top of page

The AI Governance Problem Isn't Where Most People Are Looking

Sep 1
4 min read

By Zach Debelak / Hernando Bunuan | Z2Sixty Ventures | September 2026


Everyone is watching the model layer. The real stress is happening underneath it.

Strip away the specifics and every AI deployment runs into the same three questions: who is acting, what are they acting on, and who is accountable when it matters. The systems built to answer those questions — identity management, data governance, human oversight — were designed for a slower, more human world. AI didn't wait for them to catch up. That mismatch is the actual governance problem, and it shows up in three places that don't get the headlines the model layer does: machine identity, data provenance, and — in a sector that looks unrelated on the surface — the power grid.


Who's Acting: The Identity Gap

Machine identities — non-human accounts, service tokens, and API keys used by autonomous agents — are now outnumbering human identities in many enterprise environments. The Identity and Access Management (IAM) systems built to manage access were designed around humans. Humans log in periodically. Agents authenticate hundreds of times an hour, across systems, often with permissions that were granted once and never meaningfully revisited.


The governance layer didn't keep pace with deployment. That gap is becoming a material enterprise risk. And closing it isn't optional spend — it's the kind of problem that eventually gets a line item in a board meeting, not a pilot budget.

Identity answers the first question: who's acting. It doesn't answer the second — whether what they produce is actually right.


What They're Acting On: Models Don't Know When They're Wrong

LLMs are exceptionally good at predicting plausible continuations. They aren't inherently equipped to determine whether those outputs are true. That's not a flaw to be patched in the next release. It's the architecture.


Retrieval-augmented generation (RAG) improves the material a model reasons from. It doesn't fundamentally change that limitation. A model retrieving cleaner information can still produce a confident answer without knowing whether the underlying information is actually correct. The model is always doing the same thing: predicting the next most plausible token. It just has better inputs.


What's different about a sovereign dataset is governance. When a model reasons against proprietary, controlled, institutionally verified data, the output becomes more grounded in the organization's actual source of truth. The model still predicts. But what it's predicting from — and who controls that source — changes the enterprise value of the output entirely.


This is where the data problem and the identity problem turn out to be the same problem. A sovereign dataset is only as trustworthy as the record of who — or what agent — was allowed to read, write, or modify it, and when. You can't govern what a model reasons from if you haven't first solved who's allowed to touch it. Data sovereignty is downstream of identity governance; identity governance only pays off if there's a governed dataset on the other end of it. Neither does much on its own.


Human-in-the-loop is the third leg: accountability. It isn't a safety blanket in this context — It's the mechanism that keeps accountability in the system precisely because the models can't provide it on their own. Judgment, consequence, and institutional knowledge don't emerge from prediction. They have to be designed in. Identity tells you who acted. Sovereign data tells you what they acted on. Human accountability is what closes the loop when prediction alone isn't enough.


DevRev's Computer product is what this looks like built into one system: a permission-aware agent reasoning against a governed, org-wide knowledge graph, with human approval required before anything consequential executes and a full audit trail behind every action. It isn't a hypothetical architecture — it's a live example of the exact three-part problem this piece is describing, and it's one of the companies we've backed at Z2Sixty. That governance layer isn't a phase to outgrow — it's what makes the next phase trustworthy. DevRev's own roadmap toward fully autonomous digital workers is being built on top of the same permissioning and audit infrastructure Computer runs today, not by removing it. The destination is more autonomy. The path there runs through more governance, not less.


The Energy Side Tells the Same Story

Everything above is a digital-infrastructure story — identity, data, oversight. The same dynamic shows up in physical infrastructure, too.


Texas has spent years aggressively courting data center investment. Now grid constraints are forcing a harder conversation about what that growth actually requires in terms of power infrastructure. ERCOT alone is managing a 410 GW queue of large loads waiting for grid access — data centers account for 87% of it.


Emerald AI's $150M raise last week is another signal in a pattern that's been building for several quarters: capital is moving into the software and infrastructure that coordinate AI-scale compute against a constrained grid, rather than waiting on new generation to catch up. Emerald's product makes that literal — its software schedules AI workloads against a data center's on-site batteries and generation, dialing power draw down when the grid is stressed so training and inference jobs keep running without new physical buildout. That's venture capital, not project finance — a bet that the fastest way to relieve a physical constraint is with software rather than new steel in the ground. And the constraint it's betting on isn't projected or modeled. It's already operational: U.S. interconnection queues are holding roughly 2,600 GW of proposed generation and storage, more than double the capacity currently in service.


Two Sectors. One Dynamic.

Identity governance and grid orchestration look like unrelated problems. They aren't.


Both are expressions of the same underlying reality: the infrastructure required to make AI work at enterprise scale wasn't built for what's being asked of it. The models are moving faster than the systems designed to govern, power, and verify them. The gap between AI capability and real-world enterprise deployment — in identity management, in data provenance, in human accountability, in grid capacity — is where the real work is happening.


That coordination layer is where we think durable value gets built. It's less visible than the foundation models. It doesn't generate the same headlines. But it's what makes the headline technology actually function.


That's the thesis we've been investing around at Z2Sixty Ventures.


The past several quarters haven't changed it.


They've made it harder to argue with.

 
 

Recent Posts

See All
2026 First Half Review

Dear Friends and Colleagues, This half, our thesis crystallized into a single organizing idea — Throughput Technologies — and our portfolio delivered real, verifiable milestones that validate it. The

 
 
bottom of page