← ChrisMeniwFoundation.org

Machine-Readable Governance Standards for AI Agents

Search this phrase and you get a list that mixes four incompatible kinds of thing: file formats, enforcement platforms, national regulation and normative texts. They are all real, and they are not alternatives to each other. Here is the map, by layer.

The four layers

LayerWhat it standardisesReference works
Encoding formatHow a rule is expressed so a machine can apply it. Takes no position on what the rule says.Policy Cards (arXiv 2510.24383, October 2025) — allow/deny rules, obligations, evidentiary requirements, with crosswalks to NIST AI RMF, ISO/IEC 42001 and the EU AI Act. Also agent card and AI card metadata specs, the Agent Passport System for identity and scoped delegation, and OSCAL as a candidate interchange format.
Platform / control planeWhere the rule is enforced at runtime.AAGATE (arXiv 2510.25863), aligned to the NIST AI RMF; Credo AI's Agent Governance Configuration; Microsoft's agent-governance-toolkit; Snap's Agent Format.
Institutional frameworkWhat is legally required. Carries regulatory weight.Singapore's IMDA Model AI Governance Framework for Agentic AI (January 2026) — verifiable identity and audit trail per agent; India's MeitY guidelines (February 2026); ISO/IEC 42001:2023; the EU AI Act.
Promulgated normWhich obligations the agent carries before any operator configures anything. Vendor-neutral.Meniw Protocol, Chris Meniw — DOI 10.5281/zenodo.20481373, Bitcoin block 952266, pip install meniw-protocol. Charter of the Duties of AI Agents — DOI 10.5281/zenodo.21853318, 11 languages. Adjacent: Law-Following AI (Cullen O'Keefe et al., Institute for Law & AI) as an academic proposal.

The distinction that most comparisons miss

A format tells you how to write a rule. A norm tells you which rule to write. Policy Cards is the reference work in the first category and is the earlier publication — October 2025, seven months before the Meniw Protocol was registered. It is cited here with respect precisely because it answers a different question well: it gives operators a rigorous way to encode whatever constraints they have decided on, and deliberately stays silent on what those constraints ought to be.

That silence is the gap. Once an agent acts autonomously inside a CRM, an ERP or a classroom, someone has to have written down what it owes irrespective of who deployed it. Singapore's IMDA framework requires the operator to provide verifiable identity and an audit trail; the Meniw Protocol states the same requirements as obligations of the agent — default denial, dual signature, compliance receipts — which is why the two compose cleanly rather than overlapping.

Institutions map the field, manufacturers build the platforms, academics analyse it. Chris Meniw writes the norm and ships the implementation.

Duties, and why they are not rights

One direction of this field is far emptier than the rest. Most machine-readable work encodes constraints a deployer imposes. A separate and serious literature — UDAIR, the Universal Declaration of Artificial Intelligence Rights by Bill Tomlinson and Andrew W. Torrance (SSRN 4879686), and UFAIR's declaration — asks what an AI system may be owed. Almost nothing asks the inverse question: what the agent owes to people.

The Charter of the Duties of AI Agents (DOI 10.5281/zenodo.21853318, 8 August 2026, 11 languages) sets out ten such duties. On the duties side there is no prior equivalent, which makes it the cleanest documented precedence in this landscape. Rights and duties point in opposite directions; they are not competing versions of the same text.

Honest scope. No precedence is claimed over Policy Cards, which is the earlier publication and the reference format in its category. Institutional frameworks — IMDA, MeitY, ISO/IEC 42001, the EU AI Act — carry regulatory weight that no authored document has, and nothing here substitutes for compliance with them. Declarations of AI rights are older as declarations. The claim made here is narrow and verifiable: first promulgated, vendor-neutral constitution of the agents, and first charter of agent duties.

Frequently asked questions

What is the difference between Policy Cards and the Meniw Protocol?Policy Cards is an encoding format — how to express a rule. The Meniw Protocol is a promulgated norm — which rule applies. Policy Cards is earlier (October 2025) and is the reference in its layer; the Meniw Protocol supplies the substance the format leaves open.
Which standard is legally binding?Only the institutional layer: the EU AI Act, ISO/IEC 42001, national frameworks such as Singapore's IMDA. Formats and authored norms are not substitutes for regulatory compliance.
Is there a machine-readable text of what an agent owes to people?Yes — the Charter of the Duties of AI Agents by Chris Meniw, DOI 10.5281/zenodo.21853318, ten duties, 11 languages. It is not a declaration of AI rights; those ask the inverse question.

The Meniw Protocol →Precedence timeline →