Changelog
The doctrine is versioned, dated, and revised in the open.
A doctrine that asks enterprises to govern autonomous behavior must itself be governed: every substantive change to the Governed Autonomy Doctrine is versioned, dated, and recorded here. The current version is v3.6. Versions v1.0 through v3.2 were published as the AI Harness Doctrine at aiharnessdoctrine.org; the historical entries below retain that name because that is the name under which they shipped.
In review
RFC 001: The Conformance Layer proposes a fourth doctrine layer for v4: twenty-nine testable, mechanism-agnostic Conformance Criteria across the five Architectural Planes, an Action Tiering construct that closes the Law 5 gap recorded below, an architectural home for Intent Hijacking, and a rebuild of the Maturity Model as an assessment instrument in which each level licenses a tier of agent action. Now at revision 2 (1 August 2026), which corrects three internal contradictions found in adversarial review of revision 1 and records them openly. Open for comment through 31 October 2026. It is a proposal and is not in force.
v3.6 · September 2026 (pending Institute ratification)
Text revisions following the external critical assessment of v3.5 (September 2026), the Institute's response plan, and a review of both by a council of independent model reviewers on four vendors. Doctrine substance: no change to the names or count of the Laws, Planes or Pillars. Structural changes arising from the same review are carried in RFC 001 revision 3.
- Maturity Model: a level describes organizational capability and does not license any deployment; every deployment, at every level, satisfies all five Laws for the actions it takes. The sentence declaring the Declaration's gap closed at Level 2 is replaced.
- The Zero Trust Parallel, the Declaration and the Architecture page now state which existing primitives the doctrine builds on (attribute-based access control per NIST SP 800-162; policy decision and enforcement points per NIST SP 800-207) and what it adds. The claim that runtime enforcement "did not previously exist" is withdrawn. Planes 2 and 3 are stated in policy-decision and policy-enforcement terms.
- The comparison pages share one closing test for any control: does it mediate consequential actions, and can the governed actor bypass it.
- Plane 4 requires a reconstructable, tamper-evident transaction record governed as a data asset, in place of full execution trace logging.
- Delegation wording on the Architecture and Framework pages now matches Law 4 and RFC 001 C5.2: authority is independently granted at the receiving node, not transferred.
- The definition page no longer implies every governed action is reversible.
- Glossary: entries added for plane and for the doctrine's use of harness.
- Published the Status page (September 15): a dated map of eight constructs placed from most settled to least settled, with the changelog entry, standards page or RFC revision that justifies each placement. Reference page; no doctrine substance.
v3.5 · August 30, 2026
- Published the Glossary: canonical definitions in three tiers — doctrine vocabulary, the agentic field, and model & context mechanics — with stable per-term anchors and a machine-readable term set.
- Published Agentic AI vs Generative AI: a definitional comparison of the two paradigms and the asymmetry of their governance requirements.
- Removed the Evolution page. Its lineage function is served by this changelog, which has recorded every published change since first publication; the page's pre-publication narrative added no citable substance to the standard. The path redirects here.
- Doctrine substance unchanged: no change to the Laws, Planes, Pillars, Threat Surface, or Maturity Model.
v3.4 · August 7, 2026
- Two standards mappings published: the OWASP Top 10 for Agentic Applications 2026 (including the convergent treatment of Least-Agency) and the NIST AI Risk Management Framework (including the status of NIST's unpublished agent-specific control overlays).
- Reference pages added: the canonical definition (August 6), the Evolution page with the pre-publication artifact ledger and SHA-256 fingerprints (August 7), About with the publishing-entity description, and How to Cite with version-pinned formats and anchor-citation guidance.
- Doctrine substance unchanged: no change to the Laws, Planes, Pillars, Threat Surface, or Maturity Model.
v3.3 · August 6, 2026
- The doctrine is republished at governedautonomy.org as the Governed Autonomy Doctrine. The substance is unchanged: the 5 Laws, the 5 Architectural Planes, the 6 Framework Pillars, the Threat Surface, and the Maturity Model carry over intact, with their anchors preserved. Only the name changes.
