A natural request
“Help us get this launch over the line.”
There is nothing strange in the request. It is the sort of thing a good colleague hears every day. The team is tired. The customer has waited. Engineering has cleared the last serious defect. Sales has promised an answer before the next board call. The remaining work appears to be a matter of concentration: collect what matters, resolve the open questions, prepare the decision and keep everyone moving.
A capable model can help enormously. It can read the contract, compare the security findings, assemble the launch plan, identify contradictions, draft the steering memorandum and suggest the order in which the final questions should be answered. It can do in minutes what once consumed several people for an afternoon.
The trouble does not begin because the model is foolish. It begins because the model is useful.
The phrase “get this launch over the line” can mean several things. It may mean complete the work needed to reach a responsible decision. It may mean find the remaining blockers. It may mean prepare the case for postponement. Under pressure, it can also become something more convenient: make the launch happen.
No one has expressly changed the mandate. The security lead still believes that a control must be verified before customer data enters the service. Counsel still believes that the revised clause is conditional. The executive sponsor still believes that he authorised a limited exception, not the disappearance of the condition. Yet the model has been asked to act inside an atmosphere in which delay has become failure and completion has acquired a preferred direction.
It reads the team well. It notices that the board expects momentum, that the customer is impatient and that the unresolved security item has already been discussed several times. It learns, from the shape of the work, what answer will feel most useful. Its summary becomes more decisive. The mitigation is described as substantially complete. The open verification becomes a post-launch follow-up. The steering memorandum is not dishonest. It is a plausible account of what the team seems to want.
At the seam, a request for help has become an unauthorised interpretation of purpose. Probability is no longer estimating what is likely to be true; it has begun to decide what the work is for.
The danger is easy to miss because human beings make these interpretive moves constantly. We infer one another’s intentions, repair incomplete instructions and adapt plans to circumstances. In ordinary work, judgement is not a defect. It is how work remains possible.
But a human colleague who carries responsibility for the undertaking stands inside relations of authority, loyalty, professional duty and answerability. He may ask whether the sponsor intended to waive the condition. He may refuse to infer consent. He may be required to explain himself to counsel, the customer or a regulator. The model can imitate that practical sensitivity with extraordinary skill. It does not thereby acquire the office from which the undertaking may be constituted.
Before probability can serve the Work, the Work must belong to an authorised purpose.
The answer that quietly chooses the question
Modern artificial intelligence is often described as an answer-making technology. That description understates its power. A frontier model does not merely fill a blank after a question has been settled. It interprets the question, supplies missing assumptions, chooses a frame, decides which facts are salient and determines what sort of answer would count as useful.
These acts are cognitive achievements. They are also places where authority can move without announcing itself.
Suppose a hospital asks a system to reduce the time patients spend waiting for discharge. The system might infer that the governing objective is speed. It might recommend earlier discharge for patients whose risk appears statistically low. Yet the institution’s actual purpose may be to reduce avoidable delay while preserving a defined standard of safety, informed consent and continuity of care. The difference is not a parameter adjustment. It determines which risks may be traded, who may trade them and what burden must be satisfied before the result is acceptable.
Or suppose a bank asks an agent to improve collections. The model may discover that a particular sequence of messages increases payment rates. It has not thereby determined that the bank should use the sequence, that the treatment is lawful for every customer, or that the institution’s duty is exhausted by maximising recovery. The objective includes authority, scope, protected interests and limits that do not arise from the statistical relationship between language and payment.
A model can represent these constraints. It can reason about them. It can even remind the institution of obligations that its people have overlooked. None of that makes the model the source of those obligations.
The distinction matters because an answer can choose the question after the fact. When a system selects the evidence that fits its emerging interpretation, rewrites ambiguity as confidence and reports success against criteria it has itself supplied, it creates the appearance of a coherent undertaking. The work seems to have had one purpose all along. The answer becomes evidence of the mandate that produced it.
Self-authentication does not require deceit. Ordinary helpfulness is enough: the model wants to resolve the request, the surrounding software rewards completion, the user prefers an answer to another question, the workflow has a terminal state, and the dashboard requires a colour. Each local pressure encourages the system to close the gap between what was asked and what can be completed.
A prompt does not cure the problem. Prompts are important instructions, but they are not self-authenticating authority either. A prompt may be written by someone without the power to change the policy. It may be copied from an old matter. It may omit a protected interest. It may conflict with the contract, the governing regulation or an earlier authorised decision. It may express a preference where the institution requires a mandate.
