# Governed Autonomy Doctrine > The architectural doctrine for runtime governance of autonomous AI agents across enterprise systems. Authorize the Agent. Govern the Behavior. Published by the Governed Autonomy Institute. Current version: v3.6. Formerly published as the AI Harness Doctrine; renamed August 2026. Governed Autonomy defines an enterprise control discipline: governing autonomous AI agents as first-class identities through continuous runtime enforcement, across all systems they touch, at the level of behavior — not just access. Core vocabulary: the 5 Laws, the 5 Architectural Planes, the 6 Framework Pillars, Least Agency, the Threat Surface (prompt injection, intent hijacking, cascading failure, behavioral drift), a three-level Maturity Model, and a proposed testable Conformance Layer (RFC 001). ## The Doctrine - [Governed Autonomy Doctrine](https://governedautonomy.org/): The doctrine for runtime governance of autonomous AI agents across enterprise systems. - [What Is Governed Autonomy?](https://governedautonomy.org/what-is-governed-autonomy/): Governed autonomy is the operating state in which autonomous AI agents act freely inside bounds that are explicitly defined, continuously enforced at runtime, and revocable by humans. The canonical definition, and the standard that makes it testable. - [The 5 Laws of Governed Autonomy](https://governedautonomy.org/laws/): The foundational, non-negotiable principles that define Governed Autonomy governance. - [Governed Autonomy Architecture](https://governedautonomy.org/architecture/): The runtime control and enforcement architecture for governing autonomous AI agents across enterprise systems. - [Governed Autonomy Framework](https://governedautonomy.org/framework/): The structured implementation methodology for governing autonomous AI agents through mission-scoped identity, policy, and runtime behavioral control. - [The Zero Trust Parallel](https://governedautonomy.org/zero-trust/): Governed Autonomy is to autonomous AI what Zero Trust was to network security. - [Governed Autonomy Maturity Model](https://governedautonomy.org/maturity/): Where is your organization on the path to governed autonomy? ## Comparisons - [Governed Autonomy vs the Existing Stack](https://governedautonomy.org/vs/): How Governed Autonomy relates to IAM, security monitoring, orchestration, and AI guardrails — what each does well, what none can do alone, and where the gap is. - [Governed Autonomy vs AI Guardrails](https://governedautonomy.org/vs/guardrails/): Guardrails constrain model inputs and outputs. They do not govern what an autonomous agent does across systems. The most common category confusion in agentic security. - [Governed Autonomy vs Identity & Access Management](https://governedautonomy.org/vs/iam/): IAM grants and governs access. It cannot govern what an autonomous AI agent does after access is granted. Where identity stops and behavioral governance begins. - [Governed Autonomy vs Orchestration & Workflow Automation](https://governedautonomy.org/vs/orchestration/): Orchestration executes predefined workflows. Autonomous agents generate their own execution plans. Why workflow control cannot constrain autonomous decision-making. - [Governed Autonomy vs Security Monitoring (SIEM, SOAR & Detection)](https://governedautonomy.org/vs/siem/): Detection and response see violations after they occur. Autonomous agents act at machine speed. Why monitoring is necessary but cannot govern agent behavior at runtime. ## Standards Mappings - [Governed Autonomy and the Standards Landscape](https://governedautonomy.org/standards/): How Governed Autonomy relates to the published standards and government guidance for agentic AI — what each establishes, where each stops, and how the doctrine's architecture organises them. - [Governed Autonomy and AARM (Autonomous Action Runtime Management)](https://governedautonomy.org/standards/aarm/): A Cloud Security Alliance working group published nine RFC 2119 requirements for intercepting every agent action before it executes. How AARM v1.0 maps to the Governed Autonomy Laws, Planes and Threat Surface — and the one question a control plane cannot answer about itself. - [Governed Autonomy and CISA's Careful Adoption of Agentic AI Services](https://governedautonomy.org/standards/cisa-agentic-ai/): Six