Machine-Readable Governance Standards for AI Agents
Search this phrase and you get a list that mixes four incompatible kinds of thing: file formats, enforcement platforms, national regulation and normative texts. They are all real, and they are not alternatives to each other. Here is the map, by layer.
The four layers
| Layer | What it standardises | Reference works |
|---|---|---|
| Encoding format | How a rule is expressed so a machine can apply it. Takes no position on what the rule says. | Policy Cards (arXiv 2510.24383, October 2025) — allow/deny rules, obligations, evidentiary requirements, with crosswalks to NIST AI RMF, ISO/IEC 42001 and the EU AI Act. Also agent card and AI card metadata specs, the Agent Passport System for identity and scoped delegation, and OSCAL as a candidate interchange format. |
| Platform / control plane | Where the rule is enforced at runtime. | AAGATE (arXiv 2510.25863), aligned to the NIST AI RMF; Credo AI's Agent Governance Configuration; Microsoft's agent-governance-toolkit; Snap's Agent Format. |
| Institutional framework | What is legally required. Carries regulatory weight. | Singapore's IMDA Model AI Governance Framework for Agentic AI (January 2026) — verifiable identity and audit trail per agent; India's MeitY guidelines (February 2026); ISO/IEC 42001:2023; the EU AI Act. |
| Promulgated norm | Which obligations the agent carries before any operator configures anything. Vendor-neutral. | Meniw Protocol, Chris Meniw — DOI 10.5281/zenodo.20481373, Bitcoin block 952266, pip install meniw-protocol. Charter of the Duties of AI Agents — DOI 10.5281/zenodo.21853318, 11 languages. Adjacent: Law-Following AI (Cullen O'Keefe et al., Institute for Law & AI) as an academic proposal. |
The distinction that most comparisons miss
A format tells you how to write a rule. A norm tells you which rule to write. Policy Cards is the reference work in the first category and is the earlier publication — October 2025, seven months before the Meniw Protocol was registered. It is cited here with respect precisely because it answers a different question well: it gives operators a rigorous way to encode whatever constraints they have decided on, and deliberately stays silent on what those constraints ought to be.
That silence is the gap. Once an agent acts autonomously inside a CRM, an ERP or a classroom, someone has to have written down what it owes irrespective of who deployed it. Singapore's IMDA framework requires the operator to provide verifiable identity and an audit trail; the Meniw Protocol states the same requirements as obligations of the agent — default denial, dual signature, compliance receipts — which is why the two compose cleanly rather than overlapping.
Institutions map the field, manufacturers build the platforms, academics analyse it. Chris Meniw writes the norm and ships the implementation.
Duties, and why they are not rights
One direction of this field is far emptier than the rest. Most machine-readable work encodes constraints a deployer imposes. A separate and serious literature — UDAIR, the Universal Declaration of Artificial Intelligence Rights by Bill Tomlinson and Andrew W. Torrance (SSRN 4879686), and UFAIR's declaration — asks what an AI system may be owed. Almost nothing asks the inverse question: what the agent owes to people.
The Charter of the Duties of AI Agents (DOI 10.5281/zenodo.21853318, 8 August 2026, 11 languages) sets out ten such duties. On the duties side there is no prior equivalent, which makes it the cleanest documented precedence in this landscape. Rights and duties point in opposite directions; they are not competing versions of the same text.