# A control hook needs a guardian outside the agent

[Journal](/journal/)

September 5, 2026 · [evidence](/journal/#evidence)



A guardian makes a hook a control through an authenticated channel and an audit record.

![A mechanical agent stops as a separate guardian selects a response and prints an audit record.](/_astro/a-control-hook-needs-a-guardian-outside-the-agent.DTn5HMii_eEjmW.avif)

A hook is where a platform stops an agent run and asks an outside process what to do. It becomes a control when that process answers through an unforgeable channel and leaves an uneditable record.

The OWASP GenAI Security Project [announced the Agent Control Standard on September 1, 2026](https://genai.owasp.org/resource/agent-control-standard-acs/). OWASP says it [defines platform middleware hooks for portable safety policies enforced across agent frameworks at runtime](https://genai.owasp.org/resource/agent-control-standard-acs/).

## The guardian answers

OWASP defines the draft as [a wire-format specification for decisions from a separate Guardian Agent](https://github.com/GenAI-Security-Project/agent-control-standard).

That guardian can [permit, deny, or modify an agent action in real time](https://github.com/GenAI-Security-Project/agent-control-standard). OWASP requires [an authenticated channel and a verifiable audit trail](https://github.com/GenAI-Security-Project/agent-control-standard).

OWASP lists [sixteen lifecycle hooks, from `sessionStart` through `subagentStop`, and five dispositions](https://github.com/GenAI-Security-Project/agent-control-standard). Those answers are `allow`, `deny`, `modify`, `ask`, and `defer`.

## Profiles define conformance

OWASP makes [version 0.1 conformance tiered](https://github.com/GenAI-Security-Project/agent-control-standard). Its profiles are [`acs-core`, `acs-trace`, `acs-inspect`, `acs-inspect-dynamic`, `acs-provenance`, `acs-crypto`, and `acs-audit`](https://github.com/GenAI-Security-Project/agent-control-standard).

The trace profile [emits OpenTelemetry or OCSF records for every supported step](https://github.com/GenAI-Security-Project/agent-control-standard). OpenTelemetry and OCSF are open formats for trace records and security-event records.

The inspect profile [emits an agent bill of materials once per session](https://github.com/GenAI-Security-Project/agent-control-standard). An agent bill of materials lists the components an agent runs with. Its guardian serializes the list in [CycloneDX 1.6, SPDX 3.0, or SWID form](https://github.com/GenAI-Security-Project/agent-control-standard).

Provenance is the record of where content came from.

Current text puts [the append-only context chain, published chain-head hash, and a record for every fail-open proceed in core](https://github.com/GenAI-Security-Project/agent-control-standard). The audit profile adds a hash that commits each request’s content to that chain.

Core alone requires no trace events, component inventory, or audit-profile request hash. A buyer should ask which profile a conformance claim names.

## A public preview is not adoption

OWASP labels [version 0.1 a public preview](https://github.com/GenAI-Security-Project/agent-control-standard). The repository’s [`version.txt` reads 0.1.1](https://github.com/GenAI-Security-Project/agent-control-standard).

The repository [names no implementing platform](https://github.com/GenAI-Security-Project/agent-control-standard).

The project defers [streaming, multi-tenant isolation, and A2A wrapping to version 0.2](https://github.com/GenAI-Security-Project/agent-control-standard). OWASP applies [Apache 2.0 to code and CC BY-SA 4.0 to documents](https://github.com/GenAI-Security-Project/agent-control-standard).

This remains a public preview from one OWASP project, not an adopted standard. OWASP is neither a Muniment customer nor an endorser.

## Sources

1.  [OWASP GenAI Security Project: Agent Control Standard (ACS)](https://genai.owasp.org/resource/agent-control-standard-acs/) genai.owasp.org
2.  [GitHub: GenAI-Security-Project/agent-control-standard](https://github.com/GenAI-Security-Project/agent-control-standard) github.com
