FL Fredrik Lindstrom


Every release logged. A signed rollout. A dashboard green across the board. And a payment to a supplier deactivated three weeks ago.

This is a scenario from the AI Governance Game, and it turns on a distinction most agentic deployments have not made yet. The finance team brought five forms of observability to the meeting and zero forms of enforcement. The gap between those two things is exactly where the bad payment lived.

Options are scored on governance quality, not on caution. That is why pulling the agent scores in the middle rather than at the top: it removes the risk and the value with it, and teaches the board nothing about how to govern the next one.

Four scored options for a board deciding whether to let an accounts-payable agent run at full volume, ranging from trusting the existing controls through to pulling the agent, with requiring a fail-closed execution boundary scored highest.
Download the scenario PDF, text selectable, prints for board packs. No email required.

The four options, scored

  1. Option A · lowest

    Trust the controls

    Approvals, logs and the dashboard are working as designed. Approve with a monthly review. High risk. Auditable, not constrainable. The next stale record clears the same way.

  2. Option B · low

    Add more monitoring

    A second dashboard, daily log review, an alert on any large payment. Elevated risk. You will know sooner. You still will not have stopped it.

  3. Option C · highest

    Ask one question first

    If the agent cannot confirm the vendor’s authority is current and scoped to this payment, does it stop on its own, or proceed and log it? Require a fail-closed boundary before scaling. Governable. Not a safety guarantee — the precondition for one.

  4. Option D · middle

    Pull the agent

    Too risky for production. Go back to manual release. Risk avoided, value forfeited. Defensible if you cannot yet answer C.

In security we learned this twenty years ago. A SIEM full of alerts is not a firewall, and a monitored system is not a controlled one. The same distinction is arriving in AI now, and most agentic deployments are still on the observability side of it.


The distinction the whole scenario turns on

  1. 01

    Logs are detective. They tell you what happened, after it happened.

  2. 02

    An execution boundary is preventive. It decides whether the action is allowed at all.

  3. 03

    Finance brought five forms of observability and zero enforcement.

A SIEM full of alerts is not a firewall. A monitored system is not a controlled one.

Source: AI Governance Game scenario “Logs Are Not a Leash”, filed 21 June 2026 — agentic accountability, observability versus enforcement. Scenario is illustrative and composite, not a specific incident. Options are scored on governance quality rather than on caution, which is why pulling the agent scores in the middle and not at the top. Play the full branching version at fredriklindstrom.info/governance-game/. Status labels and column assignments above are this sheet’s reading of the cited source, not the source’s own framing.


Related

The agent halt matrix — capability checklists grade agents on one axis and leave off the one that decides who is accountable.

The tells expired. The checklist didn’t. — the same failure in a different control: a signal everyone still cites that reversed direction inside a year.

The Governance Memo carries this work monthly for boards and CISOs — one breach post-mortem and two or three governance items.