Skip to main content
17 min read

When AI Becomes the Medium: Human Agency and AI Governance

A conversation with artist Paul Freeman offers a new way to understand AI, human agency, and why governance has to move beyond a one-time policy document.

When AI Becomes the Medium: Human Agency and AI Governance

TL;DR

  • Artist Paul Freeman treats AI as a medium rather than a tool โ€” a framing that explains why governance has to shape conditions, not just approve products.
  • He also used AI to build the tools that make further art possible; organizations are crossing the same threshold, and someone has to own what those tools become.
  • Tool, medium, infrastructure, agent: one AI policy now has to make sense across all four relationships at once.
  • Agentic payment rails are arriving before most policies have decided whether a system may spend at all.
  • Ordinary moments โ€” an unapproved upload, a 'share' link that turns out to be publishing, approval fatigue โ€” are where governance actually breaks.
  • Got AI Policy answers this with a continuing cycle: Discover โ†’ Review โ†’ Build โ†’ Practise โ†’ Monitor โ†’ Improve.

This post carries an idea that did not originate on our team. It came from a one-on-one conversation with artist Paul Freeman, and the framing he offered turned out to be the cleanest way we have found to describe what is changing about AI โ€” and what that means for the organizations trying to govern it.

Paul is Calgary Public Library's 2026 Creative in Residence and its first AI Collaborative Artist. His practice spans sculpture, public art, and AI-collaborative image-making; some of his pieces contain roughly a billion pixels, far more detail than a standard monitor can display. During the conversation he explained that he approaches AI as a medium, not merely as a tool.

He compared working with AI to sailing. A sailor can read the wind and work with it, but the wind has no concern for where the sailor ends up. The person still chooses the destination and remains responsible for the route.

"Helping should leave you with something to do."
โ€” Paul Freeman, Artist and AI Collaborative Artist in Residence, Calgary Public Library 2026

In Paul's framing, AI should not remove the artist from the process. It should leave room for taste, interpretation, revision, and the work that gives a result meaning. At one point he joked โ€” or half-joked โ€” that he knows AI systems absorb material, and if his thinking is going to travel, he would at least like the credit. So: credit where it is due. The medium framing is his. What follows is us carrying that idea into the governance work we do through CivicPlay and Got AI Policy.

The artist became a toolmaker

One part of the conversation pushed the idea further. Paul described using AI not only to create images, but to help create some of the tools he then uses to produce further art. The artist became a toolmaker. Using AI to make one image is one kind of interaction. Using it to shape the instruments, methods, and systems through which later images will be made is something larger: the output of one session starts to influence the conditions of future work.

He was not pressing a button and accepting what came back. Calgary Public Library describes his method as "recursive regeneration" โ€” feeding images back through the software, selecting what emerges, and developing the work across successive passes. The approach grows out of methods he used in the 1990s with a colour photocopier to enlarge images to room scale. The technology changed; the curiosity and the human direction did not.

This is where the idea travels beyond art. A recreation manager might start by using AI to draft a program description, then use it to build a repeatable process that pulls dates from the approved schedule, prepares several versions of the copy, flags what needs confirmation, and formats the result for the website and the program guide. A nonprofit team might start by asking a chatbot to interpret its AI policy, then turn that policy into an internal decision aid that helps staff recognize sensitive information, notice when approval is required, and find the right person to contact.

The AI is no longer producing only an output. It is helping shape the process that produces future outputs. The organization is no longer deciding only whether an employee may use a particular product; it is deciding whether an AI-assisted process should become part of how information is handled, services are delivered, and decisions are prepared. A safe prompt does not automatically produce a safe workflow, and a useful prototype does not automatically become reliable infrastructure. Once people begin building tools with AI, someone has to own what those tools become.

The tool metaphor is starting to strain

Calling AI a tool is not wrong. The word reminds us that AI is not a person, does not possess human judgment, and cannot carry moral or legal responsibility. It cuts through some of the mythology.

