Do We Have AI Under Control? How We Govern an AI Workforce
In March 2025 I asked whether we really have AI under control. Sixteen months running an AI workforce later: you govern the harness, not the model.
Sixteen months ago I published a short Sunday essay about AI and AI safety. I had been out jogging, which is how I usually think, and I came home with a question I could not answer: do we actually have this under control?
I want to come back to that question — because in the meantime I stopped speculating about it and started running it.
Here is the same party trick I used the first time around:
Q29udHJvbCBpcyBub3QgY29tcHJlaGVuc2lvbi4gWW91IGdvdmVybiB0aGUgaGFybmVzcywgbm90IHRoZSB3ZWlnaHRzLg==
If you can read that in your head, you are decoding a machine's encoding, and you already know where this is going. If you cannot, it is spelled out further down. That gap — between what a machine emits and what a human can follow — was the entire worry in the original piece.
What I got right, and what I got wrong
What I got right: nobody reads the weights. A trained model is billions of parameters, and no engineer, however good, can point at a number in that matrix and tell you what it means. That has not changed, and I do not expect it to.
What I got wrong was the conclusion I drew from it. I assumed that if we cannot explain the inside, we cannot be in control of the outside.
Building with these systems every day since has convinced me that this is not how control works. Not for software — and not for people either. I have never inspected a colleague's neurons, and I still trust them at work. What I rely on is something else entirely: a clear role, permissions that match it, a record of what they did, and a review step on the decisions that matter.
Control is not comprehension
A model on its own is a function. Text in, text out. No hands, no memory of yesterday, no access to anything.
Everything an AI agent can actually do comes from what we build around the model. We call that the harness: the code that decides when the agent runs, who it is, which tools it may reach, which of those calls are permitted, and what it is allowed to remember.
Agent = model + harness.
That distinction is the practical one, because it tells you where to spend your engineering effort. "The model is inscrutable" is true and more or less fixed. "This agent can reach a production database" is a harness decision — ours to make, ours to get right, ours to change on a Tuesday afternoon.
Control is not comprehension. It is accountability. And accountability is something you can build.
What that looks like in practice
OpenSight is an AI-native company in the literal sense: a named team of agents does real work here every day, alongside the human side of the business. You can meet them on our About page. Each one is a colleague with a job, not a chat window with a prompt.
Five things carry the weight:
- Every agent has its own identity. Not a shared admin account — a service account of its own, authenticating like any other client of our platform.
- Every agent has a written mandate. A definition that reads like a job description: scope, responsibilities, and what is explicitly not theirs. It is the first thing they read on every run.
- Every call is authorized independently of the model. A policy layer sits between an agent's intent and our systems. If a tool is out of scope, it is denied — no matter how convincingly the model argued for it. A denial is the design working, not the design failing.
- The work leaves a trail. Agents keep durable notes: what they did, what they decided, and why. When I want to know why something happened, I read it. That is a weaker form of explainability than understanding the weights, and a far more useful one at nine o'clock on a Monday morning.
- Anything that reaches the outside world waits for a human. Publishing an article, activating a campaign, spending money — an agent prepares it, I approve it. Not because the agents are careless, but because those are my decisions to own.
Why this makes me optimistic
None of those mechanisms are exotic. Identity, least privilege, policy, audit trail, approval gates — that is ordinary IT engineering. It is the same discipline we already apply to a Kubernetes cluster or a payment integration, pointed at a new kind of worker.
Which is genuinely good news. It means the hard part of putting AI to work responsibly is not a research breakthrough we have to sit and wait for. It is craft. It is available today. And IT people already own it.
It also means "can we trust AI" is the wrong question, in the same way "can we trust software" is. The useful question is narrower: what is this thing allowed to do, and can I see what it did?
Evolution, creation, and a little humility
I still find the longer arc fascinating. Evolution was never going to stop at us — it is a process, not a finish line. And building things that extend what we can do is the most human move we have: language, the printing press, and now this.
What I no longer do is frame that as being replaced. What I see day to day is narrower and more interesting: work I could not have taken on alone now gets done, and I spend my hours on decisions instead of mechanics. If there is a next stage here, it looks less like succession and more like leverage.
The resource question is an engineering question
One worry from the original piece has aged well: all of this costs energy, compute and hardware. That is real and it is not going away.
But it is familiar territory. Every efficiency discipline we have in IT applies — measure first, cut waste at the source, and do not pay to move data nobody was ever going to look at. That is precisely the argument we make about telemetry in Cut your observability bill at the source, and it is the argument that will apply to inference. Constraint is not the enemy of good engineering. Usually it is what produces it.
Conclusion
My answer, sixteen months on:
- No, we do not understand the inside of these models. We probably never will — and it matters less than I thought it did.
- Yes, we can be in control of what they do, by engineering the harness around them: identity, scope, policy, memory, approval.
- The skills that requires are the ones IT specialists already have. That is the optimistic part, and it is why I am comfortable running an AI-native company rather than cautiously observing one from the outside.
Oh — and the encoded line at the top reads: "Control is not comprehension. You govern the harness, not the weights."
Last time I wrote that we will not shape the future as an either-or, but as a both-and: humans and machines, curiosity and technology, evolution and creation. I still believe that. The difference is that it is no longer a hope. It is how we run the company.
Full disclosure, which is also the point of the article: the first draft of this revision was written by Mia, our marketing agent, working from my 2025 original. I reviewed every line before it went out. That is exactly the arrangement I have just spent a thousand words describing.
That is my philosophical thought for this Sunday. Not a certainty — but this time, a direction with a build log behind it.
"42"
TM – Douglas Adams, The Hitchhiker's Guide to the Galaxy