A JSON-schema, machine-readable governance artefact that declares an agent's allowed and forbidden behaviours for runtime enforcement 1.
- Developed in
- ch. 05, Pattern: Policy Card
- Chapters
- ch. 04, The Stack · ch. 05, Patterns · ch. 10, Reading List · ch. 23, AI Agents
- In the open reference
- Open control profiles
- Source
- 1 numbered reference, listed below
Where it is used
13 chapters of the Body of Knowledge use the term. Each link opens the first section that does.
- 04 · The Stack Layer 01: Govern-as-Code 2 mentions
- 05 · Patterns Pattern: Policy Card 3 mentions
- 06 · The Role What the role owns, by workflow 2 mentions
- 10 · Reading List Papers (machine-readable evidence and agent governance) 1 mention
- 11 · AI Defined Kinds of AI that change the governance problem 5 mentions
- 12 · Governance Program Policies across the lifecycle 1 mention
- 13 · Risk Management Treating risk: the mitigation hierarchy 1 mention
- 15 · Deployment Secondary use and downstream harm 1 mention
- 16 · Fairness & XAI The impossibility results 2 mentions
- 17 · Incidents A severity scale mapped to the clocks 2 mentions
- 18 · EU AI Act The risk ladder 1 mention
- 20 · Existing Law Intellectual property 1 mention
- 23 · AI Agents Runtime guardrails for tool calls 1 mention
Patterns that use this term
12 pattern pages use the term; the 10 that use it most:
- Runtime Guardrail 7 mentions
- Policy Card 6 mentions
- Downstream Use Register 4 mentions
- Framework Crosswalk 3 mentions
- Sanctioned AI Gateway 3 mentions
- FRIA-as-Code 2 mentions
- Eval Gate in CI 1 mention
- Agent Identity & Scoped Credentials 1 mention
- Human-in-the-loop Gate 1 mention
- Use-Case Intake & Risk Tiering 1 mention
Related terms
Sources
- [1] Policy Cards: machine-readable runtime governance artefacts for agents. arXiv 2510.24383. 2025-10. https://arxiv.org/abs/2510.24383 (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .