Journal

· evidence

A control hook needs a guardian outside the agent

A guardian makes a hook a control through an authenticated channel and an audit record.

A mechanical agent stops as a separate guardian selects a response and prints an audit record.

A hook is where a platform stops an agent run and asks an outside process what to do. It becomes a control when that process answers through an unforgeable channel and leaves an uneditable record.

The OWASP GenAI Security Project announced the Agent Control Standard on September 1, 2026. OWASP says it defines platform middleware hooks for portable safety policies enforced across agent frameworks at runtime.

The guardian answers

OWASP defines the draft as a wire-format specification for decisions from a separate Guardian Agent.

That guardian can permit, deny, or modify an agent action in real time. OWASP requires an authenticated channel and a verifiable audit trail.

OWASP lists sixteen lifecycle hooks, from sessionStart through subagentStop, and five dispositions. Those answers are allow, deny, modify, ask, and defer.

Profiles define conformance

OWASP makes version 0.1 conformance tiered. Its profiles are acs-core, acs-trace, acs-inspect, acs-inspect-dynamic, acs-provenance, acs-crypto, and acs-audit.

The trace profile emits OpenTelemetry or OCSF records for every supported step. OpenTelemetry and OCSF are open formats for trace records and security-event records.

The inspect profile emits an agent bill of materials once per session. An agent bill of materials lists the components an agent runs with. Its guardian serializes the list in CycloneDX 1.6, SPDX 3.0, or SWID form.

Provenance is the record of where content came from.

Current text puts the append-only context chain, published chain-head hash, and a record for every fail-open proceed in core. The audit profile adds a hash that commits each request’s content to that chain.

Core alone requires no trace events, component inventory, or audit-profile request hash. A buyer should ask which profile a conformance claim names.

A public preview is not adoption

OWASP labels version 0.1 a public preview. The repository’s version.txt reads 0.1.1.

The repository names no implementing platform.

The project defers streaming, multi-tenant isolation, and A2A wrapping to version 0.2. OWASP applies Apache 2.0 to code and CC BY-SA 4.0 to documents.

This remains a public preview from one OWASP project, not an adopted standard. OWASP is neither a Muniment customer nor an endorser.

Sources

  1. OWASP GenAI Security Project: Agent Control Standard (ACS) genai.owasp.org
  2. GitHub: GenAI-Security-Project/agent-control-standard github.com

Continue reading

All publications

Join the waitlist

Get desktop release updates.

We will email you about desktop releases and new features. muniment is a desktop workspace for your models, tools, and files.