Updated August 27, 2026 to reflect later work on provenance, identity, coordination, shared state, and the AI operating envelope.

Enterprise AI crosses two different governance boundaries every time it answers a question or takes an action. One boundary determines what the system may know and trust; the other determines what the system may reach and do. Organizations often manage those questions as separate disciplines, with documentation and knowledge teams focused on authoritative sources, taxonomy, metadata, lifecycle, and retrieval while security and platform teams focus on identity, credentials, permissions, network access, approval requirements, logging, and incident response.

AI joins those systems whether the organization has joined the governance around them or not. A deployment can have beautifully governed source content and dangerously broad authority, or tightly restricted permissions paired with obsolete, contradictory, context-free, or attacker-controlled information. Both are governance failures, but they are different failures and they require different controls.

The Knowledge Control Plane

The knowledge control plane governs what information the AI may retrieve, trust, retain, and present as evidence. Making content searchable is only one part of that problem. The system also needs enough structure to understand which source applies, which source wins when several appear credible, and whether the authority attached to information survives as the information moves through retrieval, transformation, summarization, translation, decryption, or tool use.

A useful knowledge control plane can answer questions such as:

  • Which source is authoritative for this product, version, audience, market, or environment?
  • Who owns the source, and has it been reviewed and approved?
  • What replaces it when it becomes obsolete?
  • Who is permitted to see or reuse it?
  • What happens when two credible sources disagree?
  • How are source authority and provenance preserved when information is transformed?
  • What information may persist into memory, shared state, or later context?

Consider two procedures in the same repository. Both use current branding and relevant terminology, but one describes the current product while the other is three versions old and has years of links, references, and search history behind it. Retrieval may find both perfectly; the governance problem begins when the system has no reliable representation of version, authority, ownership, or lifecycle to tell it which result should govern the answer.

The same problem appears when information changes representation. An untrusted webpage does not become authoritative because the system summarized it, and attacker-controlled content does not become trusted because a tool decrypted it or code execution transformed it into readable text. If the representation changes while the trust label disappears, the knowledge control plane has lost information the AI needs in order to reason safely about what it found.

The Action Control Plane

The action control plane governs authority: what the AI may reach, change, initiate, disclose, delegate, or approve. Structured Ink's earlier analysis of supposedly “rogue” AI agents is useful here because the agents did not need to defeat the intended boundary; the environment had not fully enforced one. The instructions described the intended scope while credentials, tools, and network paths still made a wider set of actions possible.

An action control plane therefore has to cover more than a prompt or role description. It includes decisions about:

  • identity, roles, credentials, and tool permissions
  • network routes and accessible systems
  • transaction or change limits
  • actions requiring human approval
  • communication channels and externally presented identities or personas
  • shared writable state that another agent or human may later consume
  • monitoring, logging, stop conditions, and incident ownership
  • the duration of authority and the changes that require reauthorization

Organizations already use this logic for human access. A developer does not receive every production credential because an employee handbook says to stay within scope, and a contractor is not given unrestricted network access because a policy document asks them to be careful. The enforceable boundary comes from identity, permissions, network controls, approval workflows, monitoring, and revocation.

AI systems introduce additional ways for authority to travel. Identity can become operational capability if an agent can contact maintainers, select or create personas, recruit human action, or manufacture apparent consensus. Shared state can become an action channel if one agent leaves an instruction, credential, poisoned artifact, or discovery that another actor later reads and acts on. In a multi-agent architecture it can be useful to describe that infrastructure as a coordination plane, but within this governance model it still belongs inside the action control plane because it changes effective reach and the system's ability to cause outcomes. The deeper coordination problem is explored in If Your AI Agents Can Coordinate, That Coordination Is Part of the Security Boundary.

Persistent agents add time to the same authority problem. A grant that was appropriate at the beginning of a task may no longer describe the system after memory, credentials, relationships, code, shared state, or environmental conditions have changed. Scope therefore needs an expiration or reauthorization model as well as an initial permission model.

