Abstract
The modern governance of artificial intelligence did not stand still while model capability advanced. Between 2017 and 2026, the field moved through a recognisable series of governing objects. The Transformer made the model the visible centre. Model cards and datasheets documented intended use, performance and provenance. Preference learning, reinforcement learning from human feedback and Constitutional AI shaped model behaviour. Foundation-model research, system cards, risk frameworks, management systems and regulation widened attention to development, deployment and organisational responsibility. Retrieval, tool use and agents then turned language models into participants in larger systems. Identity, registries, gateways, deterministic policy, durable workflow, observability and agent protocols followed.
This progression is substantial. Any account that reduces contemporary AI governance to output filtering is obsolete: the strongest current platforms govern models, agents, tools, communications, policies, workflows, enterprise objects and lifecycle evidence. The remaining question is object-centred. Constituent controls do not automatically establish custody of the complete cognitive act—the authorised undertaking moving from purpose and admitted Evidence through judgement, action, verification and Settlement into an accountable record.
This paper offers a historical and architectural review rather than a first-of-kind declaration. It identifies the object governed at each stage, the capability pressure that moved governance outward and the residual property not secured by local controls alone. It then states what would count as whole-act governance, what evidence would disprove Indwel’s present distinction and why the next enterprise AI category may be determined less by what models can generate than by what institutions can responsibly permit generated intelligence to become.
1. Method and claim discipline
This review is organised by governed object, not by vendor chronology alone. For each period, the governing questions are:
- What new artificial capability became important?
- What object did the field attempt to document, align, constrain or manage?
- Which failure modes did the new controls address well?
- Which institutional property remained outside their native scope?
The paper draws first upon primary technical papers, controlling law, normative standards, official frameworks and current first-party platform documentation. First-party vendor sources are authoritative for what a vendor presently documents. They are not independent proof that the capability works in every configuration, nor evidence that a platform lacks functions it has not publicly described. Negative findings must therefore be expressed as not demonstrated in reviewed evidence, with explicit disproof conditions.
The periodisation is analytical rather than absolute. Model documentation continued after 2019. Model alignment continued after 2022. Agent governance did not begin on one date. The periods name changes in emphasis and architectural pressure.
The review also distinguishes four kinds of claim:
- historical fact—a paper, standard, law or product capability appeared;
- documented architecture—a system is described as having a particular control;
- Indwel interpretation—the object governed by that control is narrower than the complete cognitive act;
- category claim—Sovereign Cognition supplies a distinct commercial architecture.
Only the first two can be established by external sources alone. The third is an argument. The fourth requires product proof, technical specification, conformance and continuing competitor review.
This discipline matters because the field is converging. Features once available as loose differentiation—persistence, human approval, deterministic workflow, external policy, agent identity, observability, audit and model independence—are now widely documented. A credible category cannot be built by pretending otherwise.
2. 2017: capability selects the object
The publication of “Attention Is All You Need” in 2017 introduced the Transformer, an architecture based on attention mechanisms rather than recurrence or convolution for sequence transduction.1 Its immediate contribution was technical: quality, parallelism and training efficiency. Its historical consequence was broader. It helped make the learned model the organising object of the next era of AI.
That choice was understandable. The model contained the striking new capability. It could be trained once and adapted across tasks. Scaling data, compute and parameters produced systems whose abilities were not fully specified in advance. The visible progress occurred inside the model, so research, investment and governance followed it.
Early governance questions therefore attached naturally to model development and release. How should a model be evaluated? Which uses were intended? Which harms might arise from release? Which capabilities should be withheld? What did the training process produce, and under what conditions should the artefact be made available?
The model was not yet an enterprise actor in the contemporary sense: it did not ordinarily possess durable identity, delegated credentials, broad tool access or a long-running operational state. The principal concern was what the artefact could generate and how its release might affect users and society.
This period established a durable habit: “AI” became shorthand for the model. Product descriptions, safety debates and public imagination concentrated on the artificial speaker, while surrounding software was treated as application plumbing. The habit persisted after the architecture changed.
3. 2018–2020: documentation, intended use and transparency
The first important governance movement did not attempt to control every model decision. It attempted to make models and datasets more legible.
“Model Cards for Model Reporting” proposed standardised documentation covering intended use, performance characteristics, evaluation conditions and relevant groups.2 “Datasheets for Datasets” proposed an analogous account of dataset motivation, composition, collection, recommended uses and limitations.3 These were not modest contributions. They named a central problem of machine-learning governance: technical artefacts can travel farther than the assumptions under which they were created.
The governed objects were the model artefact and the dataset artefact. The principal mechanisms were disclosure, evaluation and contextual information. Their purpose was to improve accountability before deployment and help users understand whether an artefact was suitable for a given use.
The movement supplied several enduring insights. Performance is conditional: a model does not possess one universal quality independent of population, domain and use. Provenance matters because the composition and creation of training material affect what a system can responsibly do. Intended use and foreseeable misuse belong in technical documentation rather than optional public relations, and governance requires an account that survives beyond the people who built the artefact. System cards, responsible-scaling reports, AI inventories and regulatory technical documentation all inherit part of this logic.
Their native scope, however, is still artefact-centred. A model card can say where a model should not be used. It does not establish the purpose of a particular institutional undertaking, decide which evidence that undertaking may rely upon or mediate every transition by which a model contribution becomes an external effect. A dataset datasheet can preserve provenance. It does not determine whether one retrieved item has been admitted as evidence for one contested proposition inside one live body of work.
