Does this give an organisation regulatory compliance?
No, and no product can promise that. It enforces controls and produces evidence. Regulatory interpretation, conformity assessment and the management system stay with the organisation and its accountable people.
Would it have prevented the 2026 lab incidents?
Not on its own. Those were containment failures during testing with safeguards deliberately switched off. The shared lesson is that a rule must be enforced by the system, not stated in an instruction, and that nothing should be released without authority and evidence. A governed runtime protects the paths that pass through it; sealing the environment is a separate responsibility.
Doesn't a cloud agent gateway already deny actions by default?
Yes, and the research names it as the closest precedent: it authorises tool calls. What this adds is policy over the consequence of the content, checkers whose measured qualification is cited in each decision, approval bound to a verified licence, a permit bound to the exact output, and one evidence record for every audience.
Does governance make the AI model trustworthy?
No. It does not change what happens inside a model. It makes an agent's actions permissioned, bounded and provable: what it may do is decided outside the model, before the action, and the proof is created as it happens.
Were the ten domains built by independent teams?
No. They were built by the author as proof packs, not finished products. They show the core did not need to change; independently built domain packs are the next, stronger test.
Are the identity and licence checks connected to real registries?
Not yet. The mechanism and its fail-closed behaviour are implemented and tested; the connections to real identity providers and licence registries are test adapters today.
Is it running as a regulated production system?
Not yet as a certified production deployment. The authority path has been measured against real signing hardware and write-once storage under sustained load; full production validation comes next.
What does it not protect against?
A compromise of the trust directory itself, a malicious approver who holds a valid licence (that approval is attributable, not impossible), a malicious host, and a wrongly written policy. It proves which rule was in force, not that the rule was legally right.