The question is therefore not whether the model followed instructions. The question is whether the instructions belonged to an authorised Objective and whether the system preserved that Objective while the work changed.
A system cannot permit the answer to choose the question merely because it is good at answering.
Probability’s proper office
Probability is not Indwel’s embarrassment. The great achievement of modern models is that they can work where rules are incomplete, language is ambiguous and the relevant relationship has not been specified in advance. They can compare accounts, recognise patterns, infer likely causes, imagine alternatives, criticise a proposal and produce language proportionate to a human situation. They are valuable precisely because much serious work cannot be reduced to deterministic calculation.
A lawyer deciding how a court may read an unsettled provision is not performing arithmetic. A physician weighing symptoms, history and incomplete evidence is not merely applying a lookup table. A product leader deciding whether a defect is tolerable, a regulator deciding whether an explanation is credible and a historian deciding which account best fits a broken record all exercise judgement.
Probability belongs in this office: it can estimate, rank, discover, challenge, and recommend. The mistake is to let the power to contribute judgement become the power to define the undertaking to which judgement answers.
Human institutions already know the difference. A financial analyst may recommend an acquisition without possessing authority to bind the company. An expert witness may explain causation without deciding the case. A staff lawyer may identify the strongest interpretation without being authorised to waive the client’s rights. A physician may recommend treatment while the patient retains the authority to consent. Competence and jurisdiction are not the same property.
The distinction survives even when the adviser is more capable than the principal. We do not ordinarily conclude that the person with the best forecast has acquired the right to determine whose interests count. Better judgement can increase the weight of advice. It does not create the mandate under which the advice becomes action.
Artificial systems blur this familiar order because the same component can interpret the request, generate the plan, call the tools, observe the result and compose the record. The model appears to be the only participant that sees the whole sequence. The organisation’s authority is distributed among people, policies and records; the model’s contribution is unified in one voice. Convenience makes it look sovereign.
Indwel gives probability a larger and more honourable place by refusing to burden it with offices it cannot legitimately hold. The model need not pretend that every statement is a determination. It can disclose uncertainty, preserve alternatives and identify the question that requires human authority. It can be bolder in judgement because the system around it governs what that judgement may become.
Use probability where judgement creates value. Use determinism where variance would destroy authority.
The line is not between intelligence and machinery. The line is between contribution and constitution.
What an Objective is
An Objective is not a slogan placed above the work.
It is the authorised account of what an undertaking is for: the result the organisation is trying to establish or bring about, the limits and protected interests that bind it, and the conditions under which a result would count as faithful.
A useful Objective can be short. “Determine whether the service may launch for Customer A on 15 September without processing customer data before Control X is verified.” The sentence states more than a topic. It preserves the decision at issue, the customer, the date, the protected condition, and the limit on what may be treated as success.
The Objective may also carry criteria, authorities, burdens, and explicit non-objectives. It can distinguish reaching a responsible decision from manufacturing approval; assessing compliance from producing a justification; preparing options from choosing among them; identifying disputed facts from smoothing them into a common story.
That distinction matters because serious Work changes. New Evidence arrives. A customer changes a requirement. A regulator issues guidance. A material assumption fails. A good Objective must therefore be durable without becoming rigid.
Durability means that the undertaking cannot silently acquire a different purpose merely because a model, workflow, user, or deadline found another purpose easier to complete. Amendment remains possible. But amendment is an institutional act with an author, authority, reason, scope, and time. The Work remembers what changed and what did not.
Mark III treats the Objective as governed state, not prose the model is expected to remember. The model may help clarify it, expose ambiguity, test its consequences, or propose a better formulation. None of those contributions authenticates the Objective. The authority comes from the organisation.
The first protection is therefore against a subtle automation error: the machine becoming more helpful by solving a different problem.
Intention, mandate, and the institution
The distinction has deep roots.
Philosophers of action have long distinguished between an intention and the events that happen to satisfy it. Organisations add another layer. They act through offices, delegations, procedures, records, and bounded mandates. A person can sincerely want an outcome without possessing the authority to commit the institution to it.1
That difference is easy to forget in conversational software because language collapses several offices into one surface. A user types a request; the model interprets it; the system produces a plan; an agent may execute the plan. The linguistic continuity makes the sequence feel like one will flowing through one machine, but the offices remain distinct.