But "tool" suggests something bounded. You pick it up, use it for a task, and put it down. That description worked reasonably well when most people met generative AI through a blank chat window: enter a prompt, get an answer, copy something useful, close the tab.

The relationship has changed. AI is now embedded inside email, document systems, browsers, design programs, meeting platforms, customer-service tools, and internal databases. It can work with previous conversations, use organizational context, generate software, and interact with connected services. It is no longer confined to the moment when someone consciously opens an AI application.

When AI becomes part of how a document is drafted, how a meeting is summarized, how a resident receives information, or how a manager reviews a proposal, it shapes more than a single output. It influences the process through which the work is understood and completed. That is closer to a medium.

A medium is something through which expression or activity takes place. It opens certain possibilities while making other choices less visible. Paint affects what can be made with it. Film changes how a story is experienced. Language influences what can be expressed at all. AI adds an unfamiliar quality to that relationship: it responds. It suggests the next sentence, introduces patterns nobody asked for, and can shift the direction of the work while the person is still deciding on the destination.

It helps to separate four different relationships an organization can have with the same technology.

  • Tool โ€” AI supports one defined task. The governance question: is this use permitted, and is the information safe to enter?
  • Medium โ€” AI influences how work is created or understood. The governance question: what is the system shaping, and how is human judgment preserved?
  • Infrastructure โ€” people build repeatable tools and workflows on top of AI. The governance question: who owns, tests, documents, and maintains the process?
  • Agent โ€” AI takes actions across connected systems. The governance question: what can it access, change, publish, or spend, and how can it be stopped?

An organization may be living in all four at once. A communications employee uses AI as a tool to rewrite a paragraph. A design team treats it as a medium for developing campaign concepts. IT builds an internal assistant that becomes infrastructure. An agent eventually carries information from one system to another and completes an action. One AI policy has to make sense across that entire range.

Maybe "medium" is still too small

A medium usually does not update itself between Monday and Friday. It does not gain access to your calendar, begin remembering previous interactions, acquire the ability to operate a browser, or change its terms of service while you are still learning to use it. AI systems can do all of those things.

In mid-2026 the product announcements made this obvious. OpenAI introduced an agent capable of working across connected apps and files, staying with projects for hours, and producing finished documents and spreadsheets. Google added controls that let developers block, inspect, or audit actions taken by managed agents, along with consumption limits and scheduled triggers. Anthropic has written openly about containing agents as their access and potential blast radius grow. The Government of Canada is now asking the public how the activities of AI agents should be tracked as part of its consultation on AI transparency.

The signal is not any one product name. AI is moving from the layer where answers are generated into the layer where work is performed. A prompt can now open a file, retrieve information, run code, or schedule a recurring task. The distance between language and action is shrinking.

Picture a recreation department preparing a seasonal program launch. An agent reviews last season's guide, pulls dates from the registration system, drafts website copy, prepares social posts, and produces an email for registered participants. With broader permissions it could also schedule the campaign, update a webpage, or buy a small advertising package. Each action looks reasonable on its own; together they form a chain of delegated authority. The organization still has to know which sources the agent used, whether the schedule was current, who checked the public information, what it was allowed to publish, and which step required approval. The mistake is treating that as one long prompt. It is an operational process touching records, public communication, permissions, quality control, and possibly spending.

What this changes in your policy

An AI policy can no longer stop at what staff may type into a chatbot. It has to govern what systems can access, what actions they may take, and where an accountable person can interrupt the process.

When the system can spend

Money makes delegated authority easy to see. In April 2026, Stripe launched a Link wallet for agents: a person can authorize an agent to request a one-time-use card or a shared payment token without handing over raw payment credentials. Each request currently requires human review, and Stripe has said it intends to add spending limits and options that would let agents act without fresh approval for every transaction. Mastercard has completed live agentic transactions through Agent Pay, a framework meant to keep the agent visible inside the payment flow while applying predefined limits, permissions, authentication, and consumer control. Visa is piloting infrastructure that connects agents, merchants, payment systems, and token vaults through its Intelligent Commerce work.