The distinction is not a criticism of documentation. It is a boundary. Documentation governs the conditions under which an artefact should be understood. Whole-act governance must also govern what happens when that artefact enters a consequential undertaking.
4. 2019–2022: preferences, instructions and constitutions inside the model
As language models became more general and conversational, governance moved from describing behaviour to shaping it. Preference learning and reinforcement learning from human feedback offered a practical way to train models toward outputs people preferred. OpenAI’s InstructGPT work explicitly framed the problem as alignment with user intent and showed improvements in instruction following, truthfulness and toxicity relative to a base model.4 Anthropic’s work on helpful and harmless assistants similarly applied preference modelling and reinforcement learning.5
Constitutional AI then introduced a more explicit list of principles into model training. Anthropic’s method used a constitution to guide self-critique and AI feedback, seeking harmless behaviour with reduced dependence on direct human labels for every harmful output.6
The governed object consequently changed from the artefact as documented to the model as behavioural participant, with mechanisms including:
- demonstrations and preference comparisons;
- reward models and reinforcement learning;
- system instructions and instruction hierarchies;
- constitutions and self-critique;
- safety policies and refusal behaviour;
- adversarial testing and red teaming.
The movement addressed a real gap. Pretraining optimises prediction over data. It does not, by itself, produce a cooperative assistant that follows instructions, refuses dangerous requests or communicates uncertainty in useful ways. Behavioural alignment made general models deployable in settings that would otherwise have been intolerable.
It also established the model-level meaning of “constitutional”. The constitution shaped values and behaviour inside the model. It answered questions such as: How should the assistant respond? Which principles should it use when critiquing an answer? Which instruction should take precedence?
That is a legitimate and important use of the term, but it is not the same object as an exterior constitution of work. A model constitution can shape how a model interprets a request. It does not make the request institutionally authorised. It can teach the model to defer to higher-priority instructions. It does not establish which human or legal authority may amend the Objective of a live undertaking. It can make the model less likely to produce a harmful recommendation. It does not confer or withhold permission for an external system to act upon a recommendation.
The difference is clearest in the word intent. In alignment research, intent often means the user’s desired model behaviour, including explicit instructions and implicit expectations such as truthfulness and helpfulness. In institutional work, an Objective may be constituted by a contract, policy, office, board resolution, professional duty or lawful delegation. The person writing a prompt may not possess authority to change it. The most helpful interpretation may be unauthorised.
Model-level alignment therefore improves the artificial contributor. It does not settle the constitutional order of the undertaking to which the contributor answers.
5. 2021–2024: foundation-model risk and lifecycle governance
The rise of foundation models widened the field’s view. Stanford’s 2021 report on foundation models treated the model not simply as a task-specific component but as infrastructure whose defects, capabilities and social effects could propagate across applications.7 The report’s interdisciplinary scope—technical principles, applications, law, economics, inequality, security and environmental impact—made clear that governance could not stop at output quality.
System cards expanded model cards toward deployed systems and mitigation processes. The GPT-4 system card, for example, described safety evaluations, red teaming, risk areas and deployment mitigations around a frontier model.8 Anthropic’s Responsible Scaling Policy tied escalating model capabilities to escalating safeguards and evaluation thresholds.9
Public frameworks and law widened the object further. NIST’s AI Risk Management Framework described governance across organisational functions and the AI lifecycle, organised around Govern, Map, Measure and Manage.10 The Generative AI Profile extended that work to distinctive generative-AI risks.11 ISO/IEC 42001 established requirements for an organisational AI management system, including policy, objectives, risk, lifecycle controls, evaluation and continual improvement.12 The European Union’s AI Act created a risk-based legal regime with obligations attached to providers, deployers, high-risk systems, general-purpose models, documentation, logging, human oversight and post-market monitoring.13
The governed objects in this period were the foundation-model system, the AI lifecycle, the organisational AI management system and the regulated AI system. This movement corrected several model-centred limitations: it recognised that responsibility belongs to organisations, not algorithms alone. It treated development, deployment, monitoring and affected people as part of governance. It created inventories, roles, policies, impact assessments and continuing review. It made documentation and oversight enforceable rather than purely voluntary in some contexts.
It also moved the question from “Is the model safe?” to “Is the socio-technical system responsibly developed and used?”
Lifecycle governance changed the frame decisively. Sovereign Cognition builds upon that achievement rather than replacing it.
The residual boundary is that lifecycle governance ordinarily operates across a class of systems and uses, while a complete cognitive act is a particular authorised undertaking. An AI management system may require risk assessment, documentation, monitoring and control. It may not supply one native object that preserves the Objective, admitted evidence, unresolved burdens, authorities, model contributions, external effects and terminal truth of each consequential matter.
A regulated system can comply with logging requirements while logging a constitutionally incomplete representation. A deployer can maintain excellent policies while a live undertaking loses an open condition between retrieval, summary, approval and execution. Organisational governance is necessary. It does not, without a work-level object, guarantee custody of the matter passing through the governed estate.
6. 2022–2025: retrieval, tool use and the rise of the agent
The next pressure came from action. Retrieval-augmented systems gave models access to external documents. ReAct interleaved reasoning traces with actions and observations, allowing a language model to update a plan through interaction with external sources.14 Toolformer trained models to decide when and how to call APIs.15 Production systems added code execution, search, databases, business applications and computer use.