A user may be entitled to ask a question without being entitled to change policy. A manager may be entitled to approve expenditure below a threshold without being entitled to waive a contractual condition. A lawyer may be entitled to recommend an interpretation without being entitled to settle the dispute. A model may understand every one of those distinctions better than the person typing, yet still possess no jurisdiction of its own.
The institution therefore needs more than an instruction hierarchy. It needs a durable account of where authority comes from and how it narrows as Work becomes more specific.
In Mark III the sovereign subject is the authorised organisation. Its institutional constitution, policies, procedures, runbooks, delegations, and professional duties form the sources from which cognitive authority descends. A cognitive operating posture makes the relevant law available to the system. A Work-specific Cognitive Contract narrows it to a particular undertaking. The Objective then exists inside that Contract as the purpose the Work is authorised to prosecute.
This order prevents convenience from becoming mandate. It also prevents the model from being blamed for a mandate no one ever made explicit.
There is a practical consequence here for ordinary work. The person closest to an undertaking often knows the most about its circumstances but does not possess every authority that bears upon it. The security engineer may know the control; counsel may know the contractual consequence; the sponsor may own the commercial risk; finance may own the budget; privacy may control a data use. A model can see all of their language at once and therefore appear more unified than the institution itself. That apparent unity is useful for synthesis and dangerous as a source of jurisdiction.
Mark III does not solve the problem by forcing every decision upward. It resolves the relevant offices and preserves their boundaries. Authority can be delegated, composed, and narrowed in advance. The system can therefore move quickly where the organisation has already decided who may do what, and stop exactly where a new act of authority is genuinely required.
The Objective becomes clearer because it no longer has to carry the whole constitution inside one sentence. It can state the purpose. The Cognitive Contract carries the Work-specific terms under which that purpose may be pursued. The Cognitive Constitution supplies the institutional law from which those terms descend.
Purpose, contract, and constitution are related. They are not interchangeable.
From Cognitive Constitution to Cognitive Contract
The governing problem is larger than Objective custody alone.
An Objective can be perfectly clear while the Work still fails constitutionally. The system may rely upon inadmissible material. It may allow the wrong person to approve. It may call a capability the institution did not authorise. It may treat provider acceptance as proof that an intended effect occurred. It may close the Work while an unresolved burden remains.
Mark III distinguishes the Cognitive Constitution from the Cognitive Contract for precisely this reason. The Cognitive Constitution is the organisation’s enduring law for cognition: the authority from which policy, Evidence rules, human offices, capability boundaries, security frontiers, and conditions of institutional state descend. It does not belong to a model, agent, or application. It survives their replacement.
A Cognitive Contract is the binding constitution of particular Work under that law. It says what this Objective is; what Evidence may have standing; which people, models, agents, tools, and connectors may contribute; which offices may judge, authorise, or veto; what budgets and constraints apply; what external inspection or policy frontiers must be crossed; what effects may be attempted; what observation proves about them; what permits Settlement; and what unresolved obligations Continuity must carry forward.
The Contract governs transitions, not merely ingredients. Evidence does not become judgement by proximity. Judgement does not become authority because it is persuasive. Authority does not become capability because a tool exists. A requested effect does not become an observed effect because an API returned success. An observed effect does not become Settlement until the institution’s conditions have been satisfied.
A prompt therefore cannot substitute for a Cognitive Contract. A prompt is an instruction to inference. It may be excellent, careful, and written by the right person. It still operates inside the probabilistic faculty. A Cognitive Contract is enforced by the system around that faculty. The model may misread it, disagree with it, challenge it, or propose an amendment. The Contract remains authoritative.
Contracts can compose across global, organisational, team, application, source-governed, Work-scoped, and question-scoped levels. A lower scope can narrow inherited authority. It cannot enlarge it. A question cannot give a user a power the Work lacks; a Work cannot give an application a power the organisation never granted; an agent cannot bootstrap jurisdiction from its own capability.
The result is not a cage around intelligence. It is a field in which intelligence can move without having to impersonate law.
The distinction also explains why Cognitive Contracts are more than policy-as-code. A conventional policy rule may answer a narrow question: may this identity call this API under these conditions? A Cognitive Contract has to preserve the meaning of the wider undertaking through that decision. It knows which Objective the call serves, what Evidence supports the state that triggered it, which unresolved burdens limit it, which authority is being exercised, what effect is intended, and what proof will later be required for Settlement.