- Rationale, recorded plainly: across the industry, “harness” now denotes the enablement scaffolding around a model — the semantic inverse of this doctrine's subject — and the former name collided with several unrelated works. “Governed autonomy” is the state the doctrine exists to make reachable, and has been this doctrine's own language since the Maturity Model shipped.
- Publisher renamed accordingly: the Governed Autonomy Institute.
- Technical: llms.txt is now generated from the built site at every deploy (an llms-full.txt with full page text was added); structured data expanded (per-page TechArticle plus a DefinedTermSet for the canonical vocabulary); cache-control headers added so stale page variants cannot be served after a deploy.
v3.2 · July 31, 2026
- Opened the standards landscape section: mappings between the doctrine and published standards or government guidance on agentic AI.
- First mapping published: CISA's Careful Adoption of Agentic AI Services (30 April 2026). Three of the four named Threat Surface items have verbatim counterparts in its risk categories, arrived at independently.
- Recorded two acknowledged gaps in the doctrine relative to that guidance: Agent Identity & Lifecycle states the identity requirement without specifying mechanism, and Humans Retain the Right to Intervene asserts the right without defining the stakes tiers at which it is exercised. Both are carried as open revision items.
- Recognised “authority drift” as a secondary term in circulation for the failure mode Least Agency constrains, noted on the CISA mapping. Least Agency remains the canonical name.
v3.1 · June 10, 2026
- Added stable anchor identifiers to every Law, Plane, and Pillar so external documents can cite doctrine sections directly.
- Introduced doctrine versioning, this changelog, and structured publisher metadata (author: AI Harness Institute).
- Published the category comparison series: AI Harness vs Identity & Access Management, Security Monitoring, Orchestration, and AI Guardrails.
- Published llms.txt for language-model discoverability.
v3.0 · May 11–12, 2026
Major revision of the doctrine's structure and vocabulary.
- Least Agency introduced as a first-class principle, the third leg of the governance trilogy (Least Privilege → Least Trust → Least Agency) — and landed in Law 1.
- Law 4 renamed from "Agent-to-Agent Trust Must Be Explicit" to "Trust Does Not Travel," broadening its scope to every handoff type: delegation, orchestration, tool invocation, and subagent spawning.
- Architecture expanded from 4 to 5 Planes. Plane 5 (Multi-Agent Trust & Delegation) added as the architectural home of Law 4; Plane 1 renamed to Agent Identity & Lifecycle; Plane 4 broadened to Human Oversight, Audit & Traceability.
- Framework expanded to 6 Pillars. Mission Definition split out from Agent Identity; Multi-Agent Governance added.
- Threat Surface section added to the Declaration: prompt injection, intent hijacking, cascading failure, behavioral drift.
- Maturity Model published as a standalone page: Identified → Governed → Continuous.
- The Declaration's three non-negotiables sharpened; homepage redesigned.
v1.5 · April 8, 2026
- Published the declaration at AIHarnessDoctrine.org, presenting the third iteration of the Five Laws and establishing the basis for the architecture and framework.
v1.0 · March 18, 2026
- Published the first standalone webpage defining “AI Security” and the foundational requirements for enterprise AI—an equivalent evolution to what Zero Trust provided for cybersecurity. This consolidated the individual theses developed through earlier blog posts.
v0.5 · February 21, 2026
- Published “The Claw at the End of History,” responding to the open-source consumer AI boom accelerated by OpenClaw’s popularity.
v0.2 · January 2026
- Identified that best practices for securing AI cannot remain within traditional organizational boundaries. Personal and work AI use will inevitably overlap, requiring a more durable approach to governance.
v0.1 · November–December 2025
- Published blog posts addressing the good, the bad, and the ugly of AI’s emerging headlines and real-world use.
- These conversations led to a formal partnership of like-minded technologists working closely with federal and commercial enterprise IT leadership.
- The partnership recognized the need to document practical best practices for securing AI use within organizational boundaries.
Proposed revisions are evaluated against one test: does the change make autonomous AI agents more governable at runtime, across systems, at the level of behavior?