The model ceased to be only a generator and became an agentic participant that could:
- maintain a task state;
- choose tools;
- revise plans;
- call other agents;
- access external data;
- take actions with operational consequences;
- continue beyond one conversational turn.
Governance followed with guardrails, tool allow-lists, typed interfaces, approval hooks, sandboxing, traces, evaluation and human-in-the-loop patterns. Protocols accelerated the transition. Anthropic introduced the Model Context Protocol in November 2024 as a standard way for AI applications to connect to external data and tools.16 Google announced Agent2Agent in April 2025 to support discovery, communication and collaboration across agents, later moving the project to the Linux Foundation.17
These protocols are infrastructure, not constitutions. Their importance lies in what they reveal: the artificial participant now crosses organisational and technical boundaries. A model can encounter material created elsewhere, invoke capabilities it did not ship with and delegate to an agent governed by another platform.
The governed object accordingly became the agent run, the tool call, the agent trajectory and the protocol interaction, with substantial control mechanisms including:
- structured tool schemas and constrained parameters;
- explicit approval before sensitive actions;
- trace capture across model and tool calls;
- session and checkpoint persistence;
- evaluators for trajectories and outcomes;
- sandboxing and capability restriction;
- identity propagation and credential brokerage;
- protocol-level discovery and communication.
The rise of the agent also exposed a deeper security problem. The model must interpret both trusted instructions and untrusted data in one inferential process. Indirect prompt injection allows hostile content in documents, webpages or tool responses to influence behaviour. Recent work extends the concern beyond injected instructions to data presented as trusted metadata or context.18
The industry’s response increasingly favours system-level defences: reference monitors, information-flow labels, capabilities, isolated policy generation and deterministic enforcement outside the model.19 This convergence strongly supports one part of Indwel’s architecture: a probabilistic component should not police every boundary through its own reasoning. It also sharpens the remaining question. An exterior guard can determine whether an agent may call a tool with specified parameters. It cannot know, from the request alone, whether those parameters were derived from admitted evidence, whether an unresolved burden should have blocked the action or whether the represented purpose still belongs to the principal. Those properties must have been preserved before the request reached the guard.
Agent governance secures the participant and its interactions. Whole-act governance must secure the constitutional meaning carried across those interactions.
7. 2025–2026: identity, gateways, durable workflows and control planes
By 2025 and 2026, enterprise platforms had begun to resemble operating systems for artificial workers. Google’s Gemini Enterprise Agent Platform documents unique agent identity, a central registry for agents, tools and MCP servers, an Agent Gateway for policy enforcement, memory, observability and lifecycle governance.20 AWS documents AgentCore Policy as a boundary outside the agent that intercepts agent-to-tool requests and applies deterministic Cedar policies.21 Microsoft’s Agent Framework combines agents with explicit workflows, shared state, durable execution and human-in-the-loop approval.22 OpenAI Frontier describes enterprise agents operating with organisational context, permissions, boundaries, evaluation, governance and auditable actions.23
Palantir approaches the same pressure from the enterprise-data and operational side. Its Ontology represents business objects, relationships, logic and actions; AIP connects models to that operational layer; action logs record decisions and changes associated with Ontology actions.24
The details matter because they show how far exterior governance has already travelled. Google’s current Agent Gateway blocks outbound traffic to unregistered destinations and binds gateway communication to registered agents, endpoints, MCP servers and policy. The associated registry is not merely a catalogue: it is part of the control plane through which identity and permitted connectivity are made operational.25 AWS is equally explicit about position. AgentCore Policy evaluates agent-to-tool traffic outside the agent’s code, with deterministic Cedar policy at the Gateway boundary; current documentation also includes session-scoped temporal policies, so the policy decision can depend upon action history rather than a single isolated call.26
Microsoft’s Agent Framework makes another part of the perimeter durable. Workflows have explicit state, checkpoints and resumption; pending human requests survive checkpoints and reappear when execution resumes.27 OpenAI Frontier frames enterprise agents through Business Context, agent execution, shared identity and access management, built-in evaluation, observability, explicit permissions and auditable actions.28 These are not cosmetic governance layers. They preserve identity, state and control across increasingly long and consequential agent activity.
Palantir’s action log supplies a related lesson from operational software: an action can be represented as an object in the Ontology so that the decision and resulting data change remain available to later workflows and analysis.29 Once action history becomes first-class data, the audit trail is no longer merely a text transcript attached to an AI run. The market is plainly learning to make consequence durable.
Governance and model-risk platforms have also expanded. They inventory models and agents, map policies and regulations, collect evidence, monitor performance, preserve lineage and provide control-tower views across the AI estate. Observability systems capture prompts, traces, tool calls, costs and evaluations. Decision-intelligence and process platforms combine predictions, optimisation, workflows and execution.
The governed objects now include:
- the agent identity;
- the agent and tool registry;
- the communication boundary;
- the runtime policy decision;
- the durable workflow;
- the enterprise object and action;
- the AI asset and control estate;
- the trace and evaluation record.
The resulting governance is exterior, deterministic, and operational. It is no longer accurate to say that the market simply asks models to obey their own rules.
The strongest platforms can prevent an unauthorised tool call before execution. They can attribute actions to an agent identity, route human approval, persist state across interruptions, enforce policies, evaluate trajectories and preserve detailed audit evidence. These are constituent capabilities that a serious Sovereign Cognition system may use rather than reinvent.
