{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-001.json",
  "source": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-001",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-AGENT-001",
    "profile": "agent-runtime",
    "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-001",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-001.json",
    "title": "Registry entry",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Every agent is registered before it reaches production, in an entry written by the pipeline that records its identity, owner, purpose, autonomy level, tools and scopes, data classes and memory stores, delegation rights, versions, checkpoints, stop handles, expiry, and regulatory role and class.",
    "failureModes": [
      "ASI10: An agent drifts from its intended behaviour or scope (through compromise, misalignment or neglect) and keeps acting, possibly deceptively, where nobody is watching."
    ],
    "scope": "Every agent that calls tools, in production or in an evaluation harness.",
    "enforcementPoints": [
      "deploy"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "The entry, and every log line that joins to it",
        "schemaId": "agent-register-entry",
        "schema": "https://aigovernanceengineer.com/schemas/agent-register-entry.v1.json",
        "layer": 2
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "To be specified."
    },
    "layer": 2,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "agent-registry",
        "title": "Agent Registry",
        "url": "https://aigovernanceengineer.com/patterns/agent-registry"
      }
    ],
    "seeds": [
      {
        "id": "registry-entry",
        "title": "Registry entry",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#the-agent-registry"
      }
    ],
    "derivedFrom": [],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART14",
          "name": "EU AI Act Art. 14 human oversight",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART26",
          "name": "EU AI Act Art. 26 deployer obligations for high-risk systems",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART72",
          "name": "EU AI Act Art. 72 post-market monitoring",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
        },
        {
          "id": "AIGE-OBL-OWASP-AGENTIC",
          "name": "Top 10 for Agentic Applications 2026",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.6",
          "title": "AI system operation and monitoring"
        },
        {
          "id": "A.6.2.8",
          "title": "AI system recording of event logs"
        }
      ],
      "nistAiRmf": [],
      "owasp": [
        {
          "id": "asi10",
          "externalId": "ASI10",
          "name": "Rogue Agents",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi10"
        }
      ],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 1,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"The agent registry\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#the-agent-registry",
        "verified": "primary"
      },
      {
        "n": 2,
        "title": "OWASP Top 10 for Agentic Applications for 2026",
        "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
        "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "verified": "primary"
      },
      {
        "n": 3,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      }
    ],
    "implementationNotes": [
      "The deploy pipeline writes the entry, so an agent cannot reach production without one; the versions block makes an incident replayable and the stop block makes the kill switch more than a claim.",
      "Reconcile the registry against what runs, including SaaS connectors, coding agents on laptops and local MCP servers; an agent found by discovery is registered within a deadline or switched off."
    ],
    "openQuestions": [
      "Verification procedure and evidence schema to be specified; requires technical review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
