PostAgents, security & trust

Oversight the caller installs is oversight the caller can omit.

A founder selling AI governance software promised personal review, then his own automation ran straight past it — the same failure behind the agent incidents that made the news.

Lukman Nuriakhmetov
Lukman Nuriakhmetov
1 min read · May 21, 2026

A founder reached out to me about a role last month. His company builds AI governance software — the kind that makes AI "trustworthy and auditable." His message promised: "I'll personally review your responses before making any decisions."

I replied. He wrote back — two lines, clearly him.

Two days later, the exact same templated message landed in the same thread. Word for word. Like our conversation never happened. It cost me five minutes.

But it's the same failure behind the bigger stories — the Replit agent that deleted a production database during a freeze, the Gemini agent that wiped a developer's files, Meta's Sev 1 last month. Someone promises human oversight. The automation they installed runs right past it.

The real problem is simpler: oversight the caller installs is oversight the caller can omit.

If you build AI agents — or you're staring down EU AI Act Article 14 — where have you seen the gap between the oversight that's promised and the oversight that's real?

Tags: ai-governance · ai-agents · eu-ai-act · human-oversight