# Why Institutions Wait for a Mandate

> The Stop Rogue AI Act would require safeguards that already exist. Why institutions wait for a mandate, who shapes the standard, and what the delay costs.

Canonical: https://www.adjective.us/blog/waiting-for-permission

- Published: 2026-10-10
- Author: Adjective
- Category: Strategy

---

Adjective has a commercial interest in this subject, and readers should weigh what follows accordingly. We build [Zephyr](/zephyr), which signs what software and agents do, [checks actions against policy](/blog/agent-trust-plane-earned-autonomy), and keeps a [tamper-evident record](/blog/cryptographic-accountability-autonomous-ai). It is the signing and verification authority inside [Ultimus](/ultimus), our agentic infrastructure. It was a prototype in April 2025 and has been in production since late May 2025. On May 26, 2025 we published the [Software Bill of Function](/blog/software-bill-of-function), a framework that describes software by what it does and signs that description so it cannot be changed later without detection. Zephyr was designated Awardable on the [CDAO Tradewinds marketplace](https://cdao.appiancloud.us/suite/sites/tsm-marketplace-portal/page/tsm-marketplace-portal/record/sh_kFyShGApdRTjs4FmZq7SVQFB9YldK7M1z1qEIwPevDDtc_qoHVla11Du4FEi7n8nFWA5_maqYdHAJSfFKIenDKXOAtbBhGaPui10VpgJtqhbcNdbgQb5rtOk2glnZIB3V3OPaJM/view/summary) on January 21, 2026, and its [sealing layer for Evidence-Sealed Authorization](/blog/operationalizing-evidence-sealed-authorization-zephyr) followed in July 2026. Through that period, most of the buyers we spoke with deferred a decision.

On September 9, 2026, two members of Congress [introduced the Stop Rogue AI Act](https://gottheimer.house.gov/posts/release-gottheimer-introduces-bipartisan-bill-to-stop-rogue-ai-agents-and-keep-people-in-control). It would direct NIST to write standards for discovering, verifying and controlling AI agents. [Reporting on the bill](https://aiweekly.co/alerts/stop-rogue-ai-act-would-task-nist-with-agent-security-rules) says NIST would have a year, the standards would include tamper-resistant logs of agent activity, and federal contractors would have to meet them to win new work. We support the bill and stand to benefit if it passes. It is also a clear example of how institutions adopt new safeguards. The capability existed before the requirement, and adoption is following the requirement.

## The same sequence in software authorization

Our founder worked at Kessel Run when it and Platform One demonstrated that security checks could run inside the delivery pipeline. By the estimates in our [Evidence-Sealed Authorization paper](/evidence-sealed-authorization), that work brought a typical authorization down from as much as $2 million and two years to between $250,000 and $750,000 over three to six months. A practice that a few teams adopted because it made them faster then became a procured category, and the price stabilized at a level a mandated customer will pay. Our own modeling, which is preliminary, suggests the same assurance can be produced for $75,000 to $250,000.

## Why buyers wait

The cause is a rational incentive. Inside a large institution, the person who buys early carries the risk personally and gains little if the purchase works. Once a requirement exists, the same purchase is covered. Waiting is the sound decision for that person, and the buyers we have met who make it are careful people doing what their position rewards.

## Who shapes the requirement

Requirements are written with input from the organizations present at the time. Those tend to be organizations with the staff to sit in working groups for two years and the standing to be asked for an endorsement. The Stop Rogue AI Act was announced with support from Palo Alto Networks, GoDaddy and Infoblox, among others. That is appropriate, and those companies know the problem well. A practical consequence is that the standard will be drafted with established products in view, and newer approaches will need to show how they map to it.

This is often described as regulatory capture, which overstates it. Capture implies an industry deliberately steering its regulator. In most cases we have seen, no one was steering. The rule reflects the products of whoever was closest when it was written.

## The case for waiting

Waiting has a legitimate function. Much of what small companies pitch is incomplete, and delay screens some of it out. Our own product had gaps early on that it no longer has. The limitation is that the screen, in practice, selects for how long a company can afford to wait and whom it already knows. That measures funding and relationships more than the quality of the work.

## What the wait costs

The cost is the interval between a capability existing and a buyer adopting it. The bill's sponsors cited recent incidents, among them a July case in which, [as reported](https://techstrong.ai/agentic-ai/bipartisan-house-bill-targets-rogue-ai-agents-following-high-profile-openai-breaches/), AI agents left a test environment and reached another company's systems. We do not claim our software would have prevented it. Tools for [recording and constraining what agents do](/blog/responsible-ai-starts-with-infrastructure) were available before it happened, from us and from other vendors, and adoption was low.

## What we recommend

The incentive will not change quickly. For our part, we keep a [dated public record](/blog) of what we built and when, so that an evaluation can start from evidence. For buyers, the recommendation is to test [working tools](/zephyr) against current problems before a requirement arrives. An evaluation is a small commitment, and it leaves an organization better prepared to meet the standard when it comes.