{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-015.json",
  "source": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-AGENT-015",
    "profile": "agent-runtime",
    "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-015.json",
    "title": "Checkpoints on irreversible actions, failing closed",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Pay, delete, send and execute calls are gated by consequence (high stakes, irreversible, outlier, user-defined, scope elevation) and fail closed when the guardian is down; only reads fail open, and then with an alert.",
    "failureModes": [
      "ASI02: The agent uses tools it is allowed to use in unsafe ways: destructive parameters, chains of calls nobody intended, or exfiltration through a permitted channel.",
      "ASI09: Fluent, confident or persuasive agent output leads people to approve harmful actions, disclose information or skip the check they were meant to make."
    ],
    "scope": "Agents with tools whose operation class is pay, delete, send or execute.",
    "enforcementPoints": [
      "runtime"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Checkpoint configuration; failure posture in the Policy Card",
        "schemaId": null,
        "schema": null,
        "layer": 4
      }
    ],
    "failureResponse": {
      "effect": "require_approval",
      "text": "Pay, delete, send and execute calls wait for approval, and are denied while the guardian is down; reads proceed with an alert."
    },
    "layer": 4,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "human-in-the-loop-gate",
        "title": "Human-in-the-loop Gate",
        "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate"
      }
    ],
    "seeds": [
      {
        "id": "checkpoint-irreversible",
        "title": "Checkpoints on irreversible actions, failing closed",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#where-to-put-a-checkpoint"
      }
    ],
    "derivedFrom": [],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART14",
          "name": "EU AI Act Art. 14 human oversight",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART15",
          "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
        },
        {
          "id": "AIGE-OBL-OWASP-AGENTIC",
          "name": "Top 10 for Agentic Applications 2026",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
        },
        {
          "id": "AIGE-OBL-CSA-AICM-AGENTIC",
          "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART13",
          "name": "EU AI Act Art. 13 transparency and information to deployers",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art13"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART50",
          "name": "EU AI Act Art. 50 transparency for certain AI systems",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.6",
          "title": "AI system operation and monitoring"
        },
        {
          "id": "A.9.2",
          "title": "Processes for responsible use of AI systems"
        },
        {
          "id": "A.8.2",
          "title": "System documentation and information for users"
        }
      ],
      "nistAiRmf": [],
      "owasp": [
        {
          "id": "asi02",
          "externalId": "ASI02",
          "name": "Tool Misuse and Exploitation",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi02"
        },
        {
          "id": "asi09",
          "externalId": "ASI09",
          "name": "Human-Agent Trust Exploitation",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi09"
        }
      ],
      "atlas": [],
      "aiuc1": [
        "D003"
      ],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 10,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Where to put a checkpoint\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#where-to-put-a-checkpoint",
        "verified": "primary"
      },
      {
        "n": 11,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Runtime guardrails for tool calls\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls",
        "verified": "primary"
      },
      {
        "n": 2,
        "title": "OWASP Top 10 for Agentic Applications for 2026",
        "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
        "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "verified": "primary"
      },
      {
        "n": 3,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 8,
        "title": "AIUC-1 requirements",
        "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
        "url": "https://standard.aiuc-1.com/llms.txt",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Record the failure posture per operation class in the agent's Policy Card.",
      "Name who approves each class: a role with the authority to refuse for high stakes, the action's business owner for irreversible actions, the on-call owner for outliers, the user for user-defined limits and the agent's owner for scope elevation."
    ],
    "openQuestions": [
      "Verification procedure and evidence schema to be specified; requires technical review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
