State of Agent Governance — Edition 1: Two Regulatory Clocks Are Now Enforced

Agent governance has crossed from policy aspiration to enforced obligation — and the differentiator is now proving, per decision, that the policy was enforced before data crossed a boundary.

By Containment.ai Research  ·  Published August 14, 2026  ·  Product status: Trust page →
One control plane, three moments of risk. The same deterministic discipline governs three boundaries: the human prompt (AI Chat Firewall, between an employee and the AI provider), the agent action (Agent Governance, between an agent and a tool or system), and the mission boundary (Mission Authorization Gateway, between an AI system and an edge, domain, or OT environment). All three run intercept, canonicalize, evaluate, enforce, audit.
FIG. A — ONE ENFORCEMENT LAYER, THREE MOMENTS OF RISKCONTAINMENT.AI

A Containment.AI research edition for defense & national-security AI leaders. Every external figure below is quoted from a primary source (linked); every telemetry figure is from Containment.AI's own platform analytics.

The one-line thesis

Agent governance has crossed from policy aspiration to enforced obligation. Two regulatory clocks — the EU AI Act and CMMC — now carry fines and award-eligibility consequences on fixed dates. For defense and national-security operators, the differentiator is no longer having an AI policy; it is being able to prove, per decision, that the policy was enforced before data crossed a boundary. That is a runtime, deterministic, signed-record problem — not a checklist.

1. The regulatory clock is now enforced, not aspirational

EU AI Act — GPAI provider obligations. Per the European Commission's official guidelines page (updated 28 April 2026):

  • "From 2 August 2025, the obligations for providers of GPAI models entered into application."
  • "From 2 August 2026, the Commission's enforcement powers enter into application. The Commission will enforce compliance with the obligations for providers of GPAI models, including with fines."
  • "By 2 August 2027, providers of GPAI models placed on the market before 2 August 2025 must comply."

Source: European Commission, Guidelines for providers of general-purpose AI models (fetched 2026-08-04).

CMMC — the 48 CFR final rule. Per the DoD Final Rule published in the Federal Register (Vol. 90, No. 175):

  • The Final Rule (48 CFR Parts 204, 212, 217, and 252 — DFARS) was formally published in the Federal Register on September 10, 2025, with an effective date of November 10, 2025.
  • Contracting officers will begin incorporating the updated DFARS 252.204-7021 and 252.204-7025 clauses into new DoD solicitations, making CMMC certification a prerequisite for award eligibility.
  • Beginning November 10, 2025, CMMC will be a requirement for eligible DoD contracts, with a three-year phased implementation culminating in full enforcement by November 2028.

Source: DoD Final Rule — "Cybersecurity Maturity Model Certification (CMMC) Program," 48 CFR Parts 204, 212, 217, 252; Federal Register Vol. 90, No. 175, Sept 10, 2025 (fetched 2026-08-04).

Why these two matter together for the defense buyer. CMMC gates whether you can win the contract; the EU AI Act gates whether your GenAI can operate in-market without fines. Both regimes reward the same underlying capability: a verifiable, non-repudiable record that a control was applied at the moment data or an action crossed a boundary. Neither is satisfied by after-the-fact log aggregation.

2. What enforcement-first governance looks like at volume

Most AI-governance tooling observes and maps posture. Containment.AI's model is different: intercept at the boundary, evaluate deterministically before the call completes, enforce, and record a matched audit-evidence artifact for every decision. In the trailing 30 days, across Containment.AI platform environments (including design-partner and evaluation deployments), the platform recorded:

  • 72,407 enforcement decisions logged (30d)
  • 72,407 matched audit-evidence records captured (30d)
  • 1 : 1 decisions to audit records
  • 7,321 successful browser-extension auths (30d)

The load-bearing number is not the volume — it is the 1:1 pairing. Every single enforcement decision produced exactly one captured audit-evidence record, with zero drift between the two counts. That is the mechanical property a CMMC assessor or an EU AI Act enforcement request actually needs: not "we have logs somewhere," but "every governed action has a corresponding, contemporaneous evidence record." Governance that can't guarantee that pairing produces gaps — and gaps are exactly what auditors and adversaries find.

Source: Containment.AI platform analytics (PostHog), events enforcement_decision_logged, audit_evidence_captured, extension_auth_success, queried 2026-08-04, trailing 30 days. Figures reflect platform activity including seed/design-partner/evaluation environments; they are a demonstration of the enforcement-and-evidence mechanism, not a paying-customer count.

3. The gap the category still leaves open

The agent-governance category is maturing along two complementary layers, and defense buyers should understand which problem each solves:

Layer What it does What it does NOT do
Agent-inventory / GRC posture (governance-management tooling) Discovers agents, maps them to frameworks, tracks control ownership and readiness. Does not stand between the agent and the data at runtime; cannot deterministically block a non-compliant action before it executes.
Runtime boundary enforcement (the gateway pattern) Intercepts every agent↔data / agent↔model crossing, evaluates policy pre-execution, enforces deny/allow, and emits a signed evidence record per decision. Is not a replacement for org-wide GRC posture management — it is the enforcement + evidence layer that GRC posture assumes exists.

For a forward-deployed, DDIL (denied/degraded/intermittent/limited-bandwidth) or air-gapped defense environment, only the second layer is viable: you cannot rely on a cloud posture-scanner to stop a data-crossing on a disconnected edge node. This is the wedge for the Mission Authorization Gateway.

4. What this means for the defense buyer — this quarter

  • DoD prime / supplier: With CMMC in-contract since 10 Nov 2025 and award-eligibility gated on SPRS-posted status, every AI/agent workflow touching CUI needs a boundary that produces defensible, contemporaneous evidence. This is buyer context, not a Containment.AI certification claim — our value is producing the evidence artifact those assessments consume.
  • Aerospace OEM CISO: Multinational programs increasingly touch both DoD (CMMC) and EU (AI Act) obligations. A single deterministic enforcement-and-evidence boundary is cheaper to defend than two parallel compliance stacks.
  • Classified-intel / Defense-Tech autonomy lead: Edge-deployed, non-bypassable enforcement with a signed decision receipt is the difference between "the agent probably followed policy" and "here is the record proving it did, before the action fired."

Containment.AI's Mission Authorization Gateway is a deterministic enforcement layer for AI agents in defense and critical-infrastructure environments. It intercepts, evaluates, and issues signed decision receipts on every agent action — before execution. Learn more at containment.ai/platform.

READY TO CLOSE THE GAP?
Deterministic AI governance for regulated and mission environments.
Request a 30-minute Boundary Review → Apply to the Design Partner Program → Keep controlled data out of public AI →