The category pressure is therefore direct. If Indwel described itself only as probability inside determinism, persistence around a model, human oversight or auditable agent action, the distinction would already be weak.
The remaining claim must therefore be more exact: the authorised cognitive undertaking is the native governed object, and every constituent component receives its office from that undertaking.
Current platform documentation does not generally demonstrate that object as a joined constitutional whole. It may be composable from multiple products, and a competitor can disprove the distinction by showing that it natively preserves equivalent custody under different terminology. The standard cannot require competitors to speak Indwel.
8. The field has discovered the perimeter
The historical pattern is now visible: each expansion of artificial capability moved governance one layer outward.
| Capability pressure | Governing response | Native governed object |
|---|---|---|
| General learned inference | evaluation and release discipline | model artefact |
| Conditional performance and provenance | cards and datasheets | model and dataset |
| Conversational instruction following | RLHF, constitutions, instruction hierarchy | model behaviour |
| Foundation-model scale and propagation | system cards, risk frameworks, regulation | AI system and lifecycle |
| Retrieval and tools | guardrails, schemas, sandboxes, approvals | tool call and agent run |
| Long-running agents | state, workflow, traces, evaluation | trajectory and process |
| Cross-agent ecosystems | identity, registries, gateways, protocols | agent estate and communication |
| Enterprise action | ontology, policy, audit, control towers | operational objects and AI assets |
The history is not one of governance failure. Governance has been learning to follow capability.
The pattern is acknowledged increasingly in scholarship. GovAI has argued that comprehensive governance must address non-model capability gains produced by scaffolding, tools, compute, agents and organisational systems.30 NIST has launched an AI Agent Standards Initiative focused on secure and interoperable agents.31 UK AISI’s empirical work on 177,000 MCP tools documents the speed and breadth with which agents are acquiring access to external capabilities.32
The direction of those initiatives is itself evidence of the changing object. NIST’s programme now includes work on agent authentication and identity infrastructure, not merely model evaluation. AISI’s monitored MCP ecosystem shows action-capable tools becoming the majority of use, including tools operating in browsers, computers and financial systems.3334 The practical governance problem is increasingly about principals, capabilities, identity, delegated authority and external consequence. A model-only account cannot describe that estate, even when the model remains its most conspicuous component.
The field is therefore converging upon an exterior-system view. Sovereign Cognition does not claim to be the first architecture to move controls outside the model. It proposes a different centre for those controls.
The dominant movement has been from the model outward: govern the model, then its system, then its tools, then its agents, then the estate in which those agents operate. Indwel moves from the undertaking inward: constitute the Work, preserve its Objective and Evidence, admit models and tools as contributors, govern their transitions, and settle only what the Work is entitled to treat as durable.
Both movements may use the same constituent technologies. Their architectural difference concerns what owns the state and authority of the whole.
The measurement gap follows the same boundary. Contemporary evaluations can score answer quality, policy compliance, tool success, harmful behaviour, task completion, trace quality and the length of work an agent can perform. These are valuable measures. None alone establishes that the completed task remained the task that was authorised, relied only upon evidence entitled to govern it, preserved unresolved burdens, caused only legitimate effects and reached a terminal state the institution may truthfully adopt.
Whole-act evaluation therefore requires a longitudinal object. The fixture must contain an Objective, authorities, evidence classes, contradictory material, changing circumstances, consequential transitions and a terminal-truth rule. The evaluator must inject faults at handoffs—not only at the model output—and observe whether the system preserves or loses constitutional custody. A system that refuses or remains unresolved may outperform one that completes the nominal task after silently discarding a governing condition.
This changes the meaning of performance. Speed, accuracy and autonomy remain relevant, but they are conditioned by legitimacy of transition. The fastest path to the wrong institutional state is not superior cognition. Nor is a long trace evidence of a governed result. The state-of-field question is consequently both architectural and metrological: what is the governed object, and what observable evidence would show that its essential properties survived?
METR’s task-completion time-horizon work is useful precisely because it makes one dimension of agent capability longitudinal: how long a task, calibrated against human completion time, can an agent complete at a given reliability?35 That measure captures a real expansion in autonomous competence. It does not tell us whether the task remained constitutionally the same task while the agent pursued it. Stanford’s 2026 AI Index exposes the complementary measurement gap: capability and agent performance continue to advance while responsible-AI benchmarking and reporting remain materially thinner, even as organisations formalise governance roles and policies.36 The missing measure is not another general safety score. It is evidence that authority, Evidence standing, open burden, and consequence survived the extended act.
9. Prior art beyond AI governance
The whole-act question did not begin with artificial intelligence. Several older fields had already learned, by different routes, that consequential work cannot be understood by inspecting one intelligent participant or one local procedure in isolation.
Distributed-cognition research widened the cognitive unit beyond an individual mind. Edwin Hutchins showed how reasoning is organised across people, representational artefacts, instruments and socially maintained procedures.37 The relevance to contemporary AI is not that a ship's navigation team anticipated large language models. It is that cognition was already understood as a property of organised systems in which no single participant possessed the whole state. A model may be the most generative participant in a modern cognitive system and still not be the proper owner of the undertaking.
Lucy Suchman's studies of situated action supplied a second warning. Plans, scripts and formal procedures do not exhaust the intelligence of actual work.38 People interpret circumstances, recover from breakdowns, amend practical courses and discover what a situation requires while acting within it. This matters for both model-centred and workflow-centred governance. A prompt is not the undertaking's final constitution, but neither is a flowchart. The governing system must preserve authorised purpose while permitting situated judgement, evidence change and legitimate amendment.
