Put the operating model between AI reasoning and infrastructure action.
Does AI have a trusted model of the environment and explicit rules defining what it may do?
Build the authoritative model before giving agents meaningful authority — truth first, then permission.
Add policy, approval, execution, and verification to the same model.