PACA: Governing the AI/Human Workforce
September 2026
The observation: systems without a safety layer
After taking a pause on the blogs and tool building in early 2026, I came back to the spark that started it all: a 2025 conversation with an AI safety professional, and the realisation that organisations themselves are misaligned, non-conscious intelligences with no safety layer. It had taken the emergence of artificial intelligence and the critical discourse about its safe operation to solidify this line of thinking, but the potential for misalignment had existed for as long as we humans have been creating complex systems.
The 2026 turn has been the rise in the deployment of autonomous AI agents and the significant challenges that this represents. The standard failure mode that organisations are facing is that they’re struggling to effectively manage the use of artificial intelligence to achieve their goals. The catastrophic failure mode is that AI agents do something genuinely dangerous within an organisation leading to real world harm. Jack and I had been working in the background, around our day jobs, to think about these challenges and how we’d solve them. The output was a lot of theory and a few tools focussed on this problem.
It was on a call with a mentor, a senior technology executive seeing Australian enterprises struggle with AI, that Jack and I were issued a challenge:
How do you manage the blended AI/human workforce and how they interact?
We got off the call and knew what we had to do – we started building PACA.
The framework: authority derived from purpose
PACA is a framework for governing purposive systems that have a cognising element. These are systems that exist to pursue a goal or purpose and perform some kind of informational judgement to achieve that goal. It means it applies to the systems that we humans have created to make our societies function.
This cognising has traditionally been done by people. But there are other modes of cognising that have existed for some time, such as human-authored instruments like rules or software (cognition frozen at authoring time), and, more recently, genuinely agentic artificial intelligence. While PACA can be used to govern all these modes of cognising, the driver for the urgent need to govern systems using this approach is the rise of artificial intelligence operating at speeds that outrun direct human supervision.
The core move is that an agent’s authority is derived from its purpose, not assigned as permissions. It takes the normative frame of a system and uses that to guide and govern an agentic system. Everything that happens, happens on the record: things like cost, authorisation, provenance, refusal. The same grammar governs the human and AI roles. It is a framework for the future blended workforce. And critically, it operates by governing the overall system, not just the agents.
The lineage is sixty years of cybernetics applied to a substrate that can finally be specified. In particular, it draws from Stafford Beer’s Viable System Model and Donella Meadows’ leverage points for intervening in systems. PACA uses these to give structure to systems operating AI agents so that coherence and fit can be measured holistically, not just at the level of agent performance. While the emergence of AI is the driver for the need for this kind of approach, it is also the technology that finally enables it.
The running instance: a governed intelligence organisation
We’ve used PACA to build two projects side by side: pacata.ai, the implementation of PACA as a governance platform, and an agentic cyber threat intelligence tool based on my 2025 AISA Cybercon presentation The Single Person (and Several-Dozen AI Agent) CTI Team. The CTI tool runs multiple specialised systems (collection, triage, reporting, review, intake, editing), designed and operated by one human, running under PACA governance.
As of 13 September 2026, it has issued 488 tickets, completed 145,000 actions, identified 69 actions where systems operated beyond their authority, folded them into 36 findings, and tracked every dollar spent. It has also identified 2,632 hollow grants of authority that were never exercised, which is overprovisioning surfaced, not just overreach. Every one of those actions passed through an authorisation decision, recorded with its reason and cost and chained to its predecessor.
The governed work is real: nearly 15,000 information reports produced, more than 11,000 of them in the past fortnight.
The strongest signals come from the refusals. An agent denied a tool it wasn’t authorised to use – and the workaround it then attempted, caught on the record. Agents declining work that fell outside their normative mandate. Deterministic code flagged for exceeding its system’s authority.
We’re currently testing multi-agent intelligence assessment writing workflows under PACA. The audit agents, operating with the PACA telemetry, have offered dozens of recommendations for system improvement. They’re also surfacing gaps in theory and recommendations for improvement of PACA itself. This is Beer’s System 3* (the audit channel) operationalised using artificial intelligence.
The two systems are building one another: theory informing system design, and systems improving theory through the analysis of its record.
The reflexive property: governance that improves at machine tempo
Underneath the numbers, PACA’s operating logic is cybernetic. Feedback loops absorb the information emitted by interacting systems to measure coherence, performance, fit, and safety. Control and information channels are mapped and recorded, and the complex interactions between systems are made discoverable for the enterprise as a whole. The systems themselves become comprehensible, both as specified and enacted. The difference between them is the coherence gap, and it’s closed by either an adjustment of the specification or the process.
Changes to an organisation’s specification travel a controlled, recorded authoring channel. The system itself adapts under governance, on the record. By specifying the system in detail and capturing the record of its actions, managers can access the full range of leverage points when incrementally improving a system. It gives them the possibility of adjusting more than just the parameters.
The governance itself improves off its own findings. In our build this is demonstrated, not aspired to: one of the audit agents found a defect in its own detection method, and the fix was committed citing the finding. The full loop — finding, remediation, verification in the next run’s record — has run in hours. Organisations typically run that loop in quarters.
A control loop slower than the system it governs is always governing last quarter’s organisation. A workforce that changes at the speed of model releases needs governance that moves at the same tempo.
The control half of AI safety
AI agents are the newest class of trusted insider. The dominant failure will be overreach of authority, not attack. Aligning the models is critical, and the work done in this space is one of the most important technological endeavours of our time. But continuing to neglect aligning the systems within which the agents are exercising authority risks failure modes we are not presently equipped to detect, much less manage.
When incidents happen, the question is this: can you prove what was authorised and reconstruct what occurred? It needs a record built by the governance layer, not testimony from the agent. Beyond detecting incidents, PACA informs the design of agentic systems, governs their behaviours, brokers their interactions, and surfaces cracks that could lead to failures. It provides the capability to detect where a system may drift from its purpose well before it fails.
The safety case for increasingly capable AI can’t rest on the models alone. Bounded authority, evidence that does not depend on an agent’s testimony, and accountability that traces to a human are what keep capable systems governable if alignment falls short. If alignment holds, they’re the proof.
This is the control half of AI safety: not making models want the right things, but bounding, evidencing, attributing, and analysing what they do. These structures matter more, not less, as capability grows.
Where it’s going
We’re simultaneously building the PACA theory, the Pacata platform, and the CTI tool, each improving the others. The tools are being built commercially; the theory will be published as an open specification once it’s earned it.
If you’re interested in the framework, the running instance, or the commercial work, please feel free to reach out at hello@pacata.ai.