Adaptive case-management and case-handling research approached the same problem from enterprise systems. Knowledge-intensive work often cannot be represented as one predetermined sequence. Van der Aalst, Weske and Grünbauer argued that flexible cases require the system to present the whole case and its information, permit authorised workers to choose among enabled activities and preserve context across the case's life.39 Contemporary agent frameworks increasingly rediscover this need through durable state, resumability and human intervention. Yet a case container, however useful, does not by itself determine which source has evidential standing, which unresolved burden prevents closure or what terminal state the institution may treat as true.
Records and archival disciplines add the institutional dimension. A record is not merely an event trace. Its value depends upon provenance, context, integrity, authority and its place within an accountable course of action. The same distinction governs the difference between a log of model calls and a reasoned Receipt, or between accumulated events and a Chronicle that preserves the authoritative history of the Work. The system must not merely remember that something happened. It must preserve what the event meant, under which authority it occurred and what status it was entitled to change.
Systems-safety scholarship provides the causal warning. Nancy Leveson's systems-theoretic account of accidents rejects the assumption that safety can be established solely by preventing component failures.40 Serious losses may arise from interactions among components that are each functioning according to specification but are coordinated under inadequate constraints. The analogy to AI governance is direct but bounded. A deterministic gateway, approval step and audit service may all work locally while the composed cognitive act carries a false Objective, incomplete Evidence or an unpreserved burden into effect. The failure belongs to the control structure of the whole, not necessarily to one defective component.
These traditions are intellectual neighbours, not evidence that Sovereign Cognition was previously implemented under another name. They establish a prior lesson: human work, cognition, authority, records and safety are system properties. Indwel's distinct burden is to demonstrate how those lessons become one technical constitution for artificial cognition—one that governs the undertaking across probabilistic inference, deterministic control, human judgement and institutional consequence.
This prior art also limits the novelty claim. Indwel should not claim to have invented distributed cognition, situated action, adaptive case management, accountable records or systems control. The proposed novelty lies in joining their governing concerns around the complete cognitive act and making that joined object native to the architecture.
10. Why constituent governance does not automatically become whole-act governance
A composition can contain excellent controls and still lose the property those controls were meant to protect. Consider a system with:
- a cryptographically distinct agent identity;
- a trusted tool registry;
- a deterministic policy engine;
- a durable workflow;
- a human approval step;
- an immutable audit log.
The agent reviews contract, security and procurement material. It concludes that a vendor exception permits launch. In reaching that conclusion, it overlooks a later amendment requiring verification before customer data is processed.
The workflow routes the proposed launch to the correct executive. The approval page shows the agent’s summary but not the omitted amendment. The executive approves. The policy engine confirms that the executive possesses authority and that the requested action falls within the permitted scope. The tool executes. The log preserves every event.
Every named control can work as designed, and the act can still be constitutionally false.
The deterministic controls operated upon a representation that had already lost governing evidence and an unresolved burden. Identity established who acted. It did not establish that the act represented the authorised purpose. Policy established that the request was permitted under the supplied state. It did not establish that the state was true. Approval established that an authorised person clicked. It did not establish that the person was given the material necessary to exercise the office. Audit preserved the path. It did not make the path legitimate.
The distinction is between segmental determinism and whole-act constitutional custody. Local determinism secures a transition against defined inputs and rules. Whole-act custody secures the constitutional property carried from the beginning of the undertaking to its terminal state.
The property may be lost through one material transition:
- a prompt is treated as authorised Objective;
- retrieved context is treated as admitted evidence;
- a model summary replaces contrary material;
- an unresolved burden disappears from the approval view;
- an action parameter is derived from untrusted data;
- execution is represented as verification;
- workflow closure is represented as settlement;
- a trace is represented as an authoritative account.
The deterministic component downstream need not malfunction. It can process a false representation perfectly.
The whole-act claim is therefore compositional: a composition is only as governed as its least-governed material transition.
No theorem of mathematical impossibility is being claimed. The burden is engineering: a system claiming whole-act governance must identify every transition capable of altering authority, evidence, burden, consequence, settlement, or terminal truth; specify the governing component; preserve the relevant state; and demonstrate failure behaviour when the obligation is unsatisfied.
11. What whole-act governance would have to demonstrate
A system need not use Indwel terminology to satisfy whole-act governance. It must, however, demonstrate equivalent functions across one persistent undertaking.
11.1 Objective custody
The system preserves what the undertaking is for, who constituted it, which interests and limits bind it and who may amend it. Model interpretation cannot silently become amendment.
11.2 Evidence custody
The system distinguishes Sources, admitted Evidence, memory, generated content and untrusted material. Admission is proposition-specific and reviewable. Provenance survives retrieval, summarisation and tool use.
11.3 Frontier and burden preservation
The system represents what remains unknown, contested, conditional or incomplete. It does not reward fluent completion by collapsing open burdens into a final answer.
11.4 Probabilistic non-self-authentication
A model output cannot promote itself into authority, evidence, policy, permission, settlement or terminal truth merely by being plausible or by being copied into a structured field.
11.5 Material-transition closure
Every change capable of affecting authority, evidence, burden, consequence or truth crosses an enumerated governing boundary with explicit preconditions and resulting state.
