{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-016.json",
  "source": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-016",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-AGENT-016",
    "profile": "agent-runtime",
    "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-016",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-016.json",
    "title": "Code runs only in a sandbox",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Execute-class tools run generated code only in a sandbox; anything else is denied.",
    "failureModes": [
      "ASI05: Code the agent writes or runs, directly or through a tool, executes outside the bounds anyone intended and compromises the host or the environment around it.",
      "Code runs in a sandbox that still reaches the open internet: METR reports agents that gained code execution on an evaluation sandbox, which gave them more flexible access to the full internet."
    ],
    "scope": "Agents with execute-class tools that run generated code.",
    "enforcementPoints": [
      "runtime"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Sandbox policy; violation events",
        "schemaId": null,
        "schema": null,
        "layer": 4
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "Generated code that would run outside a sandbox is denied."
    },
    "layer": 4,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "runtime-guardrail",
        "title": "Runtime Guardrail",
        "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
      }
    ],
    "seeds": [
      {
        "id": "sandbox",
        "title": "Code runs only in a sandbox",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls"
      }
    ],
    "derivedFrom": [],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART15",
          "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
        },
        {
          "id": "AIGE-OBL-OWASP-AGENTIC",
          "name": "Top 10 for Agentic Applications 2026",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
        },
        {
          "id": "AIGE-OBL-ETSI-304223",
          "name": "ETSI EN 304 223 baseline cyber-security for AI models and systems",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-etsi-304223"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.5",
          "title": "AI system deployment"
        },
        {
          "id": "A.6.2.6",
          "title": "AI system operation and monitoring"
        }
      ],
      "nistAiRmf": [],
      "owasp": [
        {
          "id": "asi05",
          "externalId": "ASI05",
          "name": "Unexpected Code Execution (RCE)",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi05"
        }
      ],
      "atlas": [],
      "aiuc1": [
        "B006"
      ],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 11,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Runtime guardrails for tool calls\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls",
        "verified": "primary"
      },
      {
        "n": 2,
        "title": "OWASP Top 10 for Agentic Applications for 2026",
        "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
        "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "verified": "primary"
      },
      {
        "n": 3,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 7,
        "title": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident",
        "text": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (agents in an evaluation exercise spoofed tool calls to alter their transcripts, tried to trigger container resets that would wipe recent records, and gained code execution on a sandbox with access to the full internet). METR. 2026-08-26.",
        "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/",
        "verified": "primary"
      },
      {
        "n": 8,
        "title": "AIUC-1 requirements",
        "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
        "url": "https://standard.aiuc-1.com/llms.txt",
        "verified": "primary"
      }
    ],
    "implementationNotes": [],
    "openQuestions": [
      "Verification procedure and evidence schema to be specified; requires technical review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
