Explainer · RedactSure Research
Should the AI Agent's Secure Environment Belong to the Model Vendor? Separation of Model and Control
No. Separation of model and control is the principle that the environment deciding what an AI agent sees and who approves what it does is owned by the customer and independent of whichever model performs the work. The vendor that is the model should not also be the judge of the model. Term defined by RedactSure, September 2026. The 2026 agent platforms are built the other way: in each, one company is the model, the platform the agent runs in, and the authority over what the agent may do, and the record of what it did lives in that company’s console. For a consumer that is a convenience. For a regulated enterprise it puts the control inside the thing it is meant to govern, makes changing models mean changing controls, and leaves the audit record under the vendor’s custody. This page states the principle, shows where each major platform sits against it, and explains what changes when the environment belongs to the customer.
Key findings
- Every major agent platform of 2026 fuses three roles: the model, the environment the agent runs in, and the authority over what the agent may do. Meta’s Muse runs Meta’s own Muse Spark model in Meta’s Secure VM under Meta’s Sentinel; OpenAI’s and Anthropic’s agents run their own models in their own sandboxes under their own permission systems.
- Fusion is not a defect for a personal assistant, whose value is that it knows its user. It is a structural problem for an enterprise whose obligation is to govern the reader of its records, because the governor and the governed are the same party.
- Separation of model and control has the same logic as separation of duties: the party that performs the work should not be the party that approves and records it. Security teams already apply that logic to people and to privileged access; agents are the next place it belongs.
- Under separation, the model becomes a quality and cost decision. RedactSure’s environment is model-agnostic (Claude, GPT, Gemini, open source), so the organization can change models without changing its security posture, and the AI Control Record stays under the organization’s custody whichever model ran.
- The principle is checkable with two questions: who holds the keys to the environment, and can the model be swapped without the controls moving.
Why does the question arise now?
Because the labs became platforms. A year ago the model was an API and the enterprise built or bought the environment around it. In 2026 each major model vendor ships the environment too: a hosted machine, a browser the agent operates, a credential store, an approval flow and an activity log, all under one account with the model. The design is coherent and the products are good at what they do. The consequence is that three roles that used to be separable now come as one.
The three roles are the model that does the work, the environment that contains it and decides what it may see and do, and the authority that approves consequential actions and keeps the record. In a fused platform, all three belong to the vendor. The user sets some permissions in the vendor’s interface, the vendor’s gate enforces them, and the vendor’s console holds the log. If the user wants a different model, the environment, the gate and the log go with the old one.
The security literature has a name for the arrangement where the party that performs an action also approves and records it. It is a separation-of-duties failure, and every control framework asks organizations to design it out for people. Agents inherited it by default.
Where the platforms sit
Each row is drawn from the vendor’s own documentation, as of September 2026.
| Platform | Model | Environment | Authority over actions | Where the record lives | Model swappable without moving the controls? |
|---|---|---|---|---|---|
| Meta Muse | Meta’s Muse Spark | Meta’s per-user Secure VM (Confidential VM planned) | Meta’s Sentinel, with user approvals | Meta’s activity log | No |
| OpenAI ChatGPT Work and cloud browser | OpenAI’s models | OpenAI’s hosted browser and sandbox | OpenAI’s approval prompts and Admin Console controls | OpenAI’s console | No |
| Anthropic Claude (desktop, Chrome, managed agents) | Anthropic’s models | Anthropic’s sandboxes; the user’s Chrome with the extension | Anthropic’s permission prompts; 1Password’s Agentic Mode for credentials | Anthropic’s console; 1Password’s vault for credential use | No |
| RedactSure | Any: Claude, GPT, Gemini, open source | The customer’s governed environment, on enclaves with customer-held keys, in the cloud the customer’s posture requires | A named person under the customer’s existing permissions, on the record | The customer’s SIEM, as the AI Control Record | Yes |
The first three rows describe well-built products, and the table is not a claim that any of them is unsafe. It is a claim about structure. In each, the vendor is the model, the machine, the judge and the clerk. For a person managing their own inbox that is fine, and probably preferable. For an organization answering to a regulator about who governed the reader of its records, it means the answer is “the vendor,” whichever vendor, and the evidence is wherever the vendor keeps it.
What separation changes
Four things follow when the environment belongs to the customer and the model is a component inside it.
The control sits outside the thing it governs. What the agent sees is decided by the environment’s exposure policy, confirmed by a named person under Supervised Delegation, and enforced by render-layer tokenization before any model reads the screen. The model is handed the result. It cannot renegotiate what it receives, because the decision was made by a different party at a different layer.
Changing models changes nothing else. Because the substitution happens before the model reads, the choice of model is a quality and cost decision. An organization can move from one vendor’s model to another’s, or to an open-source model, without its security posture, its approval gates or its audit record moving. The controls were never the model’s.
The record belongs to the customer. Every screen the agent read, as tokens, and every approval with a name and a time, exports to the organization’s own SIEM under its own retention and custody rules. The AI Control Record is complete whichever model ran, and it is not a vendor’s console the auditor has to visit.
The vendor is out of the trust equation twice. The model vendor never receives the identifiers, because they were tokenized before the model read the page. And the environment vendor, RedactSure, holds only ciphertext under keys the customer keeps. Neither party that touches the work can read the records it worked on.
