Governed Autonomy and the Standards Landscape

Standards bodies are converging on agentic risk faster than they are converging on agentic architecture. These mappings show where each document lands.

The category comparisons ask how Governed Autonomy relates to the existing control stack — IAM, security monitoring, orchestration, guardrails. This section asks a different question: how does the doctrine relate to the published standards and guidance that address the same problem?

The answer is usually the same shape. Standards work is strongest at the control layer — what to require, what to prohibit, what to log. It has been weakest at the architectural layer — where each control lives, which must hold simultaneously, and how far an organisation can safely extend autonomy today. That is changing: the AARM and SCIM mappings below both draw architectural boundaries, and this section records where they now reach further than a control catalogue. Each mapping below is written to be useful in both directions: what the standard supplies that the doctrine does not, and what the doctrine supplies that the standard does not.


CISA — Careful Adoption of Agentic AI Services

The first multi-nation government guidance written specifically for agentic AI, published 30 April 2026 by six national cyber agencies. Its five risk categories independently reproduce three of the four threats this doctrine names. The most prescriptive control-level document published to date — and the clearest illustration of what a control catalogue cannot do on its own.


OWASP — Top 10 for Agentic Applications 2026

The broadest community statement on agentic risk: ten ranked failure modes from more than one hundred contributors. Two of this doctrine's four named threats appear in nearly its own words, independently. The mapping also records where the two documents share an open edge, and treats the Top 10's Least-Agency advice as the convergent twin of this doctrine's law.


NIST — AI Risk Management Framework

The canonical enterprise vocabulary for AI risk, written before agents could act. The mapping covers the four functions, the Generative AI Profile, and the interval that matters: NIST's agent-specific overlays remain unpublished, and enterprises deploying agents today are working ahead of their own risk framework.


AARM — Autonomous Action Runtime Management v1.0

A Cloud Security Alliance working group specification with a DOI: nine RFC 2119 requirements for a control plane that intercepts every agent action before it executes, against a threat model of eleven classes. The most rigorous runtime specification published to date, and the closest convergence with this doctrine's Threat Surface — all four threats appear. The mapping records what a conformant control plane still cannot answer: what would make a particular decision correct.


IETF — SCIM Agent Governance Extension

An early individual Internet-Draft giving provisioned agent identities a lifecycle state model grounded in ISO/IEC 24760-1 and an autonomy classification. The only document mapped here that is still open for comment. Its exclusions carry the finding: it rules action-level authorization out of provisioning, and defers delegated authority entirely on the grounds that the cross-protocol semantics for it do not yet exist.


DEMM-Bench — Governance-Evidence Sufficiency

A benchmark that asks whether agent-runtime records are sufficient to reconstruct a decision, rather than whether they exist. It finds that trace-present and schema-present baselines overclaim on 75% of cases, and names the failure mode the container fallacy. The mapping records the distinction that matters most here: retrospective evidence sufficiency is not a conformance verdict, and a system can score perfectly while making consistently wrong decisions, perfectly recorded.


For a survey of the wider landscape, including artifacts that do not yet have a full mapping page, see the Standards Observatory.


Further mappings are planned against the EU AI Act and ISO/IEC 42001, each following the same structure: what the document establishes, where the two converge, where each is thinner, and the gap that survives compliance. When NIST's single-agent and multi-agent control overlays publish, they will be mapped criterion by criterion.