Read Your Clock
THE SOVEREIGNTY CLOCK READER: Sixteen questions. Seven minutes. No email required.
Read Your Clock
Four quadrants of organizational vulnerability, each with its own countdown running. The question is not whether your clock is running. It is. The question is what time it shows for your enterprise.
Why an empty reading can never look good. A small gap between design and evidence only means something when there is something on both sides. The gap panel weighs how much is actually evidenced, so a reading where little exists reads as a warning, never as alignment.
No peer benchmark is offered. There is no dataset behind this reader, so it measures you against the posture each quadrant requires rather than inventing a percentile. Nothing you enter is transmitted or stored.
Agent Governance
How close are you to an ungoverned agent causing a crisis?
Can you produce, today, a current list of every AI system in your enterprise that takes action without a human reviewing each decision?
DesignIs every one of those systems classified by how much autonomy it actually operates with today, rather than the autonomy it was approved for?
DesignFor your highest autonomy system, when was containment last tested by somebody other than the person who built it?
EvidenceIn the last ninety days, have you actively searched for AI in use that nobody authorised, rather than waiting for teams to declare it?
EvidenceQuantum Countdown
How long until your encryption becomes transparent?
Do you know which cryptographic algorithms protect your most sensitive data, across the whole estate rather than the parts that are easy to see?
DesignHave you compared how long your data must stay confidential against how long your migration will take?
DesignFor your critical vendors, do you hold a dated commitment to post quantum support, or only a roadmap?
EvidenceIf you had to change a cryptographic algorithm across a major platform, has your organization ever actually done it?
EvidenceRegulatory Compliance
How close are you to enforcement?
Is every AI system classified against the regulations of each jurisdiction you operate in, with a recorded decision even where the answer is that nothing applies?
DesignIf a regulator or a major customer asked tomorrow for the technical documentation behind one named production AI system, what would happen?
EvidenceWhere a human is required to review an AI decision, do you measure whether the review actually happens and whether the reviewer ever disagrees?
EvidenceDo you know which obligations come into force in the next twelve months, and does each have a named owner?
DesignSovereignty Erosion
How much control have you ceded to vendors, platforms and foreign jurisdictions?
When a workload is placed on infrastructure, is the reasoning recorded, including the jurisdiction it will run in and who owns that decision?
DesignDo you know how concentrated your AI capability is on a single model provider or runtime?
DesignHave you verified, rather than assumed, which external tools and connectors your agents can reach?
EvidenceIf your primary model or platform provider changed terms, raised prices sharply or became unavailable, have you ever tested moving off it?
Evidence0 of 16 answered
Your clock shows
Governance
Countdown
Compliance
Erosion
The ask
The decision requested and what it rests on, in the order a board wants it. The quadrant cards below are the evidence.
Designed against evidenced
Each quadrant has two questions about whether a control exists and two about whether it has been tested or evidenced. The gap is how far evidence falls short of design, counted quadrant by quadrant, so a strong quadrant cannot offset a weak one. Read it together with the evidence total: a small gap on a small base is not assurance.
Swipe the table sideways to see every column.
| Quadrant | Designed | Evidenced | Shortfall |
|---|
Do your answers agree with each other?
Individually plausible answers can contradict one another. These are the ones a board member or an auditor would notice.
What each quadrant maps to
Your audit function and your board will ask which established framework this maps onto before they accept a score. Verify article and control references against primary sources before citing them in a filing.
Swipe the table sideways to see every column.
| Quadrant | NIST | ISO/IEC | EU AI Act |
|---|---|---|---|
| Agent Governance | AI RMF GOVERN 1 to 4, MAP 1 to 3, MANAGE 1 and 2 | 42001 AI system inventory, roles and responsibilities, change control, operational planning | Articles 9 and 17 risk and quality management, Article 26 deployer obligations |
| Quantum Countdown | Post quantum standards FIPS 203, 204 and 205, and AI RMF MANAGE 2 | 27001 cryptographic and supplier controls, which 42001 is designed to operate alongside | Article 15 accuracy, robustness and cybersecurity |
| Regulatory Compliance | AI RMF GOVERN 1 and 5, MEASURE 1 to 3 | 42001 impact assessment, documented information, performance evaluation | Articles 11 and 12 documentation and logging, Article 14 human oversight, Article 50 transparency |
| Sovereignty Erosion | AI RMF GOVERN 6 third party risk, MAP 4 | 42001 Annex A third party and customer relationships | Article 25 responsibilities along the AI value chain |
Board summary
Written to be copied into a board or executive committee paper without editing. Complete any bracketed field before you circulate it.
Turn the reading into work
A reading is a diagnosis. These are the instruments that close the gap, and they are free for use inside your own organization.
Agent Governance quadrant
The inventory register that turns a rough count into a scored list with control gaps flagged, plus the charter that establishes who decides what an agent may do and the containment procedure that makes revocation real.
Get the instrumentsQuantum and Regulatory quadrants
The cryptographic census with the shelf life test that quantifies your protection margin in years, the vendor questionnaire that extracts dated commitments, and the obligation register rebuilt for the amended European timeline.
Get the instrumentsThe reasoning behind the Clock
The Clock is the headline diagnostic of When Agents Rule. The Introduction sets it out, Chapters 4 to 8 turn each quadrant into a discipline, and Chapters 10 and 11 build the financial case a CFO will fund.
Get the bookThe clock is already running
Read it honestly, then build the answer before the crisis asks for it.
About this reader. The Sovereignty Clock is the headline diagnostic of When Agents Rule by Steven Oppenheim. This reader is a self assessment instrument, not an audit, a certification or a benchmark. It reflects what you tell it, so a generous reading produces a flattering result and no useful information. Nothing you enter leaves your browser: there is no account, no transmission and no storage. Framework references in the crosswalk were current at the September 2026 build date and should be verified against primary sources before being cited in a regulatory filing or an audit response. Under Regulation (EU) 2026/1744 the EU AI Act high risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I; whether they apply to a given system is a legal determination for qualified counsel. This is not legal, technical or financial advice.