Abstract
This paper examines where final authority should sit once capable AI systems are embedded in organizational workflows. It compares two governance models:
-
Frontier-Provider Sovereignty: This model assigns privileged authority to the provider of the most capable models, reflected in contemporary arguments for frontier-model testing, release gating, transparency duties, and compute-related controls.
-
Action-Centered Deployer Sovereignty: This model places final authority over high-impact actions with the organization that authorizes the action, embedding it in a business process and bearing the downstream legal, operational, and commercial consequences.
The paper combines comparative reading of public governance frameworks with implementation-informed analysis of runtime heterogeneity and enterprise control requirements. It compares the EU AI Act guidance, the NIST AI Risk Management Framework, Singapore's Model AI Governance Framework for Agentic AI, recent Japanese AI policy instruments, and Canada's voluntary code and managerial guidance. Across these materials, the paper finds stronger support for distributed operational accountability than for unilateral frontier-provider control.
Furthermore, it argues that rapid enterprise adoption, declining provider transparency, and widening control gaps increase the value of a portable governance layer centered on governed action rather than on provider-native session objects. The conclusion is layered rather than absolutist: strong upstream authority remains justified for frontier capability gating, but final authority over concrete enterprise action is better located with the deployer and consequence-bearer.
Blogger's Review: This paper provides deep insights into the authority issues in AI governance, emphasizing the importance of distributed responsibility in a rapidly evolving technological landscape. This research offers valuable perspectives for future AI governance that are worth noting.