VERIK / V100 / 20 JUL 2026
Five CategoriesGovernance

The Traceable Object That Was Not Yet Traced

On July 17, 2026, the Chair's Statement of the 2026 World Artificial Intelligence Conference and High-Level Meeting on Global AI Governance was issued from Shanghai after a four-day convening attended by heads of state and the Secretary General of the United Nations. Delegations from more than one hundred countries and international organizations were listed as present. The statement carried fifteen numbered provisions. The ninth provision is the one that will be read in policy shops for the rest of the year.

That provision reads, in full: "AI agents, as new forms of AI products and services, must operate with clearly defined decision-making authority and behavioral boundaries and mechanisms for behavior tracing and risk alert."

Two days earlier, on July 15, the joint Implementation Opinions on Standardized Application and Innovative Development of Intelligent Agents issued in May by the Cyberspace Administration, the National Development and Reform Commission, and the Ministry of Industry and Information Technology of the People's Republic of China took effect. Those Opinions establish three tiers of agent decision authority (user-reserved, user-authorized, autonomous within scope), a filing and compliance-testing regime for agents deployed in sensitive sectors including healthcare, transportation, media, and public safety, and a product recall mechanism for agents that fail those tests.

Read together, the two instruments do something few governance texts before them have done. They name the artifact by function. The WAIC statement does not describe a product line, a specific model class, or a firm. It names "AI agents" as a category of software that must operate with structural properties: bounded decision authority, bounded behavior, traceability of that behavior, and an alert channel for risk. The Implementation Opinions, released ten weeks earlier and now operative, extend the naming to sectoral duty (filing), to procedural test (compliance), and to a remedy (recall).

The Second Naming in Ninety Days

This is the second governance instrument in three months to name AI agents as a distinct regulatory class. On July 16, one day before the WAIC statement, the European Commission's final specification decision under Article 6(7) of the Digital Markets Act named third-party AI assistants as a class of software entitled to interoperability with the Android operating system. The DMA instrument names the class by function (invocation, context, actions on apps and operating system, access to resources) and commits the regulator to a thirty-one-month implementation schedule.

The WAIC statement names the class by structural attribute (decision authority, behavioral boundary, behavior tracing, risk alert). The Chinese Implementation Opinions name the class by sectoral scope and by remedy. Three instruments, three continents, three different naming conventions, one shared move: the regulator has stopped waiting for the market to define what is being governed.

The shared move is not the story here. The story is what each instrument declines to specify next.

Behavior Tracing, Undefined

The ninth WAIC provision uses the word "mechanisms" for behavior tracing. It does not say what a behavior-tracing mechanism is at the substrate layer. It does not say whether the trace is produced by the model, by the runtime around the model, by an external observer, by a mandatory logging surface, by a cryptographic attestation, by a heartbeat protocol, or by an audit contract negotiated after deployment. It does not say who reads the trace, on what schedule, or against what specification. It does not say whether a trace that shows a violation is admissible before which forum. It does not say whether the absence of a trace is itself a finding.

The Implementation Opinions provide more procedural texture. They require filing, they require testing, and they establish recall. What they do not do, on public reading, is name the specification against which an agent's behavior is checked at runtime, nor the observation surface that produces evidence sufficient to trigger the recall. Filing is a paperwork surface. Testing is a pre-deployment surface. Recall is a post-incident remedy. None of these is behavior tracing at the tempo at which agents operate.

The gap between "behavior tracing" as a stated governance function and "behavior tracing" as an instrumented artifact is now a policy object in its own right. The research literature has begun to fill in the shape of what the artifact would need to be. A May 15, 2026 paper by Alamdari, Klassen, and McIlraith describes runtime monitors specified in linear temporal logic that intervene on agent violations, independent of the agent's own policy. A July 16, 2026 preprint by researchers at Delft and Utrecht reframes penetration testing for AI-enabled systems from resource compromise to Behavioral Objective Violation, arguing that the failure mode a governance regime should track is behavioral rather than infrastructural. Both papers are attempts to name the object that WAIC provision 9 requires and does not describe.

The academic proposals sit outside the governance instrument. The governance instrument sits outside the runtime. The runtime sits outside the model. The model sits outside the deployment. Each layer refers to the next by function and defers the specification.

What Sovereignty Names Requires Instrumentation

When a governance instrument names an object by function, three things follow. The object becomes a target for enforcement. The absence of the object becomes actionable. The specification of the object becomes contested space, because whoever writes the specification writes the enforcement.

The WAIC statement, by virtue of being an intergovernmental communiqué rather than a rule, delegates the specification downward without naming the delegate. The Implementation Opinions delegate to CAC and to sector regulators. The DMA decision delegates to Alphabet and to the Commission's periodic review. None of the three instruments names the entity that will hold the specification of a behavior-tracing mechanism suitable for the class of software each instrument governs.

This is not a Chinese governance question. It is not a European governance question. It is a question about what a governance artifact does after the artifact has named the object it means to govern and before any operator has instrumented the naming.

What Remains on the Table

The governance artifact is retained. The governance function is not.