{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-027.json",
  "source": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-027",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-AGENT-027",
    "profile": "agent-runtime",
    "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-027",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-027.json",
    "title": "Data classes recorded, with the DPIA linked",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "The registry entry records the agent's data classes and memory stores and links the DPIA and the records of processing, and each tool states which data classes may flow in and out (the chapter's example: no special-category data to external tools).",
    "failureModes": [
      "The registry entry names no data classes or memory stores, or links no DPIA or records of processing.",
      "A data class reaches a tool that may not receive it, such as special-category data sent to an external tool."
    ],
    "scope": "Every agent that calls tools, in production or in an evaluation harness.",
    "enforcementPoints": [
      "deploy"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Registry fields; DPIA and records-of-processing links",
        "schemaId": "agent-register-entry",
        "schema": "https://aigovernanceengineer.com/schemas/agent-register-entry.v1.json",
        "layer": 2
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "To be specified."
    },
    "layer": 2,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "agent-registry",
        "title": "Agent Registry",
        "url": "https://aigovernanceengineer.com/patterns/agent-registry"
      }
    ],
    "seeds": [
      {
        "id": "data-classes",
        "title": "Data classes recorded, with the DPIA linked",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#the-agent-registry"
      }
    ],
    "derivedFrom": [],
    "mappings": {
      "obligations": [],
      "iso42001": [],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 1,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"The agent registry\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#the-agent-registry",
        "verified": "primary"
      }
    ],
    "implementationNotes": [],
    "openQuestions": [
      "Verification procedure and evidence schema to be specified; requires technical review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
