Keeping up was never a reading problem. Nobody fell behind because they read too slowly.
You fell behind because the thing you are governing changes on a clock measured in weeks, and the process that governs it runs on a clock measured in quarters. By the time the committee next meets, the organization has been doing something different for a season.
This sheet is one page and four questions. It does not need a tool, including the kind my company sells.
Clock speed
For each thing you depend on, how fast does the ground under it actually move?
| What you depend on | What moves underneath it | Clock |
|---|---|---|
| A model you call | version changes, deprecations, refusal behavior, price | weeks |
| An agent with tools | what it can reach, what the tools permit, new integrations | weeks |
| AI inside a vendor's product | features shipped on their schedule, not yours, often without an announcement you would notice | weeks |
| Your prompts and workflows | quiet drift as the model underneath is updated | weeks to months |
| The security picture | disclosures, new CVEs, additions to the exploited-in-the-wild list | days to weeks |
| Your policy and approvals | committee cycles, annual reviews, training refreshes | quarters to years |
Every row on that table moves in weeks except the last one.
The last one is yours.
The gap
Write both numbers down. The difference is the answer.
How fast does the ground move under this capability, in weeks. How often do you actually review it, in weeks. Subtract one from the other.
minus
Nothing here is sent anywhere. Print the page and the numbers you typed print with it.
That number is not a metaphor. It is the length of time your organization is running on a description of the world that has stopped being true, and it is the single most useful number on this page because almost nobody has ever calculated it.
The deadline and the default
This is the evidenced part of the sheet. Everything else here is reasoning.
In August 2026, OpenAI published how it runs this internally. When its monitoring surfaces something concerning, the teams get an alert inside thirty minutes. And if they cannot conclusively determine within thirty minutes that the flag is a false positive, the activity pauses.
The thirty minutes is not the interesting part. The default is. Most escalation paths in most companies have neither. A question gets raised, people look into it, and it resolves when somebody gets tired or something else catches fire. The outcome is decided by attention, and attention is exactly what you do not have at three in the morning.
A prohibition list only covers what somebody thought to name in advance.
A deadline with a default does not require you to have predicted the failure at all. It requires one decision, made once, in daylight: what happens when the window closes and the question is still open.
The overhead
State it as a percentage, before somebody asks you to justify it.
In the same post, OpenAI put a number on what watching costs: monitoring overhead at roughly twenty percent of the inference compute being monitored. That is what the company with the most commercial reason on earth to move quickly is paying to watch its own models, published as a line item rather than a virtue.
You do not have to match it. You have to have a number. If a frontier lab can carry a fifth of its monitored compute, the argument that you cannot afford a review is not a budget argument, it is a preference. And if your number is zero, you have not saved anything. You have found something.
The capability
How fast the ground under it moves, in weeks
How often we actually review it, in weeks
The gap between those two
When something concerning surfaces, how long may it stay open
What happens automatically when that window closes
Overhead we are willing to pay, as a percentage
Who owns this row, by name
Date we look at all of it again
What this sheet is and is notSection three is the evidenced one. The thirty minute window, the pause default and the twenty percent overhead are all published by OpenAI about its own operations, and you can read them yourself. Everything else on this page is reasoning rather than a finding: the clock speeds in section one are my estimate of how fast each layer moves, not a measurement, and your own numbers will differ. Treat the table as an argument to have with your team rather than a benchmark to hit. A sheet about the danger of stale descriptions should be honest about which parts of itself are evidence and which parts are opinion.
Governance tooling is the market my company sells into, so discount me accordingly. Nothing on this page needs a product. Every number it asks for already exists inside your company, or can be decided in a meeting this week.
More field notes at Enterprise Field Notes