~8 months
Capability compresses review time
Review windows are shrinking.
42% of well-scoped hour-long software tasks completed by mid-2025.
WHY NOW
Capabilities are outrunning review cycles. For consequential AI, proof has to be present before action.
Pre-action controls. Offline-verifiable. Ticket-attachable. Fail-closed on uncertainty.
THREE SIGNALS
Acceleration, uneven safeguards, and action-taking autonomy now outpace most governance cycles.
~8 months
Review windows are shrinking.
42% of well-scoped hour-long software tasks completed by mid-2025.
R² = 0.097
Capability does not reliably bring stronger safeguards.
Vulnerabilities still appear across tested systems.
High-stakes actions
Action-taking AI is entering consequential workflows.
Governance has to move to the point of action.
Source: UK AI Security Institute, Frontier AI Trends Report. Observed evaluations — not a forecast.
Enterprise trust is entering the quantified era.
Buyers are moving from demo trust to measurable reliability, production-grade evaluation loops, and portable evidence across agent stacks.
Additional corroboration: Snowflake AI + Data Predictions 2026.
WHAT PROCUREMENT REQUIRES NOW
For action-taking systems, acceptable evidence is replayable, offline-verifiable, and fail-closed when scope or authenticity cannot be established.
Control must exist before the action, not after the incident.
Reviewers need artifacts they can verify independently and attach in one pass.
If scope or authenticity cannot be verified, the ticket stays HOLD.
Regulatory dates still matter, but they are no longer the lead story. Use this appendix to align planning, questionnaires, and board updates.
SOURCES
Observed signals for this page come from AISI and Meridian verification materials, with one enterprise corroboration source.