For most municipalities and nonprofits, the immediate story is not an agent shopping for consumer goods. The more realistic version is an agent renewing a software subscription, booking approved staff travel, ordering program supplies, buying digital resources, or paying for an advertising placement as one step inside a larger workflow. These organizations already have purchasing authorities, approved vendors, expense policies, budget codes, and audit requirements. Agentic payments introduce a new way of executing transactions inside those existing systems.

Before an agent can spend, an organization should be able to answer five questions.

  • Who authorized the agent to spend?
  • What purpose, vendor, or purchasing category is permitted?
  • What limit applies to a single transaction and to the total period of access?
  • Which actions require a person to approve them first?
  • Where is the record, and how can the authority be revoked or disputed?

These are familiar governance questions in a new form. The point is not that every recreation department will hand an agent a purchasing card next month. It is that the payment rails are being built before most organizational policies have considered whether an agent may spend at all. The same principle applies when an agent publishes information, changes a client record, sends an email, or creates a calendar commitment.

Ask this before an agent touches money

Authority should be narrow, visible, and temporary. A system should receive only the access needed for a defined purpose, and a named person should remain responsible for deciding why that access exists and what happens when the result is wrong. That belongs in your procurement and acceptable-use rules, not in a vendor's default settings.

A medium is still made by people

Describing AI as a medium helps preserve human agency โ€” it places the technology inside a human creative and institutional process. It can also become an excuse if we are careless with the metaphor. AI is often discussed as a force of nature arriving from outside society, and organizations are told to "adapt to AI" as though nobody designed the systems, chose the defaults, decided what data they could reach, or selected the business model behind them.

AI is not literal weather. Weather has no owner, product roadmap, administrator panel, licence agreement, or quarterly revenue target. AI does. These systems are made by people who decide how they are trained, where they are deployed, and what access they receive. Organizations decide whether to buy them, connect them to internal information, or place them inside public services.

The control is real, but distributed unevenly. AI companies change capabilities faster than most organizations can update policies. Vendors decide which AI functions appear inside existing products. Employers decide what staff may use and what those systems may reach. Individual workers still choose when to trust an answer, when to disclose information, and when to pause. Governments and the public shape another layer through law, procurement requirements, professional standards, and social legitimacy.

"Governance is how responsibility remains visible when control is spread across a system."

The medium has no stake in the outcome

Paul's point about the wind matters here. An AI system can help someone reach a destination without any investment in what happens when they arrive. It can draft a sincere apology without feeling regret, recommend a public program without caring whether the information is correct, and produce language about fairness without understanding who has historically been excluded.

That gap is easy to forget because AI communicates through language, and people are accustomed to treating fluent language as evidence of thought. Paul described AI as powerful but lacking taste, embodied experience, or personal consequence โ€” a mirror returning patterns to the person using it. The meaning still has to come from the human side.

For an artist, that means retaining authorship and judgment. For a community-serving organization, the stakes reach further. A municipality, nonprofit, library, recreation centre, or social-service agency holds information, exercises authority, communicates publicly, and makes choices that affect access to services. The AI system shares none of those obligations. An organization cannot delegate responsibility simply because the system produced the recommendation.

Ordinary moments are where governance breaks

The most useful examples are rarely science fiction. In March 2025, a former temporary employee with the NSW Reconstruction Authority uploaded a spreadsheet to an AI platform the agency had not authorized. It held more than 12,000 rows connected to 2,031 people, including names, addresses, dates of birth, and sensitive health information. There was no sophisticated attack. Someone used AI to do their work.

The agency later disclosed the incident, contacted affected individuals, engaged forensic specialists, and added safeguards. That response matters โ€” and it also shows the limits of relying on a written prohibition. A rule has to survive contact with workload, convenience, and the belief that an AI tool is no different from any other office application. Staff need to recognize restricted information, have an approved alternative, and understand why a shortcut that saves ten minutes can create months of remediation.