11.6 Pre-effect mediation
Consequential actions are governed before execution. The control is attached to the actual proposed effect and the state that justifies it, not only to a general approval or post-hoc trace.
11.7 Settlement integrity
The system distinguishes proposal, approval, execution, verification and Settlement. Terminal truth is unique and reasoned. A finished run or workflow cannot authenticate itself as settled work.
11.8 Receipt and Chronicle
The system can issue a reasoned account of the result and preserve one continuing authoritative history across models, tools, agents, people and applications.
11.9 Substitution continuity
Changing a model, provider, agent framework or tool does not silently change the constitution of the undertaking. The Objective, evidence standing, authorities and terminal state remain owned outside the substituted component.
11.10 Single-failure containment
One model or integration error cannot cross multiple constitutional boundaries and produce an unreviewed irreversible effect. Where proof is insufficient, the system fails closed or preserves the burden visibly.
These tests are deliberately demanding. They are also narrower than a claim of universal safety. A whole-act system can still pursue a bad Objective, admit false evidence, suffer cyberattack or reach an incorrect judgement. The warrant concerns custody and legitimacy of transition, not omniscience.
12. The market boundary
The commercial value of whole-act governance is not uniform. For low-consequence drafting, exploration and creativity, ordinary model and application controls may be sufficient. Additional constitutional structure can become needless friction.
The category becomes valuable where the work has several of the following properties:
- an external effect can create financial, legal, operational or human consequence;
- evidence comes from multiple sources with different standing;
- unresolved questions must survive pressure for a rapid answer;
- work continues across days, people, systems or model substitutions;
- authority is distributed and conditional;
- the institution must explain what became official;
- false completion is expensive;
- provider or model independence is commercially important.
This buyer boundary distinguishes Sovereign Cognition from a universal claim about all AI use. The category is not “governance for every prompt”. It is an architecture for consequential artificial cognition.
Its closest commercial neighbours are correspondingly serious:
- agent platforms with identity, gateways and policy;
- workflow and adaptive case-management systems;
- enterprise ontology and decision platforms;
- AI governance and model-risk platforms;
- observability and evaluation systems;
- records, provenance and compliance infrastructure.
Indwel’s position should be cooperative and exact. These systems may supply indispensable constituent capabilities. The distinction is whether they natively join the constitutional state of the complete undertaking—or can be composed to do so with demonstrable custody at every material transition.
13. What would disprove the Indwel distinction
A category claim must be capable of losing. Indwel’s present distinction would be materially weakened or disproved by evidence that a competitor or open architecture already provides equivalent whole-act custody as a native or documented composition.
The evidence would need to show:
- one persistent undertaking identity across people, models, agents, workflows and applications;
- authorised Objective creation and amendment;
- proposition-specific evidence admission distinct from context;
- explicit preservation of unresolved burdens;
- model contributions structurally unable to self-authenticate into authority or truth;
- governed pre-effect transitions tied to actual state and consequence;
- Settlement distinct from completion, approval and execution;
- a reasoned Receipt and unique terminal truth;
- a continuing Chronicle across substitutions and failures;
- defined conflict, timeout, rollback and partial-failure behaviour.
A competitor need not expose proprietary internals. Public specifications, schemas, product demonstrations, conformance tests or independently reproducible behaviour could establish the point.
Indwel accepts the same burden. The architecture described here is not a roadmap: Cognitive Constitution, Work-specific Cognitive Contracts, Evidence authority, Cognitive Governors, governed inference and action, observation, Settlement, Receipt, Chronicle, applications, security, and operational controls are live parts of the system. The relevant claim is therefore testable in operation. A whole-act claim survives only while the system preserves the undertaking through every material transition; a demonstrated break in that custody is a product failure, not a footnote to an otherwise complete architecture.
The category must also survive scientific challenge. The Complete Cognitive Act Benchmark should permit non-Indwel systems to pass, publish negative results and revise tests where they reward vocabulary rather than custody.
Finally, the historical claim must remain revisable. The market is moving quickly. Current agent platforms already challenge parts of the distinction more directly than systems available two years earlier. The source estate requires dated refresh, contrary evidence and correction.
14. Conclusion: the next governed object
Between 2017 and 2026, AI governance moved steadily outward. It began with the model artefact and its release. It documented datasets and intended use. It shaped model behaviour through human preference and constitutions. It widened into system cards, lifecycle risk, organisational management and regulation. It followed models into retrieval, tools and agents. It now governs identities, registries, gateways, workflows, protocols, enterprise objects and AI estates.
That expansion is real progress, and it makes the remaining question harder. Governance already exists outside the model. What remains is to determine whether those exterior controls are joined around an authorised cognitive undertaking, or remain excellent controls over constituents whose constitutional meaning can still be lost between them. Sovereign Cognition names the governed object Indwel puts forward for that test: the complete cognitive act.
Its governing order begins before the model is called. Human and institutional authority constitute the Objective. Sources are gathered and Evidence admitted. Open burdens remain visible. Models contribute inference without conferring authority upon themselves. Capabilities and effects cross governed transitions. Settlement establishes what the institution may treat as durable. A Receipt explains the result. A Chronicle preserves the history.
The architecture does not diminish the model; it gives the model a proper office. The field’s first decade of Transformer governance was organised around an extraordinary artificial participant. The next may be organised around the human undertaking capable of using that participant without surrendering custody of what the work is for, what it may rely upon, what it may do and what it may finally call true.
