As the adoption of AI accelerated over the last few years, questions around the use of AI centered around its capabilities, asking the following: Can this model do that? Can it write code, summarize contracts, triage tickets, and close the loop without a human touching it?
These questions are largely answered today. The AI models available at our fingertips can do a remarkable amount, and the agents we’ve built using them are already making a material impact on our day-to-day lives and are starting to move into more critical operational tasks to support real production workflows such as reading data, calling APIs, and taking actions on their own.
As such, our questions have also shifted. It is no longer "can the model do this?" but is "can we trust it to do this, and how?" This is a fundamentally different problem. Capability comes from the model, but trust is built from the alignment of these operations to the expectations of the people around it and the infrastructure supporting it.
As the CISOs at micro1 and Drata respectively, we lead security at two companies working on opposite ends of that problem. While micro1 brings human expertise into the data that shapes how models reason and behave, Drata builds the platform that governs and observes these systems. Both companies help enterprises build AI agents they can trust, ensuring they uphold the values, standards, and expectations required in real-world deployments.
From both vantage points, we keep arriving at the same conclusion: trustworthy AI is not the absence of humans. It is appropriate (not suffocating, unscalable, and unwieldy) human oversight, backed by supporting infrastructure that makes that oversight defensible.
Trust Starts With Human Judgment and Expectations (Long Before Deployment)
A model is only as good as the human expertise, training, and data used behind it. That's how frontier systems and foundational models are built.
At micro1, we extensively vet domain experts across engineering, finance, healthcare, law, and other fields. With these experts, we forge their judgment into the training data, evaluations, and reinforcement learning from human feedback (RLHF) that are used to train models how to reason and agents how to act. We build environments that mirror real-world scenarios so agentic behavior can be stress-tested, and we run contextual evaluations that benchmark how well an agent actually reasons through ambiguity and real decisions.
When a model handles a hard case to our defined expectations, it is usually because a qualified human taught it what "well" looks like, ranked good answers against bad ones, and caught the edge cases that raw data never surfaces.
That principle does not stop at deployment. The same human judgment that sharpens a model during training is what determines whether you can trust it once it is running. The work just moves from the lab to the live environment. These live environments are where the rubber meets the road, and where governance takes the wheel.
From "Can It?" to "Can We Trust It?"
Agnostic of company size and use case, AI capabilities are no longer the only thing worth watching. The story is now two fold: impressive new capabilities on one side, and on the other, the trust we build in those capabilities over time. That trust is the real variable. It's earned through continuous operational effectiveness, not a one-time check or a periodic review.
This continuous assurance model used to monitor and build trust in our AI usage and AI agents is where we're heading. We built our platform on a simple belief: in a world that moves at AI speed—a pace we’ve not experienced before—trust in our use of AI has to be continuous. Drata already helps 8,500+ customers establish, maintain, and share trust continuously; we are extending that same approach to the infrastructure and the agents now operating inside our organizations large and small.
AI governance is the new dimension of trust, and the category is forming in real time as the people closest to it feel the gap. Closing that gap comes down to determining four items acutely and continuously for every agent:
Discover it.
Decide what it's allowed to do.
Enforce that before it acts, not in flight or after the fact, while monitoring for drift.
Prove its behavior against how it was governed.
Our job as humans is to be at the center of all of this.
Human Oversight Stays Non-Negotiable
Trust has two layers: a control plane (where intent, boundaries, and accountability are set) and an execution layer (where actions actually run at machine speed). Automation belongs in the execution layer, while we are the control plane.
That distinction matches how many of us are using AI today. People decide what agents are allowed to do—what it can read, what it can write, and what it must never touch—and we continue to own the oversight, direction, and consequences when something goes wrong. With Drata, technology, security, and GRC teams write those policies in plain language as intent, not code, defining them directly without waiting on engineering cycles. These policies ultimately act as governing principles for AI use.
Human oversight is the critical, essential, and deliberate control-plane layer that continues to define the boundaries. Remove the human in the loop and accountability goes with it.
The ability to operate accountability for AI use at scale requires new technologies; traditional identity and tooling weren’t fundamentally built to handle it. One person can spin up many agents, each with different scopes and permissions. Every one of those agents needs to map back to a human owner.
The Gaps the Industry Is Still Building Toward
This problem isn’t yet solved today, by Drata, micro1, or anyone else to the level of holistic governance and awareness we require. Several real gaps still separate where the industry is from where it needs to be, and naming them honestly is more useful than waving them away.
Standards Are a Work in Progress
We have decades of practice auditing human- and system-driven processes and technologies against known security, GRC, privacy, technology, and regulatory standards. We do not yet have an agreed-upon, defensibly auditable way to use a commonly accepted third-party attested way to assess autonomous agents. AIUC-1 is one of the first frameworks built to close that gap, setting out a path toward third-party attestation for AI agents.
The Tooling Is Thin
Most monitoring capabilities today tell us what’s happening in flight or what happened after the fact, but far fewer tools capture the context, intent, and reasoning behind an agent’s action (against provided instructions) in a form a reviewer can trust and build assurance over time.
Accountability Tracing Is Immature
When one agent hands off to another, which subsequently hands off to a third and so forth, the chain of responsibility blurs quickly. Tracing a single outcome back through several autonomous actors across a multi-agent supply chain workflow of events—and ultimately back to a human owner—is materially burdensome to splice together with logs using current tooling available today.
