The Authority Programme was written one cell at a time. Four failure modes — identity issued at machine rate, composition that outruns its reviews, evidence that cannot be reconstructed, a lifecycle nobody owns — across four sectors, platforms and banking and healthcare and IT services, each cell a teardown of how the failure arrives and a primitive that answers it. Thirty-two pieces. Writing them cell by cell is the only way to get the detail right, and it is also the one thing that hides the finding, because the finding is not in any cell. It is in the comparison across them.

Here is the comparison. A bank calls it segregation of duties. A hospital calls it minimum necessary. A platform calls it connector scope. An integrator calls it the service account nobody owns. Four names, four bodies of regulation, four separate conversations that never reference each other — and one mechanism underneath, which is that a non-human principal was granted authority faster than any human-paced review could govern it, and outlived the human who authorised it. The vocabularies diverged because the sectors never compared notes. The failure did not diverge at all.

What actually shipped, 11 to 18 August

Take the week on its own terms first, because the individual announcements are real and load-bearing, and only afterwards do they add up to something none of them said.

A registry for the package. On 12 August GitHub published Agent Plugins 1.0, an open standard, backed by AWS, Microsoft, OpenAI, Anysphere and Vercel, that packages an agent's skills and its connected servers into one installable unit governed, in its own words, “independently of any single vendor.” It governs the distributable. It says nothing about the credential the plugin runs on once it is installed and executing. That is not a gap in the standard; a package format should describe packages. It is a fact about which half of the problem got the standard.

An identity for the principal. The next day Microsoft made Entra Agent ID generally available — agent identity as a first-class principal, able, in its own summary, to “authenticate, authorize, govern, and protect agent identities at enterprise scale.” And, tellingly, a lifecycle template that will “automatically transfer sponsorship when an agent identity sponsor changes roles or leaves the organization, to prevent orphaned agents.” Someone wrote a control for the exact failure the programme's banking cell is about. It shipped. It is generally available.

A company for the stop. On 18 August FORT Robotics announced it was going public, describing itself as “The Trust Layer for Physical AI” and “the first publicly traded company dedicated principally to safe and scalable deployment of physical AI,” at a pro-forma enterprise value near 556 million dollars, its product certified to Safety Integrity Level 3 under IEC 61508. Its product is the wireless emergency-stop and the safety controller: the authority to revoke a physical agent's ability to act. The market just priced revocation as a standalone asset.

The same week, Gravis Robotics raised two hundred million dollars to scale heavy-machinery autonomy across “a full spectrum between AI-augmented manual control and full autonomy” — with no word anywhere in the announcement about who authorises the crossing into full autonomy. One company sells the stop. Another sells the go. Neither sells the signed permission in between, and no announcement this week described who holds it.

What the regulators wrote

Nothing agent-specific. This is not rhetorical; it is enumerated. The April 2026 interagency model-risk guidance — issued jointly by the Board of Governors, the FDIC and the OCC, and distributed as the attachment to Federal Reserve SR 26-2 — placed generative and agentic AI outside its scope in footnote 3, and promised a request for information in the OCC's transmittal. As of 18 August that request has not issued; the OCC's news releases and bulletins run continuously through 14 August and none is it. The health privacy regulator has published no agent-specific guidance since the spring. The device regulator's lifecycle guidance for AI-enabled software remains a draft that states it “is not final nor is it for implementation at this time,” and it contains no agentic scope at all.

Read footnote 3 to the end, because its second half is the part that matters and the part that rarely gets quoted. Having placed these models outside scope, it directs that “a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document.” The specification was withdrawn. The determination was handed back to the institution. And a separate sentence in the introduction preserves supervisory action for unsafe or unsound practices regardless. The framework that would have told you what to build is gone; the obligation to have built something is not.

A correction this piece owes its own earlier work: the out-of-scope wording is interagency, not the OCC's alone. It is footnote 3 of the shared attachment to SR 26-2, carried identically in the OCC 2026-13 transmittal. The Federal Reserve cover letter does not carry it, which is how the narrower attribution first got recorded. Only the request-for-information sentence is OCC-transmittal-specific.

