Jon W. Hansen, FCIPS · Procurement Insights | Hansen Models™
As Lab Lead at Hansen AI Labs™, I have spent more than 2,000 hours working with independent AI models, on top of my 43 years in the high-tech industry. The lab behind today’s post put one question to nine AI models, running simultaneously across three independent panels: which one word in a sentence has been the problem for 43 years? None found it. The sentence was: “While organizations are accelerating their AI investments, many still lack the visibility, understanding and governance needed to deploy AI confidently across complex business environments.” The word was AI. What follows is an excerpted overview of what that means for how we control AI agents.
In the Hansen Models™ framework, I distinguish three kinds of control. A guardrail limits what an agent may do. A harness governs how it does it. A firm fence governs whether the organization understands what it’s acting on. To see the thinking behind firm fences, and how it worked in the real-world environment going back to 1998, watch this six-minute video: https://youtu.be/t5wO7i-6Blo
Guardrails sit inside a harness, and both are necessary. A well-built harness is real engineering progress. But a firm fence isn’t a stricter guardrail or a better harness. Guardrails and harnesses work inside a frame. A firm fence puts the frame itself under examination.
There is a simple test for whether a firm fence exists: can evidence from outcomes stop an action and change the explanation behind it? If it can’t, there is no fence, whatever the controls say.
That’s why the lab matters. Every one of the nine answers was well formed, reasoned and within bounds. A guardrail would have let all of them through. A harness would have executed any of them flawlessly. Only something that asked what the sentence assumed would have caught that all nine had accepted the technology as the given subject.
So, how does the firm fence model apply to some of the more notable issues with AI agent behavior?
Which control would have prevented it?
Two failure modes recur here, often together. Execution failures, where a system does something it shouldn’t, are fast and visible, and guardrails and harnesses are built to stop them. Frame failures, where a system does exactly what it was designed to do and the design is wrong, can run for years, because every check along the way confirms that the system is working. Controls that only enforce the existing rules will not establish whether those rules are appropriate. It’s the same pattern as a trip where every flight was on time, and you still missed your connection (watermelon reporting).
The industry is building in the wrong order
The industry is building and rolling out AI control leading with technology from the outside in: guardrails first, then the harness, and the firm fence, if ever, last, and usually in the form of a post-mortem.
In an age of agents, the rush to dispatch technology has bypassed the necessary first step, as it did with ERP, e-procurement and every technology era since. The disciplines that cannot afford frame failures already work the other way: aviation, nuclear power and other safety-critical industries begin with hazard analysis before they build their controls. AI agent rollouts largely do not.
The order should be the reverse:
- Phase 0™ Traceback Mapping
- Firm fences
- The harness
- The guardrails
Today, the industry starts at step four, with the guardrails.
That does not mean the guardrails should wait. The controls against fast, visible failures can and should be in place while the fence is being set. But they are concurrent protections, not the foundation. The harness and the guardrails should be built against the fence, not in its place. An organization that begins with guardrails has decided what to protect against before it understands what it is operating.
And none of this is a one-time setup. Outcomes have to keep feeding back, so that the understanding, the fence and the controls change as the operation changes. In 1998, working in that order, with the technology brought in last, took next-day delivery from 51% to 97.3%.
The market starts with the agent and asks what it can do. Hansen Models™ starts with a proven operation and asks two questions of it: what in this process should an agent take over, and why? And what could an agent enhance and extend that the process couldn’t do before? Autonomy is earned by the foundation, not assumed by the technology.
Truth Is Believing. Accuracy Is Knowing. Outcome Is Proof.™
-30-
Related
Firm Fences, Guardrails and Harnesses: What Is the Difference?
Posted on October 10, 2026
0
Jon W. Hansen, FCIPS · Procurement Insights | Hansen Models™
As Lab Lead at Hansen AI Labs™, I have spent more than 2,000 hours working with independent AI models, on top of my 43 years in the high-tech industry. The lab behind today’s post put one question to nine AI models, running simultaneously across three independent panels: which one word in a sentence has been the problem for 43 years? None found it. The sentence was: “While organizations are accelerating their AI investments, many still lack the visibility, understanding and governance needed to deploy AI confidently across complex business environments.” The word was AI. What follows is an excerpted overview of what that means for how we control AI agents.
In the Hansen Models™ framework, I distinguish three kinds of control. A guardrail limits what an agent may do. A harness governs how it does it. A firm fence governs whether the organization understands what it’s acting on. To see the thinking behind firm fences, and how it worked in the real-world environment going back to 1998, watch this six-minute video: https://youtu.be/t5wO7i-6Blo
Guardrails sit inside a harness, and both are necessary. A well-built harness is real engineering progress. But a firm fence isn’t a stricter guardrail or a better harness. Guardrails and harnesses work inside a frame. A firm fence puts the frame itself under examination.
There is a simple test for whether a firm fence exists: can evidence from outcomes stop an action and change the explanation behind it? If it can’t, there is no fence, whatever the controls say.
That’s why the lab matters. Every one of the nine answers was well formed, reasoned and within bounds. A guardrail would have let all of them through. A harness would have executed any of them flawlessly. Only something that asked what the sentence assumed would have caught that all nine had accepted the technology as the given subject.
So, how does the firm fence model apply to some of the more notable issues with AI agent behavior?
Which control would have prevented it?
Two failure modes recur here, often together. Execution failures, where a system does something it shouldn’t, are fast and visible, and guardrails and harnesses are built to stop them. Frame failures, where a system does exactly what it was designed to do and the design is wrong, can run for years, because every check along the way confirms that the system is working. Controls that only enforce the existing rules will not establish whether those rules are appropriate. It’s the same pattern as a trip where every flight was on time, and you still missed your connection (watermelon reporting).
The industry is building in the wrong order
The industry is building and rolling out AI control leading with technology from the outside in: guardrails first, then the harness, and the firm fence, if ever, last, and usually in the form of a post-mortem.
In an age of agents, the rush to dispatch technology has bypassed the necessary first step, as it did with ERP, e-procurement and every technology era since. The disciplines that cannot afford frame failures already work the other way: aviation, nuclear power and other safety-critical industries begin with hazard analysis before they build their controls. AI agent rollouts largely do not.
The order should be the reverse:
Today, the industry starts at step four, with the guardrails.
That does not mean the guardrails should wait. The controls against fast, visible failures can and should be in place while the fence is being set. But they are concurrent protections, not the foundation. The harness and the guardrails should be built against the fence, not in its place. An organization that begins with guardrails has decided what to protect against before it understands what it is operating.
And none of this is a one-time setup. Outcomes have to keep feeding back, so that the understanding, the fence and the controls change as the operation changes. In 1998, working in that order, with the technology brought in last, took next-day delivery from 51% to 97.3%.
The market starts with the agent and asks what it can do. Hansen Models™ starts with a proven operation and asks two questions of it: what in this process should an agent take over, and why? And what could an agent enhance and extend that the process couldn’t do before? Autonomy is earned by the foundation, not assumed by the technology.
Truth Is Believing. Accuracy Is Knowing. Outcome Is Proof.™
-30-
Share this:
Like this:
Related