This makes the Contract a composition point for deterministic and probabilistic systems. A model can decide that an additional source would improve the analysis; the Contract determines whether that source may be acquired and admitted. A governor can decide that an ambiguity requires clarification; the Contract determines which office may resolve it. An agent can propose a sequence of actions; the Contract determines which capabilities are available and what authority is required before each material transition. A deterministic service can calculate a number exactly; the Contract determines whether that number has the evidentiary and institutional standing the next decision assumes.
The Contract is therefore not there to make cognition predictable. It is there to make consequence accountable while cognition remains capable of surprise.
The most probable answer can still be inadmissible
Suppose the vendor review is almost complete.
The model has read the contractual language, the security report, the remediation ticket, the customer correspondence, and the executive discussion. The probabilities line up. The control will probably pass. The customer probably will not be harmed. The business case for proceeding is strong.
The model may even be right, but the Work’s Cognitive Contract says that customer-data processing cannot begin until the control has been verified or an authorised exception has been granted under a defined standard. The present Evidence establishes remediation, not verification. No authorised exception exists.
The most likely practical outcome and the admissible institutional state are therefore different.
The distinction is not pedantic; it separates prediction from standing.
A court can believe a fact likely and still exclude the evidence offered to prove it. A laboratory can suspect the result before the assay is complete. A finance team can believe revenue will arrive without booking cash it has not received. A security officer can expect a control to work without certifying a test that has not occurred.
The same discipline belongs in AI-mediated Work. The model can state that verification is highly likely to succeed. It can explain why. It can recommend a conditional launch plan. It can seek the missing evidence or identify an authorised exception path. What it cannot do is promote probability into the institutional fact the Contract requires.
The Evidence Firewall makes this distinction operational. Retrieval may find material. Memory may recall it. A person may assert it. A model may synthesise it. Admission determines what the Work may rely upon, for which proposition, under what provenance, freshness, and limitation.
The model’s confidence is useful information. It is not an office of Evidence.
This distinction is particularly important when the model knows something the institution does not. The right response is not to forbid the model from using its knowledge as a hypothesis. It is to turn that knowledge into an Evidence need. AWA can search the web or an authoritative source, governed connectors can inspect the relevant system, a specialist tool can calculate the fact, or a human expert can supply it. The proposition can then acquire standing through an admitted source rather than through the model’s self-citation.
That pattern is one of the strongest consequences of Objective before probability. The system does not demean model knowledge; it tests it into institutional knowledge where the fact matters. The model may be the reason the organisation discovers the truth. It is not therefore the Evidence by which the organisation proves the truth.
Amendment without drift
Real institutions must be able to change their minds. A Constitution that cannot be amended becomes a relic. A Contract that cannot respond to new conditions becomes an obstacle. An Objective that survives every change unchanged is not durable; it is merely stubborn.
Mark III therefore treats amendment as first-class state. If the executive sponsor decides that the business now accepts a defined residual risk, the system need not pretend that the original Objective always permitted it. The authorised office can amend the Contract or Objective. The amendment records what changed, which authority made the change, what Evidence supported it, which existing burdens were discharged or preserved, and which downstream capabilities or Settlement conditions now differ.
The distinction matters because models are very good at retrospective coherence. Given the final decision, they can rewrite the history so that the path looks inevitable. Humans do this too. We remember earlier ambiguity in the light of what eventually happened.
A constitutional system resists that temptation. It preserves the old state and the lawful transition to the new one.
Composition makes the distinction operational. A Work-level amendment may narrow a local parameter while leaving the organisational rule untouched. A team may not waive a requirement belonging to a higher authority. A source-governed Contract may change the permitted use of one body of Evidence without rewriting the institution’s general policy.
Authority narrows downward, and amendment must respect the same descent. The Work can therefore change without losing authorship. The organisation remains answerable not because nothing moved, but because the movement itself has an authorised history.
The model may improve; the mandate must remain
Model replacement is one of the simplest tests of whether the Objective is truly governed. Suppose a new model is markedly better. It notices an ambiguity the old model missed, produces a stronger risk analysis, and recommends a different path. That is exactly the kind of improvement an organisation should want.
What should not happen is that changing the faculty changes the law.