The same failure, said four ways

With the week's evidence in hand, the four vocabularies resolve into one grammar. In each sector, a control that governed people was pointed at software and kept its shape while losing the thing that made it work.

Banking: recertification covers people. The annual access review — a human attests that a human still needs a privilege — is a mature, examined control. Most principals in an agent estate are not people, have no manager to attest for them, and were provisioned between review cycles. The control still runs. It just no longer covers most of what has access. Entra's orphaned-agent clause is the vendor naming this exact hole; buying the clause is not the same as closing it across the estate.

Healthcare: the scope reaches everything. The most granular published clinical access model — Oracle Health's, which refuses wildcard scopes and requires an application to request each scope explicitly — still tops out at the resource type. Its own example scope, “system/Patient.read,” means read every patient record the client can reach. There is no per-encounter scope. Agents are live in named health systems this month, and the deployment literature describes what they do and never what they can read. Minimum necessary is a decision the standard requires; nothing records it for an automated reader, and no enforcement action has yet named a service account that over-reached.

Platforms: the registry and the identity never meet. You can now install a plugin whose provenance is governed and hand it a credential whose lifecycle is governed, and nothing checks that the credential matches the capability the plugin declared. The registry validated the package. The identity system issued a valid token to a valid principal. Each is authoritative about its own half and trusts the other. The mismatch lives in the space between two healthy systems — which is precisely the kind of space no single system owns.

IT services: the account outlives the engagement. Two global integrators announced agentic delivery this month — one taking over a global industrial group's IT operations, one shipping an agentic platform into drug development. Both describe governance, oversight, auditability. Neither says a word about the credentials the agents run on or what becomes of the service accounts when the engagement ends. The most explicit published deprovisioning spec lists four triggers to retire a service account, and “the integrator's engagement ended” is not one of them. The freshest large breach in this lane began as a third-party integration's standing tokens.

Why buying the tool is not building the control

It would be easy to read the week as good news that closes the argument: the tools exist now, so buy them. Each of the week's products is real and worth having. None is the control.

Entra Agent ID governs identity. FORT's trust layer governs the physical stop. GitHub's registry governs distribution. Each is one slice, each is a product with an incentive, and each is authoritative about its own slice and trusts its neighbours about theirs. An authorisation architecture for a whole estate is the thing that holds the plugin's declared capability and the principal's granted scope at the same time, mints a narrow grant for the action in front of it, expires it when the action completes, and leaves a receipt an examiner can read. No single-slice product does that, because doing it means reading across the slices the products are each defined to own.

That receipt is the same object in every sector: a record naming the principal, the capability, the scope, the expiry, and the human behind the grant. It satisfies the banking examiner asking for evidence rather than architecture, the minimum-necessary standard asking for a recorded decision, the platform incident-reviewer asking what actually happened, and the integrator's acceptance test asking what the client is inheriting. Four questions, four dialects, one answer: prove this was allowed. The programme specifies that answer sector by sector. The week's products, between them, do not produce it.

The question, and what would change the answer

The question worth carrying out of this week is not whether the tools exist. After this week they increasingly do. It is the one an examiner, an incident, or a handover will eventually force: if a system in your estate acted tomorrow on a permission nobody granted, what artefact would be different? If the honest answer is none, then permission is not a control in your estate — it is a description of a process, and the process has no output — and no purchase changes that until something joins the pieces and writes the receipt.

What would falsify the argument. If a supervisor issues an agent-specific specification that defines the evidence a control must produce, the claim that the determination is being left to the institution weakens. If one of the week's vendors ships the join — a grant bound to a declared capability, minted per action, expiring, receipted — rather than a single slice, the claim that buying is not building weakens with it. Neither has happened as of this writing. Until one does, the shape of the problem is the one this week drew in public: the tooling shipped, the obligation stayed, and the control is the part in between that is still yours to build.