Skip to content
> ./aidex.sh_

Practice, field notes, and patterns

Evidence

Practice

  • Agents do the work here, and execution advances only once a human has cleared the gate.

    Read in fullCollapse

    The framework is our own, human-gated, and at work against a live production service. No part of it runs unattended. Constant supervision is the honest description of our role in it, and autonomy is not the claim. It has shipped a handful of changes over a period of weeks, which makes it young, in active use, and not yet a record of anything. Six mechanics decide whether its gate holds, and all six are published on /agentic-routing.

  • The gate has failed closed and stopped execution in practice.

    Read in fullCollapse

    That is the whole of what we publish about the occasion, and the bare fact is the part worth having. A gate nobody has watched refuse is a gate nobody has tested. Fails closed costs nothing to write into a design, and it means something only after a run has actually been left stopped by it. If you are assessing a gate of your own, ask whether anyone can name an occasion when it refused, then ask what happened to the run afterward. Ours refused, and execution stopped there.

  • You cannot check any of this.

    Read in fullCollapse

    The service is not named and the trail is not linked, both by our decision, so nothing in this section is something you can go and confirm for yourself. Discount it accordingly. What we can put in front of you is the mechanism. The six gate mechanics on /agentic-routing are written to be read as a specification and judged on whether a gate built that way would hold, whatever you decide about ours.

Field notes

We have committed to one of these a month. An entry with a date and no successor does more damage than no entry at all, so the date on the most recent one is what to hold us to.

One entry a month
  1. Aug2026first entryAugust 20, 2026
  2. Sep
  3. Oct
  4. Nov
  5. Dec
  6. Jan2027
  7. Feb
  8. Mar
  9. Apr
  10. May
  11. Jun
  12. Jul
  • an entry, dated
  • a month with an entry due
A twelve-month rail for the field notes, with only the first entry filled. The dashed ticks are the months still to fill.
  1. Shadow AI has gone departmental

    Shadow AI use has stopped being scattered individuals and become departmental.

    What to do

    Name an owner.

    Read in fullCollapse

    Set against roughly the past year, that is the change: teams are standardizing on tools without going through anyone, and the tool becomes the way that team works. It is harder to unwind than individual use. Asking one person to stop costs that person a habit, and by the time a department has standardized, a workflow depends on it.

    What to do

    Put one person on record as accountable for AI decisions: a name, written down, and known to the people making those decisions week to week. It is harder to do in a week than any technical control, and it is the one that changes the outcome. A test you can run today is to ask who approved the last AI tool your organization started using, and see whether the answer is a person or a conversation.

Patterns

The first thing we find, nearly every time, is that nobody owns it. Decisions about AI are being made across the organization and no single person is accountable for any of them. That is a governance failure and not a technology one, which is why it opens this list. The four gaps below are the ones that recur underneath it.

  1. 01

    No inventory of what is in use

    Nobody can produce a list of the AI tools actually running.

    Read in fullCollapse

    Every other control is then applied to a set nobody defined, which is how a policy can be carefully written and cover none of what people are using. The inventory is the precondition for the rest of this list.

  2. 02

    No decision owner on record

    Approvals do happen.

    Read in fullCollapse

    They happen informally, by several people, and nothing records who decided. Asked afterward who authorized a particular tool for a particular use, an organization reconstructs an answer instead of producing one, and a reconstruction is not something anyone can stand behind when an auditor or a customer asks.

  3. 03

    Data classification not tied to AI

    A classification scheme exists, and it predates AI.

    Read in fullCollapse

    Nothing in it connects a tier to which models may process data in that tier, so the scheme is real and unused for this purpose. What is missing is the rule attached to each tier.

  4. 04

    No AI-specific incident path

    An incident runbook exists, and it has no answer for a bad model output, a leaked prompt, or an agent that acted wrongly.

    Read in fullCollapse

    None of the three fits the categories the runbook was built around, so all three fall through it. The practical effect is that whoever meets one of them first is deciding the response while it is happening.

  • Two beliefs come up reliably at the executive level and both are wrong.

    Read in fullCollapse

    The first is that their people are not really using AI. They are, and more broadly than leadership estimates. The second is that their people are not using it well. That judgment is wrong too, and it is wrong because it was formed without an inventory of what is in use. It is a verdict on tools leadership cannot list. The two sit together, since a leader who believes usage is narrow has no reason to look hard at how good it is.

  • The obvious next heading is the assumptions that turn out to be wrong, and we do not have one to publish.

    Read in fullCollapse

    The variation across organizations is too wide to generalize from honestly, and past the four gaps above nothing recurs often enough that we would print it as a rule. A fifth pattern would be easy to write and it would be invented. What we can tell you is where the generalization stops, which is here.

Describing client work without attribution is standard practice here, which is why nothing above names an organization or attaches a date to one.

Last reviewed

Ready to secure your AI environment?

Start with a conversation about your organization's AI exposure, governance needs, and adoption goals. We meet you where you are.