Notes
Selected bibliography
Anthropic. “Constitutional AI: Harmlessness from AI Feedback.” 2022.
Anthropic. “Introducing the Model Context Protocol.” 2024.
Bommasani, Rishi, et al. On the Opportunities and Risks of Foundation Models. Stanford CRFM, 2021.
European Union. Regulation (EU) 2024/1689, Artificial Intelligence Act. 2024.
Gebru, Timnit, et al. “Datasheets for Datasets.” 2018/2021.
GovAI. “Comprehensive AI Governance Requires Addressing Non-Model Capability Gains.” 2026.
ISO/IEC. ISO/IEC 42001:2023, Artificial Intelligence Management Systems.
METR. “Measuring AI Ability to Complete Long Tasks.” 2025; Time Horizon 1.1 updated 2026.
Mitchell, Margaret, et al. “Model Cards for Model Reporting.” 2018/2019.
NIST. Artificial Intelligence Risk Management Framework (AI RMF 1.0). 2023.
NIST. Generative Artificial Intelligence Profile. 2024.
Ouyang, Long, et al. “Training Language Models to Follow Instructions with Human Feedback.” 2022.
Schick, Timo, et al. “Toolformer: Language Models Can Teach Themselves to Use Tools.” 2023.
Stanford HAI. The 2026 AI Index Report. 2026.
Vaswani, Ashish, et al. “Attention Is All You Need.” 2017.
Yao, Shunyu, et al. “ReAct: Synergizing Reasoning and Acting in Language Models.” 2022/2023. Hutchins, Edwin. Cognition in the Wild. MIT Press, 1995.
Leveson, Nancy G. Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press, 2011.
Suchman, Lucy A. Plans and Situated Actions: The Problem of Human-Machine Communication. Cambridge University Press, 1987.
van der Aalst, Wil M. P., Mathias Weske and Dolf Grünbauer. “Case Handling: A New Paradigm for Business Process Support.” Data & Knowledge Engineering 53, no. 2 (2005): 129–162.
- Ashish Vaswani et al., “Attention Is All You Need,” Advances in Neural Information Processing Systems 30 (2017), https://arxiv.org/abs/1706.03762.↩︎
- Margaret Mitchell et al., “Model Cards for Model Reporting” (2018; published 2019), https://arxiv.org/abs/1810.03993.↩︎
- Timnit Gebru et al., “Datasheets for Datasets” (2018; published 2021), https://arxiv.org/abs/1803.09010.↩︎
- Long Ouyang et al., “Training Language Models to Follow Instructions with Human Feedback” (2022), https://cdn.openai.com/papers/Training_language_models_to_follow_instructions_with_human_feedback.pdf.↩︎
- Yuntao Bai et al., “Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback” (2022), https://www.anthropic.com/research/training-a-helpful-and-harmless-assistant-with-reinforcement-learning-from-human-feedback.↩︎
- Yuntao Bai et al., “Constitutional AI: Harmlessness from AI Feedback” (2022), https://www.anthropic.com/research/constitutional-ai-harmlessness-from-ai-feedback.↩︎
- Rishi Bommasani et al., On the Opportunities and Risks of Foundation Models (Stanford CRFM, 2021), https://crfm.stanford.edu/report.↩︎
- OpenAI, GPT-4 System Card (2023), https://cdn.openai.com/papers/gpt-4-system-card.pdf.↩︎
- Anthropic, “Responsible Scaling Policy,” first published 2023 and subsequently revised, https://www.anthropic.com/responsible-scaling-policy. The policy is cited as an example of capability-linked frontier governance, not as evidence that every commitment or safeguard has remained unchanged.↩︎
- NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (2023), https://www.nist.gov/itl/ai-risk-management-framework.↩︎
- NIST, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (2024), https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence.↩︎
- ISO/IEC 42001:2023, “Information technology—Artificial intelligence—Management system,” https://www.iso.org/standard/42001.↩︎
- Regulation (EU) 2024/1689, Artificial Intelligence Act, https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng.↩︎
- Shunyu Yao et al., “ReAct: Synergizing Reasoning and Acting in Language Models” (2022; ICLR 2023), https://arxiv.org/abs/2210.03629.↩︎
- Timo Schick et al., “Toolformer: Language Models Can Teach Themselves to Use Tools,” NeurIPS 2023, https://proceedings.neurips.cc/paper_files/paper/2023/hash/d842425e4bf79ba039352da0f658a906-Abstract-Conference.html.↩︎
- Anthropic, “Introducing the Model Context Protocol” (25 November 2024), https://www.anthropic.com/news/model-context-protocol; Model Context Protocol specification, https://modelcontextprotocol.io/specification/.↩︎
- Google, “Announcing the Agent2Agent Protocol” (9 April 2025), https://developers.googleblog.com/en/a2a-a-new-era-of-agent-interoperability/; Linux Foundation, “Launches the Agent2Agent Protocol Project” (23 June 2025), https://www.linuxfoundation.org/press/linux-foundation-launches-the-agent2agent-protocol-project-to-enable-secure-intelligent-communication-between-ai-agents.↩︎
- Woohyuk Choi et al., “Agent Data Injection Attacks are Realistic Threats to AI Agents” (2026), https://arxiv.org/abs/2607.05120; David Hofer, Edoardo Debenedetti and Florian Tramèr, “Assessing Automated Prompt Injection Attacks in Agentic Environments” (2026), https://arxiv.org/abs/2606.10525.↩︎
- Chong Xiang et al., “Architecting Secure AI Agents: Perspectives on System-Level Defenses Against Indirect Prompt Injection Attacks” (2026), https://arxiv.org/abs/2603.30016; “Adaptive Evaluation of Out-of-Band Defenses Against Indirect Prompt Injection” (2026), https://arxiv.org/abs/2606.26479.↩︎
