{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-030.json",
  "source": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-030",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-AGENT-030",
    "profile": "agent-runtime",
    "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-030",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-030.json",
    "title": "EU AI Act hooks for a high-risk purpose",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "An agent, classified by its intended purpose, that serves an Annex III purpose keeps event logs over its lifetime (Art. 12), has oversight commensurate with its autonomy level (Art. 14(3)-(4)) and competent overseers with authority (Art. 26(2)), and its logs stay under the deployer's control for at least six months (Art. 26(6)).",
    "failureModes": [
      "An agent with an Annex III purpose runs with no event log over its lifetime, or its logs are kept under the deployer's control for less than six months.",
      "Oversight is not matched to the autonomy level, or no overseer with the competence, training and authority is assigned."
    ],
    "scope": "Agents whose intended purpose falls under Annex III of the EU AI Act.",
    "enforcementPoints": [
      "runtime"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Traces; checkpoints and raw-call approvals; approver roster; log retention",
        "schemaId": null,
        "schema": null,
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "To be specified."
    },
    "layer": 5,
    "secondaryLayers": [],
    "patterns": [],
    "seeds": [
      {
        "id": "ai-act-high-risk",
        "title": "EU AI Act hooks for a high-risk purpose",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#eu-ai-act-hooks-for-agents"
      }
    ],
    "derivedFrom": [],
    "mappings": {
      "obligations": [],
      "iso42001": [],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 28,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"EU AI Act hooks for agents\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#eu-ai-act-hooks-for-agents",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Classify by intended purpose, not architecture: an agent that screens job applicants is high-risk through Annex III, and a scheduling assistant is not."
    ],
    "openQuestions": [
      "Verification procedure and evidence schema to be specified; requires technical review.",
      "Chapter 23 ties this control to the EU AI Act articles it names; the derivation carries obligations only through mapped OWASP Agentic threats, so the obligation mapping awaits review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
