PASSPORTS FOR AGENTS · A SERIES ON IDENTITY AND CONTROL FOR AI AGENTS · EPISODE 5 OF 6
T123456

The Rulebooks

The EU AI Act, ADG, ISO 42001, OWASP and the rest: different books, one demand.

In this episode

Download the rulebooks scorecard
Transcript

The rulebooks

Passports for Agents. A series on identity and control for AI agents. Episode five: The Rulebooks. Last time, six stamps: what travelling without papers has already cost. This time, what the rulebooks now demand, and by when. Regulators did not wait.

The EU AI Act

Start with the law. The EU AI Act has been in force since August 2024. Its transparency duties apply since August 2026. Its high-risk obligations were deferred this summer to December 2027, and they are specific: automatic logging and traceability of every decision, human oversight with the power to intervene and to stop, and the deployer, not only the vendor, on the hook, with logs kept for at least six months. Fines run to seven percent of global turnover.

ADG: Adopt, Defend, Govern

Then the framework built by practitioners. In May 2026, EC-Council published ADG: Adopt, Defend, Govern. Free and open, written with an advisory board from banks, insurers and technology firms. Nine governance surfaces, where attackers act and engineers instrument: identity, tools, and telemetry among them. Twelve minimum controls, each with a named piece of evidence an auditor can hold, starting with an inventory that names an owner for every system. Three autonomy tiers, from a human approving every output to an agent running on its own within limits. And a hardening overlay for agents that asks for authority bounds, kill switches, and forensic replay.

The security community

The security community has been more specific still. OWASP's top ten for agentic applications, published in December 2025, lists identity and privilege abuse, tool misuse, insecure agent to agent communication, and rogue agents. The Cloud Security Alliance says plainly that every agent needs its own identity, not a shared key. And the identity standards themselves, NIST's digital identity guidelines and Europe's eIDAS wallet, define what a credential must be: issued by a verifiable issuer, bound to a key its holder controls, revocable, and able to disclose only what a check needs.

Data, finance, and Singapore

Data protection and financial regulation were already there. GDPR in Europe and the DPDP Act in India require a record of who processed what, and why. DORA and NIS2 require tamper-resistant logs and control over third-party access. Singapore published the first governance framework written for agentic AI, in January 2026: bound the risks up front, make humans meaningfully accountable, put technical controls in place. And in July 2026, after the Hugging Face intrusion, a bill was introduced in the United States to require a kill switch for AI systems. It has not passed. It tells you where the wind is blowing.

One demand

Different books, one demand. Name it: an inventory with an owner. Bound it: a purpose, a limit, a time. Prove it: a record nobody can quietly edit. And be able to stop it. Every one of those is a document from episode one, or a check from episode two.

The fact, and the ask

Now the fact. The AI Act requires deployers to keep the logs their agents generate for at least six months. Ask your team today how long your agent logs are kept, and whether anyone could show they are complete. Next time: the ledger. Every document, mapped to the product, with the honest score against each of these rulebooks. Until then, download the rulebooks scorecard: every framework, what it asks, and a blank sheet to score yourself.

The product view: the compliance mapping

Watched elsewhere? Mark as watched

Captions and a full transcript are provided. The narration describes what is on screen.