Policy essay · 2026

Can AI Governance Keep Up with Frontier Capabilities?

Risk classification is only the beginning. Governance also needs to notice when the same system becomes more capable, autonomous and able to act.

Reading time
3 minutes
Published through
Astana Hub
Topic
AI Governance and IP

About this edition. Originally published in Russian on Astana Hub. This English site edition keeps the capability-triggered governance argument and treats every AGI timeline as a forecast, not a fact.

Forecasts about artificial general intelligence vary widely. The exact date is less useful than the planning horizon.

A research laboratory can move through several model generations while a law, corporate transformation or assurance programme moves from first draft to operating routine. If significantly more capable systems arrive within a few years, the mechanisms that will meet them are being designed now.

The transition is unlikely to arrive as one release labelled AGI. We are more likely to see stronger planning, tool use, long action chains, research, coordination between agents and the ability to improve AI development itself. Each change may look incremental. Together they alter the nature of control.

Notice what stops being stable

Consider an AI assistant in customer support. It begins by drafting a reply. Later it can access the knowledge base and customer history, update the CRM, approve a refund and coordinate actions across systems.

The service name and stated purpose may not change. Autonomy, access and consequence have changed substantially.

Three assumptions then fail: the function is fully known in advance, human oversight remains equally effective and an assessment remains valid until the next scheduled review.

Use capability and access as review triggers

Governance does not need to wait for universal agreement on the word AGI. Review can be triggered by observable changes:

  • a new material capability or model version;
  • access to another system or category of data;
  • longer planning or autonomous action;
  • a larger or more vulnerable user group;
  • a serious incident or a demonstrated route around a safeguard;
  • a former draft becoming a consequential action.

An annual review can remain part of the management system. It cannot be the only moment at which a fast-changing use case is examined.

Move control from answers to actions

As AI becomes more agentic, output quality is only part of the risk. The operating design also needs permissions, constrained execution, staged access, monitoring, rollback and a credible stop condition.

The key object is no longer only the generated text. It is the sequence of actions the system can initiate and the point before irreversible consequence at which a person or technical control can intervene.

Build shared evidence from incidents and testing

Frontier developers know about a new capability before customers, regulators and the public. One model can then spread across products, sectors and jurisdictions.

Independent evaluation, comparable incident categories and evidence exchange can reduce that information gap. Enforcement will remain jurisdiction-specific, but the technical evidence base can become more interoperable.

Companies still have a distinct role: they turn a general model into a concrete system by giving it data, tools, users and authority.

The mechanisms remain useful if the forecast is wrong

AGI may arrive later, develop gradually or remain a disputed label. Event-triggered review, independent testing, action controls, clear permissions and incident learning are still useful for today's AI agents.

It is not enough to see a system once. Governance must notice when the system is no longer the one that was originally approved.

Selected sources

Working in public

Analysis is only useful when the next operational question is visible.

I publish field notes to show how I move from a requirement or risk into product behaviour, control, evidence and ownership.

See the advisory approach

Continue reading

A Human Clicked Approve. Was the Decision Actually Reviewed?

The button records human presence. Control begins where disagreement can change the outcome.

Read site edition

Shadow AI Is Already Inside the Company

A ban can close access to a service. It cannot show where AI already participates in work, what data it receives or which decisions now depend on it.

Read site edition

AI Is Already in the Workflow. What Changes Now?

AI rarely enters a company as one large programme. It arrives as a browser tab, a plugin or a familiar service with a new capability.

Read site edition