atelier d'auteur · bruxelles · mmxxvi
Dt fig. I no. 01 - department title brussels · mmxxvi

Département des Harnais

author's workshop · ai agent harnesses
section des essais · texte-comme-image
l'atelier · essai t1 section des essais 2026-06-23

Why We Don't Trust People

Trust in AI agents is framed as a novel, almost philosophical dilemma: Can you trust a system that never gives the same answer twice?

The question feels unprecedented. It is actually a century old. Industry encountered it—and solved it—for another variable, opaque, impossible-to-internally-debug component: the human worker.

Because nobody, anywhere, trusts a worker.

It sounds brutal, but it is the foundational principle of modern management. The trust we think we grant individuals is sustained by a machinery so old and dense we no longer see it: the contract, which bounds what is owed; the trial period, which bounds risk; certification, which bars action until competence is proven; and supervision, dialed back in stages, never all at once. We rely on audits, performance reviews, professional ethics, and mandatory insurance. When a hospital "trusts" a surgeon, it is trusting ten interlocking institutions. The surgeon is merely the point of application.

Quality assurance is the ultimate admission of this concession. It was born on May 16, 1924, when Walter Shewhart wrote a one-page internal memo at Western Electric—the first control chart. He explicitly treated the human operator as a probability distribution, with variance limits and drifts to be detected. His intellectual heir, W. Edwards Deming, would later capture the core of this in a maxim:

"A bad system will beat a good person every time."

The entire quality industry flows from this insight. You don't make the human component reliable; you build a system that produces a consistent output from variable components. This foundation—not the perfection of operators—is what built aviation, nuclear power, and pharmaceuticals: the industries where errors kill.

That is the precedent. Here is the exception.

AI agents are currently entering the exact same roles as these heavily harnessed workers—but they are entering them naked. The data from mid-2026 tells the story:

  • 80% of the largest US companies are running agents (Microsoft Security, February 2026).
  • 60% of organizations report they do not know how to quickly shut down a rogue agent (CSA/Token Security, April 2026).
  • 82% discover agents they didn't even know existed, and only 21% have a formal decommissioning process (Kiteworks, March 2026).

Meanwhile, across hundreds of documented incidents where an agent destroyed data, leaked information, or triggered unauthorized payments, the number of cases where liability has been formally established—by a regulator, a court, or anyone else—is, to date, near zero.

A worker with no contract, no trial period, no certification, who can neither be monitored nor fired: no organization would ever hire a human under these conditions. Yet every organization is currently deploying agents under them.

Why isn't this vacuum filling itself? Because the apparatus governing human labor didn't fall from the sky. It was demanded, piece by piece, over a century and a half, by parties with a vested interest in demanding it: states, insurers, victims, and the workers themselves. Agents have no natural constituency advocating for their protection. Consequently, we only see the fragments that serve the buyer: identity management, dashboards, and basic insurance policies. There is a trendy vocabulary—we "hire" agents, "evaluate" them, give them "performance reviews"—but the metaphor stops exactly where institutional reality should begin. It is fleet management dressed up as Human Resources.

I recognize the promise, word for word: guardrails will soon be superfluous because models are improving so quickly. Yet notice who is carrying this message: the very people selling the component. No industrial buyer has ever signed off on a supplier claiming their part is too good to require incoming inspection. We wouldn't accept a factory shipping goods without QA on the grounds that "the workers have gotten much better." Yet that is exactly the promise of the moment.

But this isn't a direct carbon copy. Two differences make the requirements stricter, not looser:

  • Residual Liability: A human worker retains personal accountability—a career to lose, a reputation, sometimes jail time. This reality operates from within; it acts as an internal brake. An agent has nothing to lose: no career, no reputation, no fear. Everything that was once shared between institutional guardrails and personal incentives must now be carried by the system alone.
  • Velocity: A human makes mistakes at human speed, where a monthly audit is fast enough to catch them. An agent makes them at machine speed, concurrently, across a thousand instances. Retroactive control always arrives too late.

Therefore, the apparatus can no longer be a binder of procedures or a code of conduct. It must live inside the execution loop. It must be code.

This is precisely the harness I am building—and it is why this isn't a technical novelty. It is simply the shape that governance must take for a worker operating at machine speed. We are asking the wrong question about trusting AI agents. We have never trusted anyone. We built the systems that made trust unnecessary. Now, we have to build that system for them.

References

— John Linotte · Département des Harnais · Bruxelles · 2026-06-24