{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-012.json",
  "source": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-012",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-AGENT-012",
    "profile": "agent-runtime",
    "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-012",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-012.json",
    "title": "Trajectory anomaly detection",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "The agent's behaviour is monitored as it unfolds, and anomalies (calls unrelated to the purpose, parameters outside the profile, calls after expiry, spend spikes) are flagged and either halt the agent or escalate to a person.",
    "failureModes": [
      "A call unrelated to the task purpose, a parameter outside the registry profile, a call after expiry or a spend spike occurs and no anomaly event is raised.",
      "An anomaly is flagged but neither halts the agent nor reaches a person.",
      "The monitoring is switched off: METR states that its red-teaming found several simple ways for agent monitoring to be disabled, one by changing an environment variable."
    ],
    "scope": "Every agent that calls tools, in production or in an evaluation harness.",
    "enforcementPoints": [
      "runtime"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Anomaly events and decisions",
        "schemaId": null,
        "schema": null,
        "layer": 4
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "To be specified."
    },
    "layer": 4,
    "secondaryLayers": [],
    "patterns": [],
    "seeds": [
      {
        "id": "trajectory-anomaly",
        "title": "Trajectory anomaly detection",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#an-agent-incident-taxonomy"
      }
    ],
    "derivedFrom": [],
    "mappings": {
      "obligations": [],
      "iso42001": [],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [
        "B006"
      ],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 16,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"An agent incident taxonomy\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#an-agent-incident-taxonomy",
        "verified": "primary"
      },
      {
        "n": 17,
        "title": "Frontier Risk Report (February to March 2026)",
        "text": "Frontier Risk Report (February to March 2026) (red-teaming found several simple ways for agent monitoring to be disabled, one by changing an environment variable). METR. 2026-05-19.",
        "url": "https://metr.org/blog/2026-05-19-frontier-risk-report/",
        "verified": "primary"
      },
      {
        "n": 8,
        "title": "AIUC-1 requirements",
        "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
        "url": "https://standard.aiuc-1.com/llms.txt",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Use the chapter's agent incident taxonomy for the detection signal and the first containment of each class; the severity scale and reporting clocks are those of chapter 17."
    ],
    "openQuestions": [
      "Verification procedure and evidence schema to be specified; requires technical review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