- Google Cloud, “Govern your agents,” Agent Registry and Agent Gateway documentation, current documentation as reviewed 29 August 2026, https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern and https://docs.cloud.google.com/agent-registry/manage-mcp-tools.↩︎
- Amazon Web Services, “Policy in Amazon Bedrock AgentCore,” current documentation as reviewed 29 August 2026, https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/policy.html. AWS states that agent actions through the Gateway are evaluated at a boundary outside the agent and that policy decisions are deterministic.↩︎
- Microsoft, “Workflow concepts,” “Workflow capabilities” and “Durable Extension,” current Agent Framework documentation as reviewed 29 August 2026, https://learn.microsoft.com/en-us/agent-framework/concepts/workflows/, https://learn.microsoft.com/en-us/agent-framework/workflows/, and https://learn.microsoft.com/en-us/agent-framework/hosting/azure-functions.↩︎
- OpenAI, “OpenAI Frontier,” current page as reviewed 29 August 2026, https://openai.com/business/frontier/. The page documents enterprise context, permissions, governance, controls and auditable actions; it is first-party evidence of claimed architecture.↩︎
- Palantir, “AIP overview” and “Action log,” current documentation as reviewed 29 August 2026, https://palantir.com/docs/foundry/aip/overview/ and https://palantir.com/docs/foundry/action-types/action-log/.↩︎
- Google Cloud, “Govern your agents,” Agent Registry and Agent Gateway documentation, current documentation as reviewed 29 August 2026, https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern and https://docs.cloud.google.com/agent-registry/manage-mcp-tools.↩︎
- Amazon Web Services, “Policy in Amazon Bedrock AgentCore,” current documentation as reviewed 29 August 2026, https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/policy.html. AWS states that agent actions through the Gateway are evaluated at a boundary outside the agent and that policy decisions are deterministic.↩︎
- Microsoft, “Workflow concepts,” “Workflow capabilities” and “Durable Extension,” current Agent Framework documentation as reviewed 29 August 2026, https://learn.microsoft.com/en-us/agent-framework/concepts/workflows/, https://learn.microsoft.com/en-us/agent-framework/workflows/, and https://learn.microsoft.com/en-us/agent-framework/hosting/azure-functions.↩︎
- OpenAI, “OpenAI Frontier,” current page as reviewed 29 August 2026, https://openai.com/business/frontier/. The page documents enterprise context, permissions, governance, controls and auditable actions; it is first-party evidence of claimed architecture.↩︎
- Palantir, “AIP overview” and “Action log,” current documentation as reviewed 29 August 2026, https://palantir.com/docs/foundry/aip/overview/ and https://palantir.com/docs/foundry/action-types/action-log/.↩︎
- GovAI, “Comprehensive AI Governance Requires Addressing Non-Model Capability Gains” (2026), https://www.governance.ai/research-paper/comprehensive-ai-governance-requires-addressing-non-model-capability-gains.↩︎
- NIST, “Announcing the AI Agent Standards Initiative for Interoperable and Secure Innovation” (2026), https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure.↩︎
- UK AI Security Institute, “How are AI agents used? Evidence from 177,000 AI agent tools” (26 March 2026), https://www.aisi.gov.uk/blog/how-are-ai-agents-used-evidence-from-177000-ai-agent-tools.↩︎
- NIST, “Announcing the AI Agent Standards Initiative for Interoperable and Secure Innovation” (2026), https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure.↩︎
- UK AI Security Institute, “How are AI agents used? Evidence from 177,000 AI agent tools” (26 March 2026), https://www.aisi.gov.uk/blog/how-are-ai-agents-used-evidence-from-177000-ai-agent-tools.↩︎
- METR, “Measuring AI Ability to Complete Long Tasks” (19 March 2025), with current Time Horizon 1.1 measurements updated 8 May 2026, https://metr.org/blog/2025-03-19-measuring-ai-ability-to-complete-long-tasks/ and https://metr.org/time-horizons/. METR measures autonomous task-completion horizons; it is cited here as a capability metric, not as a whole-act governance benchmark.↩︎
- Stanford Institute for Human-Centered Artificial Intelligence, The 2026 AI Index Report, especially the Responsible AI chapter, https://hai.stanford.edu/ai-index/2026-ai-index-report and https://hai.stanford.edu/ai-index/2026-ai-index-report/responsible-ai.↩︎
- Edwin Hutchins, Cognition in the Wild (MIT Press, 1995).↩︎
- Lucy A. Suchman, Plans and Situated Actions: The Problem of Human-Machine Communication (Cambridge University Press, 1987), and Human-Machine Reconfigurations, 2nd ed. (Cambridge University Press, 2007).↩︎
- Wil M. P. van der Aalst, Mathias Weske and Dolf Grünbauer, “Case Handling: A New Paradigm for Business Process Support,” Data & Knowledge Engineering 53, no. 2 (2005): 129–162.↩︎
- Nancy G. Leveson, Engineering a Safer World: Systems Thinking Applied to Safety (MIT Press, 2011).↩︎