness. A governing layer with its own memory, its own view of policy, and no stake in the agent's success.
  • Govern after launch. Reassess every time the model, tools, prompts, or workflows change, which is constantly.
  • Prove you can stop it, and keep an independent record the agent cannot edit.

That gives a board something better than a list of approved AI tools. It helps them understand what AI can actually do, where the lines are, and whether the lines hold.

 

The Judge That Isn't the Builder

The labs will get to these principles because physics is a harsh judge. A model that fails in the open cannot be talked out of it.  

Enterprises will also get there because auditors, courts, and insurers are harsh judges too. And the judge you need is the same one the labs are asking for: one that isn't the builder.

The companies that stand up that layer first will not be the slow ones. They will be the ones who can say yes to the next agent in a day instead of a quarter, because the question of what it is allowed to do was answered before it asked.

The models will keep changing. The control layer should not.