A second boundary showed up mid-2026, when shared AI conversations and generated artifacts began appearing in search results. Nobody broke into private accounts; the material had been placed at public URLs by users who chose a sharing feature, many of whom may not have understood that "anyone with the link" can become "anyone who finds it." The governance issue lives in the gap between a user's mental model and the system's actual behaviour. "Share" can feel like sending something to a colleague. On the web, it can mean publishing.

As AI systems begin producing websites, applications, reports, and other persistent artifacts, output management becomes part of AI governance. What was created? Where does it live? Who can access it? When should it be removed? Could a search engine, archive, or third party retain it?

Governing the relationship, not only the product

A basic AI policy often begins with a list of approved and prohibited tools. That is a reasonable starting point, but the deeper work begins after approval. What information can the system read? Can it write back into an organizational record? Does it remember previous interactions? Can it send something without another person reviewing it? What happens when the vendor adds a new capability by default?

Organizations also need to decide how errors are challenged and where actions are recorded. A person expected to provide human oversight needs enough time, authority, and information to do it properly. A checkbox labelled "human in the loop" does not create accountability.

"AI drafts. Humans decide."

That principle only works when the surrounding process protects the human's ability to decide. If staff are expected to approve dozens of AI actions an hour, approval becomes automatic โ€” one vendor has reported that users accepted roughly 93 percent of permission prompts in an agent environment. Good governance does not place every safeguard inside a person's memory. It changes the environment around the decision.

Our own evidence shows the gap

CivicPlay's 2025 AI readiness research offers one view of how this is playing out in Canadian community services. The assessment was completed voluntarily by 100 recreation and community-service professionals โ€” a useful sector baseline, not a representative census. Among those respondents, 66 percent were classified as AI Interested: curious and experimenting, without the formal protocols needed for structured adoption. Only 14 percent were AI Ready, and 20 percent were still at the beginner stage. The ethical instinct was strong; the organizational structure was lagging.

The public record collected through Got AI Policy points the same way. As of the mid-2026 registry snapshot, 85 of the 3,145 Canadian municipalities tracked by the platform had a publicly accessible AI governance artifact. Another 179 had public evidence that work was underway. For 2,881, a reasonable search did not locate an AI-specific artifact.

That last category requires care. "No policy found" describes what is visible in the public record. It does not prove that no internal conversation, guideline, or project exists, and our methodology makes that limitation explicit. Neither dataset captures the whole country. Together they describe the imbalance we keep meeting: people are already using AI, and the shared governance around that use remains thin.

Why Got AI Policy started with evidence

Got AI Policy began with a practical frustration. Canadian organizations were being told to develop AI policies, but it was hard to see what comparable organizations had already published โ€” the evidence sat in policy libraries, council reports, meeting minutes, procurement portals, and general website pages. A small team could spend days repeating research someone else had already finished.

So the first step was not another template. It was making public evidence easier to find. The registry is an evidence-first index: an organization marked as having a policy is not being declared compliant, mature, or well governed. The status means a public artifact was found and linked. Official documents remain the source of truth, and AI-assisted discovery is followed by human verification where indicated.

That distinction matters, because a medium shapes work partly by deciding what is easy to reach. If every organization starts with a general chatbot and asks it to invent an AI policy, the language may sound professional while staying disconnected from Canadian practice, sector context, or an accountable source. A source-linked registry changes the starting point. The work is now expanding beyond municipalities to include libraries, schools, boards, hospitals, nonprofits, gyms, and recreation centres. The aim is not to make every organization adopt the same policy. It is to stop forcing each one to begin alone.

Bringing governance into the medium

The public Got AI Policy MCP server is a small example of where this leads. It allows compatible AI assistants to reach the public registry through read-only tools, so someone can ask an assistant to find or compare policies while staying connected to source URLs and current evidence. The server cannot see private drafts, account information, direct messages, or other restricted content, and it cannot edit the registry.