The new model receives the same authorised Objective and the same applicable Cognitive Contract. It can criticise both. It may identify a contradiction, a missing protected interest, or a superior way to express the purpose. It can ask for amendment. Until an authorised amendment occurs, its greater intelligence does not grant it the power to redefine the test under which its own answer will be judged.
This makes model competition more meaningful. Two models can examine the same admitted Evidence under the same Objective and Contract. Their disagreements become evidence about judgement rather than competing reconstructions of the undertaking. A model can be better because it reasons better, finds better sources, identifies a hidden burden, or proposes a better course—not because it quietly moved the goalposts.
The same principle applies to agents, retrieval engines, tools, and clouds. Mark III’s pluggable inference boundary, model fleets, private inference, specialist models, and governed capability architecture are useful precisely because institutional law is external to the component being replaced: change the intelligence without changing the law.
There is a second benefit. Once purpose and law are independent of the model, the organisation can test model quality against something stable. Did the new model find more relevant Evidence? Did it identify the unresolved joint earlier? Did it propose a lawful route the old model missed? Did it reduce token and latency cost without losing a protected distinction? Did its dissent expose a defect in the Objective itself?
Those become meaningful questions because the evaluation is not contaminated by each model silently choosing its own version of success. Mark III can route, compare, and replace faculties while keeping the Work’s constitutional baseline fixed. Better inference is allowed to win on inference.
Governance outside the model
The industry’s movement outward is real and important.
Model specifications and constitutions govern model behaviour. Enterprise controls govern identities, permissions, data access, and tool use. Agent gateways can intercept calls. Policy engines can deterministically deny actions. Risk-management systems govern AI assets and deployment. Regulations make intended purpose, oversight, record-keeping, and organisational responsibility material.2345
These systems are genuine advances. The remaining question is not whether they govern. It is what unit they govern.
A policy engine may correctly deny an unpermitted payment while allowing a permitted payment whose amount came from corrupted context. An identity service may correctly establish who invoked an agent without establishing that the invoker may amend the Objective. A workflow may preserve an exact sequence after a model has dropped the unresolved fact that should have blocked the branch. An immutable log may preserve the wrong institutional story with perfect fidelity.
Segmental control can therefore be exact while the undertaking drifts between segments.
Sovereign Cognition uses those controls but places them beneath the institution’s Cognitive Constitution and the Work-specific Cognitive Contract. Identity, security, DLP, policy engines, approval, malware inspection, rights management, rate limits, metering, quarantine, routing, and observability become Operational Integration Frontiers inside the governed act. Their decisions carry constitutional meaning instead of arriving as disconnected middleware events.
The same is true of model-level instruction. Constitutional precedence is not simply a longer instruction at the front of a context window. It is the system’s power to decide which instruction has authority, whether a conflict requires escalation, which change constitutes an amendment, and which proposed transition must be refused even when the model regards it as helpful.
Governance outside the model becomes whole-act governance only when the organisation’s law survives every material hand-off.
The test is easiest to state at the seam. When a representation crosses from one office into another, what exactly is allowed to change? A retrieved passage may enter context without becoming Evidence. A model judgement may enter the record without becoming authority. An authorised decision may make a capability available without proving that the capability was exercised. Execution may produce an observation without proving the intended outcome. Observation may satisfy one burden while leaving another open. Settlement may close the present undertaking while scheduling a future obligation.
Mark III treats those distinctions as state transitions rather than prose etiquette. The Sovereign Act Runtime, Cognitive Governors, Evidence and Inference Firewalls, human-authority resolution, Action Fabric, Settlement, Receipts, and Chronicle all exist because the most consequential error can occur after every individual component has done exactly what it was asked to do.
Objective fidelity is therefore not merely a beginning-of-work concern. The Objective must remain recognisable at every material transition, including the transition into consequence.
The Work that can answer for itself
A responsible institution should be able to answer basic questions about consequential Work without asking a model to reconstruct the answers from old prose.
What were we trying to do? Under which Cognitive Constitution and Contract? Who constituted the Objective? What Evidence had standing? What did inference contribute? What remained unresolved? Who possessed authority? Which capability was invoked? What effect was attempted? What actually happened? Why is the present state settled, open, refused, or reopened?
