If Vendors Are Building Their Own AI Guardrails, Why AreHumans Still Doing the Checking?

Every company in Fortune's account this week of how enterprises are governing AI agents shares one trait the story never names. Cisco built its MyAgent platform on Cisco's own compute, network, security, and observability products. Intuit built security, risk, and fraud tracking into GenOS, the platform behind Intuit's own customer software. Workday's agent system of record and ServiceNow's AI Control Tower govern Workday's and ServiceNow's own agents, and both are sold to customers as products. In each case the party building the agents, the party running them, and the party checking them is the same company. Fortune's John Kell presents this as chief information officers racing to put guardrails around agents. It is also four vendors grading their own homework, as the graphic below lays out.

The market's verdict on that arrangement arrived in the same news cycle. A Harris Poll survey for Collibra found nine in ten organizations deploying autonomous agents and 76 percent hitting critical roadblocks moving them into production. Eighty-seven percent of decision-makers say their teams regularly re-verify the context their agents rely on. Just over half report significant staff hours reviewing and correcting agent output before it goes live, rising to 64 percent at companies above $100 million in revenue. Collibra's chief executive drew the conclusion himself: if people have to validate every response, the business value of automation disappears. The figures are summarized in the second graphic.

AI was sold as removing steps from enterprise workflows. The survey shows it adding one, a human verification step at the end of every agent's work. Collibra attributes the failures to weak data foundations, which is the problem Collibra sells against. Wheelhouse Advisors reads the same numbers differently. People re-verify agent output because the only check on that output comes from the platform that produced it, and no one running a regulated enterprise accepts a self-issued assurance. Re-verification is what a control function does when no independent control exists.

Why the Vendor's Tower Cannot Produce Trust

The first reason is the oldest principle in assurance. No public company attests to its own financial controls without an outside auditor, and no regulator accepts a bank's own model validation as the final word. The frontier labs conceded the same point at the model level this week: Dario Amodei's essay called for independent evaluators with employee-level access inside the labs, and Fortune opens its story with that call. An enterprise cannot hold its agents to a lower standard of independence than the labs are now accepting for the models behind them.

The second reason is structural. An agent that resolves a compensation dispute touches human resources, finance, legal, and the general ledger in one pass. ServiceNow's tower sees the ServiceNow steps. Workday's registry sees the Workday identity. Microsoft's Agent 365 sees the Microsoft ecosystem. Each vendor's control is honest about its own actions and blind to the outcome across the whole process, because no vendor holds the map of how that process serves a business goal, which assets it runs on, and which controls govern it end to end. ServiceNow's chief executive has claimed the role of managing everyone else's agents. A company with thousands of its own agents in the same environment cannot be the independent party, however capable its tooling.

Even the two companies that built in-house recognized the problem in their organization charts. Cisco routes every employee-built agent through a central approval team separate from the builders. Intuit made its security, risk, and fraud function a distinct part of the GenOS design from the first sketch. Separating the checker from the doer is the instinct. Putting the checker outside the vendor stack is the architecture.

What the Independent Check Looks Like

The answer is not another tower. It is a risk record that sits outside every vendor's platform and holds what no single vendor holds: the enterprise's goals, the processes that serve them, the assets those processes run on, the policies that apply, the risks in play, and the controls that govern them, all connected, with every agent mapped to the process it acts in and the controls it is subject to. From that position an independent IRM system does one of two things. It checks agent outcomes directly against the record, or it verifies the checks each vendor's tower has already made, the way an auditor tests management's controls instead of re-performing every transaction. Either way the human steps out of the loop, because something independent has stepped in. The third graphic shows where that record sits relative to the four towers.

This is the governance road to Autonomous IRM that Wheelhouse Advisors has mapped: IRM for AI, the discipline of governing AI systems as risk-bearing entities in their own right. The model describes five layers of that discipline. The vendor-native towers in Fortune's story are building several of them well inside their own stacks. The one they cannot supply for themselves is Verification and Audit, and its absence is what the 87 percent are compensating for by hand.

That gives buyers a single question to put to every agent vendor before the next contract: who verifies your tower's verdicts, and where does that record live? If the answer is inside the vendor's own platform, the enterprise is buying self-reporting, and the re-verification hours will keep arriving on the payroll. If the answer is an independent IRM record that the enterprise itself owns and controls, the vendor's guardrails finally get checked by someone other than the vendor, and the humans can stop re-verifying. The full Autonomous IRM architecture, including where the vendor towers fit and where the independent check belongs, is available on The RTJ Bridge at wheelhouseadvisors.com/rtj-bridge/the-two-roads-to-autonomous-irm.

References

1. Kell, John. "AI agents are going rogue. CIOs are racing to put guardrails around them." Fortune, CIO Intelligence, September 16, 2026. https://fortune.com/2026/09/16/ai-agents-are-going-rogue-cios-are-racing-to-put-guardrails-around-them/

2. Collibra. "New Survey from Collibra by The Harris Poll Finds 72% of Tech Decision-Makers Feel AI Initiatives Today Are Falling Short." Press release, September 16, 2026. https://www.collibra.com/company/newsroom/press-releases/new-survey-from-collibra-by-the-harris-poll-finds-72-of-tech-decision-makers-feel-ai-initiatives

3. Amodei, Dario. "We Must Pace the Frontier." September 12, 2026. https://darioamodei.com/post/we-must-pace-the-frontier

4. Fortune. "Your company's AI could delete everything in 9 seconds. ServiceNow wants to be the kill switch." May 6, 2026. https://fortune.com/2026/05/06/servicenow-kill-switch-ai-agents-bill-mcdermott/

5. Wheeler, John A. "The Two Roads to Autonomous IRM." The RTJ Bridge, September 3, 2026. https://www.wheelhouseadvisors.com/rtj-bridge/the-two-roads-to-autonomous-irm

Ori Wellington

Orion “Ori” Wellington is the lead editor for The RiskTech Journal and The RTJ Bridge, where he helps shape editorial direction, guide strategic narratives, and support media relations across Wheelhouse Advisors. As a digital editorial advisor, Ori synthesizes trends in risk, technology, and governance, drawing from roles modeled on information security, risk analytics, and IT leadership.

Part of Wheelhouse’s AI-augmented research team, Ori works to distill complex signals into actionable intelligence—bridging expertise across domains and elevating the voice of integrated risk thinking.

https://wheelhouseadvisors.com
Next
Next

IRM Market Brief: September 8 to 14, 2026