Its memory
What it carries forward from every prior session.
Governing the agent you approved is not enough.
Most organisations are still trying to govern AI as if it were a static system. They approve the use case. They review the model. They check the vendor. They agree the policy. They launch the agent. Then the agent changes.
AI is moving into the work itself: workflows, customer interactions, case handling, service desks, finance operations, compliance reviews, diligence activity, sales operations, delivery management. That shift changes the problem.
The question is no longer where AI could create value. It is what this AI may know, change, decide and do.
The new risk surface
Approval is a photograph. The agent is a film. Between the sign-off and the workflow, eight things move, and most of them move without anyone re-opening the paperwork.
What it carries forward from every prior session.
What it can reach, and what those tools can now do.
The prompt, the policy text, the operating guidance.
Granted quietly, rarely revoked, seldom reviewed.
Playbooks distributed centrally and updated centrally.
Upgraded by a vendor on a schedule you do not set.
Production evidence quietly reshaping how it behaves.
The business around it, which never holds still either.
The risk is not the existence of the agent. It is the changing capability of the agent.
Why the usual controls miss it
A policy document is not enough. A model register is not enough. A prompt review is not enough. A human-in-the-loop checkbox is not enough. Every one of those governs a moment. None of them governs a trajectory.
This is not the same argument as the control plane, which essay 004 made. A control plane governs what an agent may do right now. The change surface is everything that quietly alters what "right now" means.
The change surface
As agents become persistent, they remember interactions, infer preferences, summarise activity and carry context from one session to the next. That makes them far more useful. It also makes them far more dangerous if nobody can answer basic questions about what is being held.
What is remembered, where it came from, how long it lasts, and who can correct it.
Whether a given memory is fact or inference. Most systems do not distinguish, and the business cannot tell by looking.
Enterprises will increasingly distribute approved playbooks, procedures and workflows to agents centrally. That is powerful, because it creates consistency. It also means one change to a central skill may alter the behaviour of every agent that depends on it.
A skill library is not content management. It is a supply chain for machine capability.
Versioning, staged rollout, dependency mapping and rollback, because a bad skill update is a production incident across every agent that consumed it.
An agent's risk is not defined only by what it knows. It is defined by what it can do. Access to a system, permission to update a record, authority to trigger a workflow, ability to act on behalf of a user. We set out how to calibrate that in essay 003.
Authority granted at approval is rarely re-examined when the tools underneath it expand.
If a tool gained a capability this quarter, did any agent silently inherit it.
Operating-layer AI improves from production evidence: traces, human approvals, user feedback, exceptions, rework and outcomes. That evidence is valuable. It must not become an uncontrolled route for behaviour change.
Feedback should inform evaluation. It should not silently rewrite how the business operates.
Learning proposes. A human disposes. The gap between those two verbs is the whole control.
The obvious objection
None of this argues for slowing everything down with central committees. That will not work, and it will not hold. People route around controls that cost them time, and an agent built quietly outside the process is worse than a slow one built inside it.
The governed route has to be the safe one. It has to be the faster one.
The missing step
Capability gets created, tested, authorised, deployed, observed and improved. Then it stays, long after the workflow moved on, still holding permissions and still carrying memory. Retirement is the step every AI programme writes last and needs first, because an agent nobody owns is not dormant. It is unattended.
If those questions cannot be answered, the organisation does not have an AI operating model. It has uncontrolled automation.
Where Praxis stands
Serious operating-layer AI needs an agent capability lifecycle: a practical model for how capability is created, tested, authorised, deployed, observed, improved and retired. Not bureaucracy. The thing that lets AI move from experiment to operating capability without the business losing sight of what it has running.
The question is not only what the agent is. The question is what the agent is becoming.
Begin
One conversation, no pitch deck. Bring an agent you have already deployed, and we will map what has moved underneath it.