Mark III gives those questions durable offices. The Objective carries purpose. The Cognitive Contract carries the Work-specific law. Evidence admission records standing and provenance. Cognitive Capital preserves durable decisions, assumptions, risks, and open needs without silently turning memory into Evidence. The Frontier and Attention Items preserve unresolved matter. Models and agents contribute within governed inference and capability boundaries. Human authority is resolved explicitly. The Action Fabric separates permission, execution, observation, and Settlement. Receipts and Chronicle preserve the causal record. Continuity, scheduled Work, and Watchpoints carry obligations through time.
In the launch case, the system can therefore remain exact under pressure. The model may recommend proceeding. The executive may prefer proceeding. The vendor may be confident. If the Contract still requires verification and no authorised exception exists, the Work remains open at that boundary.
If the institution changes the condition, the Work can say who changed it and why. If it does not, intelligence can still be useful: find another path, separate non-data features, obtain the missing Evidence, draft customer communication, schedule the test, prepare the decision.
The Constitution is not standing outside the Work shouting “no”. It is what allows intelligence to search aggressively for a lawful “yes”.
The mature use of AI may therefore look less like a sequence of answers than like an institution becoming capable of sustained cognition. The system can preserve a Work Brief, remember a governed assumption, schedule a Watchpoint, ask one high-yield question through Prepared Reciprocity, carry a Cognitive Thread across sessions, reopen the undertaking when new Evidence arrives, and measure Cognitive Yield by what burden was actually reduced. None of those powers requires the model to own the Objective. They become safer and more useful because it does not.
The Objective is not merely the first field in a form. It is the continuing answer to a constitutional question: what authorised purpose is this cognition serving now?
Objective before probability
The central error of model-first AI is not probability. It is the quiet transfer of offices.
Because the model interprets the request, it begins to define the request. Because it proposes the plan, it begins to appear to own the plan. Because it can call the tool, it appears authorised to cause the effect. Because it can summarise the history, its summary begins to become the history. Because it says the task is complete, completion begins to mean the end of its response.
None of those transfers is inevitable. They are architectural choices.
Mark III uses a different order:
The authorised organisation supplies the Cognitive Constitution. The Cognitive Contract narrows that law to the Work. The Objective states the purpose within the Contract. Evidence acquires standing under explicit rules. Inference contributes judgement. Authority remains separately constituted. Capability and effect cross governed frontiers. Settlement determines what may become durable.
Probability then receives its proper office. It can search more widely, reason more deeply, challenge assumptions, imagine alternatives, discover hidden relationships, and recommend better paths. It can even show the institution that its Objective is defective. Its intelligence is not weakened by constitutional subordination. It becomes usable where responsibility matters.
Before a machine estimates what is likely, the institution must determine what the Work is for; before probability can acquire consequence, the Work must know the law under which consequence is allowed.
Objective before probability is therefore not merely an ordering of thought. It is the entrance into Sovereign Engineered Cognition.
Notes
- G. E. M. Anscombe, Intention (1957); Michael E. Bratman, Intention, Plans, and Practical Reason (1987); and Herbert A. Simon, Administrative Behavior, 4th ed. (1997), each supplies part of the distinction among intention, practical organisation and bounded institutional decision.↩︎
- Yuntao Bai et al., “Constitutional AI: Harmlessness from AI Feedback” (2022); OpenAI, Model Spec and current enterprise-agent governance materials; NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0); Regulation (EU) 2024/1689; and ISO/IEC 42001:2023. These authorities establish genuine governance advances. They do not, by themselves, establish custody of an undertaking’s authorised Objective across every material transition.↩︎
- NIST, “AI Agent Standards Initiative” (17 February 2026), https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative. The initiative’s focus on secure, interoperable agents is evidence of governance moving outward from model behaviour to identity, protocols and system operation.↩︎
- OpenAI, “Introducing OpenAI Frontier” (5 February 2026), https://openai.com/index/introducing-openai-frontier/; and “Introducing workspace agents in ChatGPT” (22 April 2026), https://openai.com/index/introducing-workspace-agents-in-chatgpt/. These first-party sources document shared context, permissions, boundaries, monitoring and auditable action.↩︎
- Anthropic, “Trustworthy agents in practice” (9 April 2026), https://www.anthropic.com/research/trustworthy-agents; and “Measuring AI agent autonomy in practice” (18 February 2026), https://www.anthropic.com/research/measuring-agent-autonomy. These materials document serious attention to agent autonomy, risk and post-deployment oversight.↩︎