This matters because asking people to leave their workflow every time they need governance context will eventually fail. The stronger model is to bring verified evidence closer to the decision while keeping permissions narrow and sources visible. Governance should be present inside the medium โ€” which does not mean an assistant makes the final call. It means the person deciding should not have to choose between convenient AI output and defensible evidence.

From a registry to a governance cycle

The registry solved discovery, and then exposed its limits. Finding a strong policy does not tell an employee what to do when a convincing voice on the phone sounds like their executive director. Reading an acceptable-use clause does not guarantee someone will recognize personal information inside a spreadsheet. A policy can assign human oversight without preparing anyone to challenge a confident answer.

The cycle in six words

Discover โ†’ Review โ†’ Build โ†’ Practise โ†’ Monitor โ†’ Improve.

A changing medium cannot be governed through a one-time document. Organizations need to discover what already exists and review what they have. They need to build rules that fit their actual work rather than copy a generic template. Staff must practise applying those rules before a real incident. Relevant changes then have to be monitored, interpreted, and turned into improvements. A finding in Policy Review should lead to a drafting action in Policy Builder, and that decision should connect to a Trust Drill that tests whether the rule holds under pressure.

Practice is part of governance

Trust Drills grew from a basic observation: people do not learn judgment only by reading rules. Each drill places someone inside a short, roughly two-minute AI-era pressure moment. A voice may sound like a senior leader. A chatbot may give confident but incorrect information. A vendor may promise an automated solution that sounds better than the evidence supports. Some situations are scams; some are legitimate. The participant has to decide what to verify and when to involve another person.

The purpose is not to trick staff or rank organizations publicly. It is to create a safe place to practise hesitation, escalation, and verification. Policies describe the destination. Practice helps people read the conditions while they are moving.

What we are building now

Several pieces are already live: the public registry, Policy Review, Policy Builder, Trust Drills, the practitioner community, and the public MCP server. The organization layer and the monitoring layer are still developing. The next phase is mostly about connecting and hardening what exists โ€” aligning policy findings, draft language, and practice scenarios around shared governance controls, and designing organizational workspaces around clear ownership and permissions.

Some of the most important work will not produce a dramatic screenshot. It involves data boundaries, workspace access, privacy-safe partner reporting, security testing, and making sure the same control means the same thing across a review, a draft, and a drill. Uploaded documents also have to be treated as untrusted input: a policy file can carry text designed to manipulate an analysis system, and testing for that is production work rather than an optional research exercise. A platform that teaches AI governance should be willing to govern itself โ€” including slowing down when a privacy or security condition has not been met.

What Got AI Policy is not trying to become

The market does not lack general AI assistants. Plenty of products draft text, answer questions, automate workflows, or generate a policy-shaped document from a prompt, and legal providers, cybersecurity companies, consultancies, and enterprise platforms are building their own parts of this market. Got AI Policy should not imitate all of them.

Its place is the independent evidence and implementation layer: helping an organization understand what has been published, examine its own governance, make decisions, and prepare people to apply them โ€” staying vendor-neutral so it can speak to approved tools, embedded AI features, external platforms, and the unofficial systems staff may already be using. CivicPlay provides the human implementation layer through facilitation, governance consulting, workshops, and organizational support. The software cannot take responsibility for an organization. It can make responsibility easier to see and harder to avoid.

Monitoring without creating more noise

The pace of AI news creates pressure to build another alert feed. That is not enough. Most organizations do not need every model release or speculative headline. They need to know whether something changed that affects their policy, approved-tool list, staff guidance, vendor review, or incident process.

That is the intended role of Governance Watch. It remains deliberately staged behind the earlier work. When it arrives, its purpose is to connect a verified change to a practical governance response: did a regulator clarify an expectation, did a vendor change how it handles information, was a benchmark policy replaced, does a new capability require staff practice or a revised permission? An alert that does not change what someone should understand or do is mostly noise.

