Governing AI: What a Japanese castle’s layered design teaches us

Chat GPT was first released in 2022. It worked as a single assistant that provided answers to anything you asked. Fast forward to 2026, AI has exploded exponentially. The new era has created multiple agents that are capable of creating their own autonomy. These new bots read data, make judgement and take real action without human interference. And these numbers will only grow as times go on. Although it’s a projection, a new Gartner report stated that large enterprises running fewer than 15 agents in 2025 could be running the order of 150,000 by 2028. The future predicts it will not stop just there. And that’s a scary prospect. Not only for you but your companies and future business. Because multiplying technologies doesn’t necessarily mean that they will be successful. This leads us back to what we are discussing in this article. How will you find a good product in this sea of technology? How can you actually govern Ai? Why is it necessary to govern AI? Most of the early 2026 surveys have found that while roughly nine in ten organizations already use AI agents in some form, only about one in ten have a clear strategy for managing those agents’ identities. Close to nine in ten reported a confirmed or suspected agent-related security incident in the prior year. And only about a fifth treat their agents as distinct identities at all (most still hand them the same human credentials or shared keys they already had on hand). Access control simply hasn’t been separated between people and agents. This is normal in the story of fast adoptions. One team will connect agents to their internal data to save time and chain tasks together. Each step is small and reasonable. The accumulation is neither. What’s making these agentic Ais different from earlier automations is that they acquire permissions as they run, call external tools, and act across many systems. So, the blast radius of a single overreach – or one leaked credential – is far wider than it used to be. Access control and governance simply haven’t kept pace with how fast the agents multiply. Why There’s No “Buy” Button For This Enterprises get another hurdle of solving this problem. What do you buy to fix this? Last month in San Francisco, the industry’s largest data-platform conference made AI-agent governance its central theme. This model had the ability to fine-grain permission control, audit logs that retained every action, and to be able to halt an agent when something goes wrong. These are powerful controls, but with a specific edge that takes out others. The narrator itself said, “it’s not the model itself that has the advantage, but how you place the data and context into it.” A competitor can go and replicate the same model, but it will be the design around it that will be visible in your ROI. Governance has always been a design problem first and a product problem second. So how do you draw a perfect structure that compliments your data and something that fits well? Thinking In Layers – The Castle’s “Nawabari” The Japanese people are known for their infrastructure. From adapting to earthquake resistant houses to making an unbreachable castle back in the days, they are strategic and methodical. Let’s take a look at this perfect example of Inyuma castle. A great castle isn’t defended by one tall wall. Its strength is in layers an outer moat, then a series of baileys nested one inside the next, and finally the keep at the center. Each enclosure has its own gate, and each gate re-checks what the last one already verified. The architects never assumed that every defence would hold but more so that they prepared for every fatality and arranged the layers so that no failure is fatal.   This method of building castles was called Nawabari. A master layout that artists used to have geography in their favor. They methodically built the castle so that every bailey, moat and forest wall could play a part in protecting the main castle. And that is also how you would want your AI governance to shape. Because with precision and strategy, comes returns and efficiency. In a shaped AI governance based on Nawabari, you can distinguish them as: Boundary (the moat): The part where the model and data will sit. Just like the messenger entering the first security check, the decisions will take place there. Identity & access (the main gate) The system decides who will enter. each agent gets its own identity, not a borrowed human credential, and the privilege it’s granted starts at the minimum. Zoned access (the baileys) Not all ground inside the walls is equal; data is partitioned by sensitivity. An agent admitted to an outer bailey has no business in the inner one. Access is scoped to purpose and re-checked at each layer, not granted once at the door. Most-critical zone (the keep) The most sensitive data and the highest-impact actions sit innermost, reached only after every gate has held and the most consequential actions require more than one approval. Continuous oversight (the watchtower) The vantage point that surveys the whole at once. Containment (the drawbridge) A well-built castle can isolate itself; when an agent drifts, you can revoke its access and contain the damage at once. The layers aren’t redundancy. They are the design. One guarded gate is a door. Five gates, each checking again, is a castle. How Automated Governance works as a Watchtower Castles had humans who could stand watch. This generation needs more agents because you can’t have a person posted at every gate. Especially in agent governance where practitioners believe that only manual review doesn’t solve the problem. To put it plainly: the only thing that can watch AI agents at the speed they move is another AI. Governance at scale becomes an agent watching the agents from the tower,  keeping, literally, an AI on the AI. That isn’t the abandonment of human control. It’s the