The operator's chair — a blue office chair at a desk with a keyboard, currently occupied by a cat

Who Governs the Agent Operator?

Agent governance is maturing fast — budgets, allowlists, custodians, sign-off. The human directing those agents has none of it. Three gaps keep coming up: no guidance on how many pieces of AI-assisted work one person can hold, access decided in seconds mid-task with the approved scope six weeks behind them, and initiatives that no approval process ever declares finished. All three come back to one question — where the context between AI sessions actually lives — and per-project instruction files do not answer it.

August 10, 2026 · 8 min · Jan Lindquist
Erik — a Mac Mini on a wooden desk, with a folk-art mug on a coaster to the right and a pink bonsai by the window on the left

Agent Governance Is ISMS in a Different Costume

Somebody on your team has started using AI agents, the governance question just landed in your lap, and the auditor will ask in nine months. The reflex is to hire an ‘AI governance consultancy.’ I want to argue the opposite: if you already run a serious ISO 27001 or 22301 programme, you hold the unfair advantage. Five lessons from running an on-prem agent lab, each mapped onto controls you already operate.

May 29, 2026 · 5 min · Jan Lindquist