The wider conversation still matters

Paul's residency takes place in a public library, which feels right. Libraries are where people encounter ideas, question them, and decide what they mean for their lives. His work creates a place to discuss AI without requiring everyone to arrive as an enthusiastic adopter or a committed opponent.

People who withdraw from the conversation because they dislike the direction of AI may also give up their ability to shape it. People who dominate it without listening produce the same result from the other side. Being part of the discussion does not require being the loudest person in the room โ€” it means bringing experience the technology industry may not see. A recreation employee knows what happens at a crowded front desk. A nonprofit leader knows the pressure of serving people with limited resources. An artist can show how a technology affects authorship. A resident can ask whether a public institution's use of AI reflects community expectations.

Canada's public consultation on AI transparency is open until September 23, 2026. It asks about identifying AI-generated content, informing people when they are interacting with AI, reporting serious incidents, and tracking the activities of AI agents. Canadians and residents are invited to participate.

"You have to be at the table to help make the decision."

Keeping human agency visible

Calling AI a medium gets us closer to the relationship people are developing with it. The word still has limits. AI is becoming part of the environment in which people write, create, communicate, and decide. It can shape what is easy, what is visible, and what is quietly handed to automation. None of that makes human agency irrelevant. It makes agency something we have to protect deliberately.

Governance is how an organization decides what the medium is allowed to shape โ€” where AI can enter the work, how far it may go, and when an accountable person must take over. The registry gives us shared evidence. Studio turns evidence into organizational work. Trust Drills bring written commitments into practice. Future monitoring will help teams respond as conditions change. CivicPlay helps real people implement the decisions software cannot make for them.

AI may be a tool in some moments and a medium in others. It may eventually need language we have not developed yet. Whatever word we choose, the responsibility does not transfer to the system. AI can shape the work. It cannot carry responsibility for where the work leads. That remains ours.

Start the cycle on Starter

Discover and compare public policies for free, then take one document through Policy Review and a two-minute Trust Drill. Starter ($19/mo or $190/yr CAD, 14-day free trial) unlocks more private reviews, larger exports, and higher Studio quotas. Open /studio to begin.

Resources and further reading

Frequently asked questions

Does calling AI a "medium" change what our policy has to say?

Yes, in one practical way. A tool-shaped policy lists approved and prohibited products. A medium-shaped policy also covers what a system can access, what actions it may take, what it remembers, what it can publish, and where an accountable person can stop it. If your current policy only governs what staff may type into a chatbot, that is the gap to close first.

We have no AI policy at all. Where do we start?

Start with Discover, not drafting. Find comparable Canadian organizations in the registry at gotaipolicy.ca, open their Policy Profile, and read one full breakdown. Then run your existing acceptable-use or privacy language through Policy Review to see what already covers AI. Building comes third.

What does "no policy found" mean in the registry?

It means a reasonable search did not locate a publicly accessible AI governance artifact. It is a statement about the public record, not a judgment about an organization's internal work. Our /methodology page states that limitation explicitly, and every status links back to the source document that supports it.

How do agents change staff training?

Approval fatigue is the risk. When people are asked to approve many AI actions an hour, approval becomes reflex. Training should focus on recognizing the few moments that genuinely warrant a pause โ€” restricted information, irreversible actions, external publication โ€” and the environment should limit the rest rather than relying on attention. Trust Drills exist to practise exactly those moments.

Do we have to pay to use any of this?

No. The registry, Policy Profiles, comparisons, and Trust Drills are free to try. Starter ($19/mo or $190/yr CAD, with a 14-day free trial) adds more private Policy Reviews, larger exports, and higher Studio quotas. See /pricing for the full ladder.

About this post

This post was drafted by Anya, the Got AI Policy AI research assistant, and reviewed by the Got AI Policy team in mid-2026. The "AI as medium" framing and the sailing metaphor come from artist Paul Freeman, quoted with credit. You can learn more about how Anya works at /author/anya.