Regulation Is Outpacing (Most) Teams
The European Union's Artificial Intelligence Act (EU AI Act) is moving toward enforcement, and frameworks like ISO 42001 and the National Institute of Standards and Technology's AI Risk Management Framework (NIST AI RMF), and the Artificial Intelligence Underwriting Company (AIUC-1) are raising the bar for how AI must be governed. Many teams are not ready, and the gap between obligation and readiness is widening.
Closing these gaps is shared work, requiring better human data and evaluation on the model training side of the spectrum (where micro1 operates) and requiring AI governance infrastructure and capabilities on the runtime side (where Drata operates). We are building toward our part of this spectrum deliberately, and we are clear-eyed that the rest of the ecosystem has to move with us.
Making Oversight Continuous and Verifiable
The goal is human judgment that does not age out the moment it is made—oversight that stays live as the agent keeps running. Here is what that looks like in practice with Drata.
Discover and Register Every Agent
We cannot govern what we cannot see. Foundational security and GRC approaches start with understanding our inventory or assets. Starting with cataloging our AI use and agents is no different. Drata registers every agent inline at inception, mapping each one to its owner, identity, permissions, and scope, so a team builds a complete inventory in minutes instead of guessing.
Enforce Policy Before an Action Executes
For autonomous agents expected to operate at machine speed, constant notification and approval is not tenable. Drata evaluates every action against approved policy in real time and blocks violations inline, before they run—and lets teams test a policy against real traffic before turning enforcement on, so humans control when the brakes engage to catch instances of agents going out of bounds.
Continuously Monitor for Drift
Over time, behavior and execution may drift. In technology, we may adjust OAuth scopes to allow deeper capabilities and actions, vendors change available API endpoints, or task execution, approach, or behavior shifts over time based on the variance of context and inputs against instructions. Drata watches every command, prompt, and tool call against the policy a team actually set, and flags the moment an agent steps outside its approved scope.
Prove It With Evidence Anyone Can Trust
We, along with our peers, leadership teams, customers, and auditors are asking the same question, and almost 90% of companies can't produce an audit trail for AI agent decisions. Drata logs every decision in a tamper-evident chain of custody, mapped to the governance frameworks and standards already reported against, so the proof is ready to share when asked.
Turning Human Judgment Into Reliable AI Behavior
Continuous oversight also has to start before an agent ever reaches production. Where Drata helps govern what agents are allowed to do once they are operating, micro1 helps define and evaluate whether those agents can actually behave well enough to be trusted in the first place.
Define What Good Looks Like
AI agents cannot be evaluated against vague expectations. micro1 works with enterprises to turn innate human expertise into clear rubrics, task definitions, success criteria, and failure taxonomies that reflect how real work is actually done. This gives teams a concrete way to measure whether an agent is reasoning correctly, making appropriate decisions, and staying aligned with the standards of the business.
Stress-Test Agents in Realistic Workflows
Many of the most important failures do not show up in simple tests. They appear in ambiguous, multi-step, context-heavy workflows where the agent has to interpret instructions, use judgment, and respond to changing conditions. At micro1, this is where evaluation environments become especially important as they allow agents to be tested against the kinds of scenarios they will actually encounter, not only the clean cases that are easiest to measure.
Identify Failure Modes With Expert Review
Trustworthy AI requires understanding more than whether an agent failed. Teams need to know why it failed, whether the issue was minor or systemic, what context the agent missed, and what kind of human judgment would have led to a better outcome. micro1 brings domain experts into the evaluation process to identify deeper issues in reasoning, policy interpretation, instruction following, and context awareness, giving teams a clearer view of where the agent is reliable, where it is brittle, and what needs to change before it can be trusted in higher-stakes workflows.
Create Targeted Data to Improve Performance
Once failure modes are understood, evaluation can become a path to improvement. micro1 turns the issues uncovered through expert review into targeted evaluation and training data, so teams are improving agents against the specific workflows, edge cases, and expectations that matter most to their business. This closes the loop between identifying where an agent is unreliable and giving it the right examples, feedback, and guardrails to perform better.
Keep Evaluation Live as Agents Evolve
Agent reliability is not a one-time score. Models change, workflows change, tools change, and user expectations change. It’s essential for evaluation to stay connected to those changes, so human judgment remains part of how AI systems are trained, tested, improved, and monitored.
Using these platforms together, human judgment is translated into something continuous and verifiable: micro1 helps define, evaluate, and improve the behavior enterprises expect from AI agents, while Drata helps govern, monitor, and prove that those agents stay within approved boundaries once they are operating.
Trustworthy AI Requires Discipline Combined With Oversight
Automation operates at a scale no human could match, yet human judgment remains non-negotiable and verification is never optional for these most sensitive of capabilities and operations we all rely on to support our businesses and daily lives. AI governance deserves the same level of acute and intentional discipline. Agentic systems handle the repeatable work at speed, while people stay responsible for the decisions, the boundaries, and the outcomes.
That is the heart of it. Trustworthy AI is human oversight translated into continuous and verifiable operations, running on AI governance infrastructure built for the agentic era.
If you are working through these questions for your own environment, start by confirming you have a reliable inventory and a named owner for every agent, then decide where you need true inline enforcement rather than after-the-fact alerts. To see how Drata approaches it, schedule a demo with the team.
If your AI agents are starting to touch real workflows, now is the time to understand where they are reliable, where they are brittle, and how that changes as they evolve. micro1 helps teams evaluate and monitor agents with domain experts, then turn those findings into the data needed to make them better. Click here to learn more about micro1’s enterprise offering.