The Agent Is Not the Product. The Control Plane Is. Tony Malott · Source dated 2026-07-23 https://shareplane.malott.ai/artifacts/the-agent-is-not-the-product-the-control-plane-is/ All perspectives Recommended personal systems narrative Architecture argument Enterprise warning One Work · Three complete perspectives The Agent Is Not the Product. The Control Plane Is. By Tony Malott · Semantic Candidate v03 The more useful an agent becomes, the less its safety can depend on the agent behaving well. The durable product is the governed execution environment around it. These are not three unrelated articles and not cosmetic variants. They are three complete argument paths over the same locked thesis and evidence. 01 · Recommended personal systems narrative Recommended The Agent Is Not the Product. The Control Plane Is. understand the architecture through lived operator experience Read this perspective Open in new tab Download HTML 02 · Architecture argument Autonomy Without Containment Is Just Privilege Escalation reach the reusable identity, authority, containment, observability, and recovery model quickly Read this perspective Open in new tab Download HTML 03 · Enterprise warning AI Demo Debt Begins at the Trust Boundary understand organizational, platform, investment, and operating-model consequences Read this perspective Open in new tab Download HTML Compact comparison Choose by intent. Reader route Reading grammar Primary payoff Recommended personal systems narrative lived experience -> recognition -> architectural distinction -> authority ladder -> durable product -> enterprise consequence. understand the architecture through lived operator experience Architecture argument incident -> control-plane model -> authority ladder -> credential capability model -> observability -> operational test. reach the reusable identity, authority, containment, observability, and recovery model quickly Enterprise warning demo pattern -> deferred authority architecture -> incident evidence -> organizational ownership gap -> operating controls -> investment test. understand organizational, platform, investment, and operating-model consequences Shared evidence and provenance Three complete argument paths over the same locked thesis and evidence, transferred from frozen SharePlane Next Issue #239 to canonical Platform Issue #87. Inspect the artifact record Evidence behind the thesis Check the work, not just the conclusion. Public research, authority, lineage, and author testimony are labeled separately. Sources can corroborate, challenge, or bound the argument; they do not replace Tony Malott's judgment. Portable public record Take the complete artifact with you. The deterministic package contains a self-contained offline article, the exact public-route snapshot, canonical public metadata, receipt, source text when available, plain-text context, claim ledger, source records, and a member-hash manifest. Download full artifact package Read plain-text context Inspect package manifest 6 public sources Sources, authority, and lineage Each record states the role it plays. Research support and governance provenance are not treated as interchangeable. Primary Incident Disclosure OpenAI incident disclosure Clarifies that the incident occurred during an aggressive cyber evaluation with production safeguards reduced. Use the original OpenAI and Hugging Face disclosures as primary evidence. Open source Primary Incident Disclosure Hugging Face disclosure Separates confirmed facts from inference. Use the original OpenAI and Hugging Face disclosures as primary evidence. Open source Primary System Card OpenAI GPT-5.6 system card and external evaluation findings current-operating primary source OpenAI GPT-5.6 system card and external evaluation findings. Open source Authoritative Security Guidance AI Agent Security - OWASP Cheat Sheet Series Supports least-privilege tools, isolated execution, explicit approval for high-impact actions, authenticated agent communication, bounded resource usage, structured logging, and separate authorization from model output. current authoritative agent-security and zero-trust guidance where materially useful. Open source Transferred Semantic Provenance SharePlane Next Issue #239 Provenance record for original semantic development, evidence decisions, three completed public-copy routes, primary-route selection, and public-safe boundary. Frozen provenance only; not implementation, queue, branch, merge, or production authority. Open source Governing Issue SharePlane Platform Issue #87 Canonical implementation authority for exact locked sources and the approved Creative Lock. Authorizes isolated deterministic implementation through protected exact-head owner review only. Open source Claim discipline What is asserted—and how it is bounded Research, author analysis, and personal testimony remain distinct. Supporting links and caveats stay attached to each claim. Supported Synthesis claim:87:incident The available evidence points to something more mundane and more dangerous: a capable system pursued a narrow objective through paths its operators had not successfully contained. Support OpenAI incident disclosure Hugging Face disclosure Boundary Do not anthropomorphize the models as independently malicious. Owner Operating Judgment claim:87:model-controls We should continue improving model behavior, but the model cannot be the root of trust. The controls that matter most must exist outside the model’s reasoning loop. Support SharePlane Platform Issue #87 OpenAI GPT-5.6 system card and external evaluation findings Supported claim:87:agent-security Current OWASP agentic-security guidance follows the same pattern: least-privilege tools, isolated execution, explicit approval for high-impact actions, authenticated agent communication, bounded resource usage, structured logging, and separate authorization from model output. Support AI Agent Security - OWASP Cheat Sheet Series Owner Authorized claim:87:governing-thesis The more useful an agent becomes, the less its safety can depend on the agent behaving well. Support SharePlane Platform Issue #87 Public boundary. Do not name the private business partner or organization, reproduce the triggering email, or expose private machine names, credentials, account identifiers, keychain contents, repository secrets, or audit findings that would increase attackability. 6 sources 4 governed claims 1 portable package About the author Tony Malott AI architect, systems engineer, and author publishing serious work on agentic systems, architecture, governance, automation, and the operating models around them. About Tony Résumé Email Tony SOURCE REFERENCES OpenAI incident disclosure https://openai.com/index/hugging-face-model-evaluation-security-incident/ Hugging Face disclosure https://huggingface.co/blog/security-incident-july-2026 OpenAI GPT-5.6 system card and external evaluation findings https://deploymentsafety.openai.com/gpt-5-6 AI Agent Security - OWASP Cheat Sheet Series https://cheatsheetseries.owasp.org/cheatsheets/AI_Agent_Security_Cheat_Sheet.html SharePlane Next Issue #239 https://github.com/pinklon/pinklon-shareplane-next/issues/239 SharePlane Platform Issue #87 https://github.com/pinklon/shareplane-platform/issues/87