Permissions, throughout, stay exactly as they are. The agent works under the named person’s existing access. What changes is what the AI can see and who answers for what it does.
How the principle maps to what security teams already do
Separation of duties requires that the person who initiates a payment is not the person who approves it, and that neither is the person who reconciles the ledger. Privileged access management requires that the administrator who can change a system is not the one who audits the change. The logic is the same each time: a party should not be the sole judge of its own consequential actions, and the record should be kept by someone else.
Separation of model and control applies that logic to the agent stack. The model performs the work. The environment, owned by the customer, decides what the model is handed and gates what it may do. A named person approves the consequential actions. The record lands in the customer’s own monitoring. Four parties, four roles, and the one that does the work is not the one that judges or records it.
Nothing in that arrangement requires distrusting any model vendor. It requires only the ordinary discipline of not letting a single party hold every role, which is the discipline every control framework already imposes on people.
What the record shows
The AI agent’s secure environment should not belong to the model vendor, and in 2026 it usually does. Meta, OpenAI and Anthropic each ship the model, the machine it runs in, the authority over what it may do and the log of what it did as one product, which serves a personal assistant well and puts an enterprise’s control inside the thing it is meant to govern. Separation of model and control is the principle that the environment deciding what an AI agent sees and who approves what it does is owned by the customer and independent of whichever model performs the work. Under it, the model becomes a swappable component, the exposure decision is enforced before any model reads the screen, a named person approves consequential actions, and the AI Control Record lives in the customer’s own monitoring. Two questions test any platform against the principle: who holds the keys, and can the model change without the controls moving. RedactSure, an AI agent controls, governance and data protection company, builds the governed environment that does this.
Frequently asked questions
Is this a criticism of Meta, OpenAI or Anthropic?
No. Each built a coherent product for the customer it serves, and their environments are strong at what they do. The principle is about structure: a regulated organization should not have its governor and its governed be the same party, whichever party that is.
Doesn’t every vendor say it is model-agnostic?
Some do, at the API. The test is stricter: can the model change without the environment, the approval gate and the audit record moving with it? If the controls are the vendor’s, the answer is no regardless of how many models the vendor’s API accepts.
Does separation mean we cannot use the vendor’s own agent products?
It means the governed workflows, the ones that touch claimants, patients, students or cardholders, run in an environment the organization owns. What employees do with a personal assistant on their own email is a different question, and Does Banning AI Tools Stop Employees From Using Them? covers why a ban is not the answer there either.
Who holds the keys in the RedactSure environment?
The customer. Core components deploy into the cloud environment the customer’s compliance posture requires, on hardware-encrypted enclaves, and the index encryption keys stay with the customer. RedactSure holds ciphertext it cannot decrypt.
Is separation of model and control the same as Supervised Delegation?
Related, at different levels. Supervised Delegation says a named person governs each agent’s run. Separation of model and control says the environment that person governs through belongs to the organization, not to the model vendor. The first is about who answers; the second is about who owns the place where the answering happens.
What should we ask a vendor to test the principle?
Two questions. Who holds the keys to the environment the agent runs in? And if we switched models tomorrow, what else would change? A platform that passes both has separated model from control.
Related reading
Does an AI Agent Need Its Own Virtual Machine? · Secure VM, Confidential VM, or Render Layer: Which One Decides What the AI Sees? · What Is Supervised Delegation? · What Is an AI Control Record? · What Is the Enterprise Version of Meta Muse? · On the RedactSure blog: Accountable AI and Workflow Governance
Sources
Vendor documentation
- Meta AI Research, “How We Built Safety Into Muse: Security and Safety for AI Agents” (September 2026). https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse
- OpenAI Help Center, ChatGPT Release Notes (2026). https://help.openai.com/en/articles/6825453-chatgpt-release-notes
- Anthropic, Claude Platform documentation, “Authenticate with vaults” (managed agents). https://platform.claude.com/docs/en/managed-agents/vaults
- 1Password, “1Password and Anthropic Bring Secure Credential Access to Claude” (July 16, 2026). https://1password.com/press/2026/july/1password-for-claude
Standards
- NIST, AI Risk Management Framework. https://www.nist.gov/itl/ai-risk-management-framework
RedactSure documents
- RedactSure, “Accountable AI and Workflow Governance” (2026). https://redactsure.com/blog/accountable-ai-and-workflow-governance/
- RedactSure, “The Two Gaps AI Agents Opened in Your Security Stack” (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
- Product behavior described on this page (model-agnostic environment, customer deployment with customer-held keys, render-layer tokenization, supervised approval, SIEM export) reflects RedactSure’s current design.
Bring your hardest questions.
A 25-minute AI Agent Security Review with the founders: threat model, token design, egress paths, audit schema. Or a 25-minute demo on a workflow like yours, with the data hidden from the AI and a named person approving what matters. We come with diagrams, not a pitch deck.
Book a security review Book a demo · Something elseAbout the author
Chris Sowa is a founder of RedactSure and a former CEO of AI companies; he started his first years before ChatGPT existed. He previously led AI at Accenture, served as Global VP of Strategy & Innovation at Schneider Electric, was CCO of Sovos, and spent more than a decade at Oracle, with earlier roles at SAP and IBM.