DEV Community

Cover image for AI Governance Must Be Runtime and Deterministic
Nelson Amaya
Nelson Amaya

Posted on Originally published at selfalignmentframework.com

AI Governance Must Be Runtime and Deterministic

I follow the AI governance news closely, and recently I have been hearing a lot of chatter about AI governance harnesses. I think the enterprise industry is slowly waking up and realizing that Large Language Models (LLMs) need a cage.

I actually like the idea of thinking about AI governance in terms of harnesses. SAFi is technically a harness itself, but the way the rest of the industry is approaching the problem is completely backward.

Take a tool like Claude Code. It is an agentic harness, it has a software layer built around the LLM to give it tools, memory, and execution capability. But in that setup, the LLM is still the star of the show. It executes and makes decisions on its own.

SAFi, on the other hand, makes the LLM a substrate of its thinking process. In SAFi, the LLM is just another step in the execution pipeline. The LLM is not in charge; it is simply a component in the loop.

Because the LLM is the reasoning module, it can propose an action. But that action must first be approved by an independent module. That approval module is pure Python, it is completely blind. It cannot reason; it just executes based on deterministic rules.

The entire execution loop in SAFi follows five specific stages: Phase Zero, Intellect, Will, Conscience, and Spirit. Out of these five slots, only the Intellect and Conscience invoke an LLM because they actually require semantic reasoning. The rest of the loop is entirely deterministic Python code.

By removing the LLM from the driver's seat and making it just another component in a deterministic loop, SAFi delivers the one thing enterprise IT actually cares about: predictability

Top comments (3)

Collapse
 
murali_gour_13cd7a6a6db2c profile image
Murali Gour •

The substrate framing is exactly right. The failure mode of most agentic systems is that the LLM is doing work it doesn't need to do, not just making decisions it shouldn't make. State checks, routing decisions, simple lookups, none of those require semantic reasoning and putting them through the LLM adds cost, latency, and non-determinism that genuinely doesn't help.

We took a similar approach at DataGrout with Governor, a Prolog-based reflex layer that resolves deterministic queries locally before they reach the model. In documented testing, 150 reflex queries saved 22M+ tokens in a single session. The interesting side effect is that the system becomes more predictable in exactly the places where predictability matters most.

The "approval module is pure Python, completely blind" design is the right instinct. Once you accept that the LLM is a reasoning substrate rather than an orchestrator, the governance problem becomes a lot more tractable.

Collapse
 
alexshev profile image
Alex Shev •

Runtime governance needs a deterministic enforcement point that survives prompt changes and model upgrades. I would also emit the policy version and evaluated inputs with every decision, so an incident can distinguish a policy defect from a model or integration change.

Some comments may only be visible to logged-in visitors. Sign in to view all comments.