The Record That Isn't a Rule
A permission file, a compliance calendar, a public register. Three institutions produced something legible. None of them produced something
Three documents, produced this year by three different kinds of institution, for three different audiences, with no person in common anywhere in their drafting.
A repository file that tells an autonomous agent what it may do. A revised compliance calendar that tells an industry when an obligation begins to bind. A public register that tells anyone who asks how many AI systems an administration has deployed. We have written about each of them separately before now. Set side by side, they stop looking like three stories and start looking like one mechanism, filed three times under three different headings.
The mechanism
Each document answers a question that a lawyer, an auditor, or a journalist already knows how to ask. AGENTS.md answers what is this agent permitted to do. The Act's revised timeline answers when does this obligation begin to bind. A register - the OMB inventory in Washington with its 3,611 entries, the Article 71 database in Brussels - answers how many of these systems exist.
Permission, schedule, count. Three of the oldest instruments of institutional record-keeping, each executed competently, each a genuine improvement on having nothing.
None of them answers the question a pre-mortem forces, which is not about permission, schedule, or count. It is: imagine this has already gone wrong - what, specifically, was never checked?
A permission document doesn't check anything. It states what checking would look like, if anybody were architecturally required to do it.
A schedule doesn't check anything. It states the date after which checking becomes mandatory, which is a way of formally agreeing not to check before then.
A count doesn't check anything. It states that a thing exists, in a line no longer than a sentence, in a list of thousands of such lines, which is a way of being thorough about presence and silent about behaviour.
One scenario, all three failures
Run the exercise across the seam where the three meet, because in practice they do meet: a single deployment can be governed by all three at once.
It is January 2028. A national social security agency in a Member State has been running an agentic pipeline for two years to assess eligibility for benefits (Annex III, point 5(a), squarely high-risk, registered in the EU database since 2026). The agency's internal governance for the agent is a permissions file: what data it may query, what determinations it may finalise without human review. Its conformity assessment obligations became binding five weeks ago, on 2 December 2027. A journalist has just published an account of a wrongful termination of benefits the system processed eleven months ago. Write down what was never checked.
Four answers, and they are the same four as last time, which is the finding rather than a rhetorical convenience.
The permission file was mistaken for an enforcement mechanism, because nobody had built one and the document was what existed instead.
The obligation that would have required independent verification of exactly this kind of determination was not yet binding, because the calendar and the harm do not share a clock.
The classification "high-risk" was assigned once, at registration, and never re-tested against two years of what the system actually did.
And the register entry (one line, in a database nobody reads to the end of) is the only record that the deployment existed at all, which makes it also the only place a pre-mortem could have been run, and it is not a place anyone runs one.
Change the jurisdiction and the shape survives. Put the same agency in Washington and the calendar answer drops out, because there is no binding federal conformity deadline to miss; what replaces it is worse, which is that there was never a date at all. The inventory still lists the system. The permission file still substitutes for a control. The exemption that needs no exemption, because there was never a rule to be exempt from.
A fourth level
Isonomia distinguished three levels at which a norm can fail. Morality is personal: Kant's test, whether you could will your private rule into a universal law. Ethics is social: a structural condition of having a community at all. Law is formal: the written minimum, backed by force.
These three documents fail at a fourth level underneath all of them; one that does not require the norm to be bent, evaded, or even under-enforced. It requires only that the record of an intention be treated as the fact of a control.
The AI Act's high-risk obligations are not weak law. AGENTS.md is not bad documentation. The OMB inventory is not a cover-up; by the standards of federal transparency it is unusually forthcoming, and the Article 71 database is a genuine piece of public infrastructure that did not exist five years ago. Each is an honest artefact of an institution trying to respond to something moving faster than its accountability machinery.
The response, in all three cases, was to produce something legible.
Legibility is what audits run on, what press releases cite, what a regulator can point to in a hearing. It is not the same operation as verification, and the distance between the two does not show up until the day something has already gone wrong - which is precisely the day a pre-mortem is designed to simulate in advance, for free, before the eleven months have passed.
This is the same defect the control that was tested once found from the other end. There, the auditor asked whether the control existed and whether it ran, and was shown something true both times, and the thing that went unasked was what the control had been tested against. Here there is not even a control... Only the document that describes where one would go. The auditor is shown something true in that case too.
Where this series has been standing
This site used the word once before, in its first article, in a single paragraph it then left alone for three months. Across three follow-ups, the same missing exercise has turned up at three different scales - a codebase, a continent's regulatory calendar, a government's own accounting of itself - worn by three institutions that individually did nothing careless.
That is the part worth sitting with. This was not a failure of diligence. Each document is more thorough than its predecessor would have required. The failure is upstream of diligence: nobody asked the question that does not care how thorough the document is, because the document was never going to be asked to answer it.
The Clause is entirely comfortable in all three. It has no quarrel with a permission file, a calendar, or a register - they are hospitable in the way an empty room is hospitable, and it has furnished a great many of them. What it cannot abide is a control, which has the tiresome property of doing something whether or not anyone is currently reading.
Write the permission file. Set the compliance date. Count the systems. Do all three well, better than anyone before you did them. None of it is governance until somebody has been made to sit down, on purpose, and describe the day it fails, not because the paperwork was wrong, but because paperwork was never the kind of thing that could have been right or wrong about this. It was only ever the kind of thing that could exist, or not.
Three documents exist.
The question this series keeps asking is the one none of them were built to answer. Klein budgets twenty to thirty minutes for it. This site, in May, claimed ten. Either figure is available to anyone, at any point before the eleven months start running, and the reason it goes unasked has never once been the cost.