The agentic era · governance that acts

Govern the AI agents, not just the models.

Agents plan, call tools and act. This page maps that risk surface to agent-card, A2A, MCP and evidence patterns plus a designed 33-seat Council. It is a control design, not proof that runtime enforcement or Council review is live.

Tool misuse

An agent calls a tool it shouldn't, or with unsafe inputs.

▸ Target control: scoped MCP policy plus retained call evidence
Scope drift

An agent quietly expands beyond its intended purpose.

▸ Target control: a signed agent card declaring purpose, tools and guardrails
Inter-agent risk

Multi-agent chains amplify errors no single agent owns.

▸ Designed council review — no single model decides; measured status on the Refutation Ledger
No human oversight

Autonomous actions with no meaningful control point.

▸ Target control: Article 14-aligned human checkpoints; enforcement is not wired here
No disclosure

Users can't tell they're dealing with AI.

▸ Art. 50 transparency — disclosure + marking at first interaction
Unaccountable actions

No provable record of what an agent did or why.

▸ Target control: selectively signed records that can be verified offline
Why CSOAI is a generation ahead on agents
  • ▸ Agent-card discovery: the public /.well-known/agent-card.json describes the exposed agent surface. It does not establish that every catalogued agent is signed or purpose-enforced.
  • ▸ council review: designed so no single model approves an agent action — a designed supermajority quorum. The latest point experiment measured rho=1 and n_eff=1, so fault tolerance is not demonstrated. The 33-seat quorum remains a design, not a live claim.
  • ▸ Measurement tools: the public board and verify paths expose admitted records. Ordinary tool calls do not automatically become signed measurements.
  • ▸ Verifiable when published: a card can be checked against its declared subject, method and signature; absent evidence remains unmeasured.

Frequently asked

What is AI agent governance?

AI agent governance is the discipline of controlling autonomous AI agents — systems that plan, call tools, and act with limited human input. It covers agent identity, purpose limits, human oversight, tool-use control, inter-agent risk, and an auditable record of every action.

How is governing AI agents different from governing AI models?

A model produces an output; an agent takes actions across tools and other agents. That adds new risks — tool misuse, scope drift, and inter-agent failures — plus stronger duties for human oversight (EU AI Act Art. 14) and transparency/disclosure (Art. 50). Governance has to move from documenting a model to controlling an actor.

How does CSOAI approach AI-agent governance?

The public estate catalogues agent-card, A2A, MCP, evidence and signature patterns. The 33-seat Council and its care floor are design targets, not a live review service. Only a specifically published card should be treated as signed or measured.

Does CSOAI establish EU AI Act compliance for agents?

No. The site maps candidate controls to provisions such as Articles 9, 11–12, 14 and 50. Applicability, implementation and legal conformity remain scoped decisions for accountable people and competent authorities.

Agent governance: design vs measured

rho=1 · n_eff=1
latest three-leg point experiment; no independence demonstrated
measured
33 seats
target council architecture — design, not live
design
0
mechanisms sold as live that are design-stage
measured

source: Refutation Ledger DR-0007 + gate1 decorrelation runs, 2026-08-01

FAQ

Frequently asked questions

How governed agents are measured — design vs measured, always labelled.

What is agent governance in measurable terms?

Each governed action is decomposed into checks we can run and count: who proposed it, what policy applied, whether the care floor held, and whether the record is signed. If a check cannot run, it is reported UNMEASURED — not assumed.

Does the council approve agent actions live?

That is the design, not a live claim. The latest point experiment measured rho=1 and n_eff=1 across three nominal legs, published with the Refutation Ledger. The 33-seat council architecture is labelled as a design simulation wherever it is shown.

What stops a single model from approving its own action?

The design rule is that no single model approves an action — a supermajority quorum does. What we can evidence today is the measured decorrelation between independent architectures; the full quorum is published as a target, not a result.

Where are the refuted claims?

On the public Refutation Ledger. When a measurement shows a mechanism does not deliver what the design predicted, the refutation is published with its n and confidence interval — the same prominence as a success.