For the Chief Risk Officer · A briefing from Proxy.Me

Risk you can see in real time.

When controls are designed into how work moves, risk management becomes anticipatory rather than corrective. This is what the book calls governance in motion.

Proxy.Me: Agentic AI Digital Apprentices by Christopher Jackson
SECTION 01

From retrospective to anticipatory

Most risk frameworks were built for systems that move at human speed. They rely on after-the-fact review: a sample, a quarterly report, an annual audit. By the time the control catches a drift, the issue is in last quarter's exposures.

AI does not move at human speed. By the time a retrospective control catches a drift in an autonomous agent, the agent has acted on hundreds of cases. The exposure is not theoretical. It already happened.

Anticipatory governance moves the controls into the flow itself. Veto lenses that prevent a decision from progressing when a required signal is missing. Authority caps that adjust automatically when a scenario changes. Cumulative authority measurement that flags the combined operational reach of multiple agents acting together, before that reach matters.

SECTION 02

What it looks like when controls live in the flow

The Work Graph records every step every agent takes. Each step carries the identity in effect, the point of view that shaped it, the veto lenses that applied, the inputs consulted, and the action taken.

Replay is built into the architecture. A reviewer can reconstruct any decision from the evidence trail without re-interviewing anyone or piecing together logs from five systems. The audit trail and the operational signal are the same artefact.

  • a.Drift is visible while it can still be corrected, not after the fact.
  • b.Every flow has a measured cumulative authority. Combinations that exceed thresholds are blocked or escalated automatically.
  • c.Scenarios raised at the organisational level propagate down to the agents and reconfigure their constraint posture in flight.
  • d.Evidence is append-only and tamper-evident. The question "what was known, by whom, under what authority" has a deterministic answer.
Governance is not a checkpoint at the end of a process. It is the shape of the process.
Proxy.Me · Appendix D
SECTION 03

What this means for your second line

Your second line of defence stops being the last word and becomes the curators of the system. They tune the lenses, calibrate the veto rules, and decide where the cumulative authority caps sit. The work moves from sampling to continuous monitoring.

The same monitoring infrastructure produces the audit trail, the regulator package, and the operational signal. Three reports collapse into one source of truth, with three different views.

Risk teams that move first on this architecture become the ones regulators trust to lead the conversation about AI governance. The teams that move last spend the next decade explaining themselves.

Proxy.Me cover
The Full Argument

Proxy.Me: Agentic AI Digital Apprentices

Three appendices on the architecture of agentic AI governance, including detail on cumulative authority, drift detection, and replay. By Christopher Jackson, May 2026.

Read about the book arrow_forward

Get notified at launch

A single email when Proxy.Me is available. Nothing else.