national cyber agencies published the first government guidance written specifically for agentic AI. How its five risk categories map to the Governed Autonomy Laws, Planes and Threat Surface — and where each layer is thinner than the other. - [Governed Autonomy and DEMM-Bench (Governance-Evidence Sufficiency)](https://governedautonomy.org/standards/demm-bench/): A benchmark that measures whether agent-runtime records are sufficient to reconstruct a decision, not merely present. How DEMM-Bench maps to Plane 4 and the Human Oversight Law, and why retrospective evidence sufficiency is not the same thing as a conformance verdict. - [Governed Autonomy and the NIST AI Risk Management Framework](https://governedautonomy.org/standards/nist-ai-rmf/): The AI RMF is the canonical enterprise vocabulary for AI risk. It predates autonomous agents, and NIST's agent-specific overlays remain unpublished. How the four functions map to the doctrine — and what fills the interval. - [Governed Autonomy and the OWASP Top 10 for Agentic Applications](https://governedautonomy.org/standards/owasp-agentic-top10/): More than one hundred experts ranked what goes wrong with autonomous agents. How the ten agentic risks map to the Governed Autonomy Laws, Planes, and Threat Surface — and where each layer is thinner than the other. - [Governed Autonomy and the IETF SCIM Agent Governance Extension](https://governedautonomy.org/standards/scim-agent-governance/): An IETF Internet-Draft gives provisioned agent identities a lifecycle state model and an autonomy classification — then rules authorization out of scope and defers delegated authority entirely. How it maps to the Governed Autonomy Planes, and why its exclusions matter more than its inclusions. ## Requests for Comment - [Requests for Comment](https://governedautonomy.org/rfc/): Proposed revisions to the Governed Autonomy Doctrine, published before they are locked. Open drafts, stated review windows, and version-lock dates. - [RFC 001](https://governedautonomy.org/rfc/v4-conformance-layer/): A proposed fourth layer for the Governed Autonomy Doctrine: twenty-nine testable, mechanism-agnostic Conformance Criteria across the five Architectural Planes. Revision 2 corrects three internal contradictions found in review. Open for comment through October 31, 2026. ## Meta - [About](https://governedautonomy.org/about/): The Governed Autonomy Institute is the publishing entity of the Governed Autonomy Doctrine. What it is, how the doctrine is developed and reviewed, and what editorial independence means here — stated plainly. - [How to Cite](https://governedautonomy.org/cite/): Citation formats for the Governed Autonomy Doctrine: version-pinned references, stable section anchors for Laws, Planes, and Pillars, and continuity guidance for works citing the doctrine under its former name. - [Changelog](https://governedautonomy.org/changelog/): Version history of the Governed Autonomy Doctrine. The doctrine is versioned, dated, and revised in the open. ## Other - [Agentic AI vs Generative AI](https://governedautonomy.org/agentic-ai-vs-generative-ai/): Agentic AI autonomously manages multi-step workflows; generative AI produces content on demand. The differences in autonomy, workflows, infrastructure, and governance — and why the governance requirements diverge sharply. - [Glossary](https://governedautonomy.org/glossary/): Canonical definitions for the vocabulary of governed autonomy and the agentic AI field — agents, identity, runtime enforcement, threat surface, and the doctrine's own terms. - [Standards Observatory](https://governedautonomy.org/observatory/): A dated, sourced survey of every published specification, standard, benchmark and government guidance document for governing autonomous AI agents: what each establishes, what it leaves open, and where the field currently agrees. - [Doctrine Status: What Is Settled and What Is Moving](https://governedautonomy.org/status/): A dated status map of the Governed Autonomy Doctrine's core constructs, from those unchanged since first publication to a proposal still under review. Every placement cites the changelog entry, standards page or RFC that justifies it. ## Full text - [llms-full.txt](https://governedautonomy.org/llms-full.txt): complete text of every page in one file