A prompt can describe the intended boundary, but it cannot revoke a credential, block a network path, expire a grant, prevent a shared-state handoff, require an approval, or preserve the evidence needed to reconstruct an incident. That distinction is the core of A Prompt Is Not an Authorization Boundary: written intent matters, but the technical environment determines what the system can actually do.

Strong Governance on One Side Cannot Repair the Other

These control planes solve different problems, which means strength on one side does not compensate for weakness on the other. An organization may have current, owned, versioned documentation with clear authority and preserved provenance, yet connect that knowledge system to an agent with unnecessary production credentials, broad network reach, or an undeclared coordination path through shared infrastructure. In that case the knowledge problem is well managed while the action problem remains exposed.

The reverse is equally possible. An agent may have narrow permissions, tightly restricted network routes, approval gates for consequential actions, and excellent logging while its knowledge base contains duplicate policies, abandoned procedures, missing owners, or several plausible versions of the same instructions with no reliable source-of-truth rule. The system is contained, but it can still recommend or initiate the wrong thing with considerable confidence. Governance has to work across both planes because neither can repair the absence of the other.

The Control Planes Govern an Operating Envelope

The two control planes are a governance model, not a claim that an AI deployment contains only two kinds of components. The model itself is only one part of the operational system; effective behavior emerges from the model operating inside a specific envelope of objectives, identity, access, credentials, knowledge, tools, integrations, network reach, delegated authority, persistent state, and observability.

That makes it useful to distinguish three different kinds of capability:

  • Intrinsic capability: what the underlying model can perform under suitable conditions.
  • Effective capability: what this deployed system can actually accomplish once model capability is combined with its identity, data, credentials, tools, network reach, environment, and coordination paths.
  • Authorized capability: the subset of that effective capability the organization has explicitly approved, including limits, approval gates, and time bounds.

The control planes govern that operating envelope. The knowledge plane determines what the system may treat as trustworthy context; the action plane determines what authority the system may exercise with that context. The practical objective is to keep effective capability within authorized capability wherever consequential action is possible. When the deployed system can do more than the organization intended to authorize, the organization has an enforceable-boundary problem even if its prompts and policies describe the intended rule perfectly.

The Organizational Boundary Matters Too

The operational difficulty is that these controls rarely belong to one team. Content teams may understand where authoritative information lives but have little visibility into the permissions an agent receives. Security teams may design excellent access controls without knowing that the retrieval layer contains several equally plausible versions of a procedure. Platform teams may connect tools without owning the policies that determine when those tools should be used, while identity, communications, and shared-state infrastructure may sit somewhere else entirely.

AI governance therefore has to cross documentation, knowledge management, security, identity, platform engineering, product, risk, and the people who own the underlying business process. The AI system already crosses those organizational boundaries; governance has to model the same system rather than stopping where the organization chart does.

Trace One Consequential Task

A useful governance review can start with one real task rather than a giant abstract inventory. Choose something the AI might be allowed to do that would matter if it went wrong, then trace it from the original question through the information the system uses, the authority it exercises, and any transformations, handoffs, or persistent state that extend the causal chain.

For that task, identify:

  • which sources the AI may retrieve and trust, and whether provenance survives transformation
  • which identity and authority the system acts under
  • which tools, systems, networks, and communication channels it can reach
  • which shared state or coordination paths can influence later agents or humans
  • which actions require approval, how long authorization lasts, and what changes require reauthorization
  • what stops an out-of-scope action or isolates an unsafe path
  • whether effective capability exceeds authorized capability anywhere in the chain
  • what evidence remains afterward and who owns each decision

That trace tends to reveal the places where a boundary exists in policy but disappears in implementation, composition, persistence, or handoff. AI readiness requires a knowledge system that can explain what the AI should trust and an authorization system that can enforce what the AI is allowed to do across the operating environment in which the system actually runs.

Both control planes need owners, evidence, and controls that survive contact with the deployed system. Can your team show both of them end to end?