RiskMandate v1.38.0
OWASP · Agent Behaviour Policies

We are proposing the Agent Behaviour Policy to OWASP.

On 8 October 2026 RiskMandate’s two founders decided to propose the Agent Behaviour Policy (ABP) to OWASP as an open project, OWASP Agent Behaviour Policies, with RiskMandate as its sponsor. The method is already published under open licences, so the move is mostly about giving it a home that is not ours. This section is where the move is kept: the charter, the line between the company and the project, what moves, what OWASP projects it works with, the application, and a tracker of every step, submission and answer, in public, as it happens.

As at: 8 October 2026. Where it stands: preparing the application; nothing sent to OWASP

What this is not, yet: an OWASP project. OWASP has not received the application, reviewed it or accepted it. Nothing here is endorsed by OWASP, and no page should be read as saying so.

01 · Why OWASP

A description of what an agent can do should not belong to the company that sells it.

An ABP is a written description, for one agent in one deployment, of everything it can do (the grant), what it was authorised to do (the mandate), the gap between the two (the delta), and what actually stands in the way (the barrier). It carries no score. RiskMandate built it, published it at abp.sgit.ai under CC BY 4.0 and the code under Apache-2.0, and sells services on it. That is a reasonable way to start something and a poor way to make it a shared language: a format the buyer, the vendor, the reviewer and the insurer all write in has to be one none of them owns.

OWASP is where the application-security community already keeps shared language of that kind: the Top 10s, ASVS, SAMM, CycloneDX, and now, in the GenAI Security Project, the Agentic Top 10 and the Agent Control Standard. Many OWASP projects are exactly what a behaviour policy records as a barrier: something enforced above the agent, out of its reach. A project that describes agents in a grammar those controls can be mapped onto adds to them rather than competing with them. And it gets what one company cannot give it: people outside RiskMandate who will try to break the model.

In a way it’s a simple move because everything is already published and they have Creative Commons, right? You know, the code is freely available. But I think this is going to help a lot the project and it’s also, I think, it’s a great OWASP project from a community point of view.Dinis Cruz, voice note, 8 October 2026 (transcribed; D30 in the brief register)

02 · Where it stands

Five gates. Nothing leaves before the gate before it.

The gates come from the initiation brief the leads commissioned on 8 October (D31). An instruction to prepare the move is not permission to make it: every external step, an email, a form, a repository, waits on the lead’s approval of the exact content and recipient.

G0

Scope

The objectives, and what agents may read and draft.

Who clears it: Dinis Cruz

Done
G1

Contribution rights

The asset manifest: every row's rights checked, nothing confidential left.

Who clears it: The leads, and RiskMandate as a company

To do
G2

Technical scope

Terminology, boundaries and limitations accepted.

Who clears it: The leads, and a reviewer outside RiskMandate

To do
G3

Outreach and application

The exact recipients, the email text and every field of the application.

Who clears it: The leads

Waiting
G4

Publication and migration

The repository target, the licences and the contribution set.

Who clears it: The leads, after OWASP accepts

To do
Done

4 of 25 steps

Happened, and the record says where.

Doing

0 of 25 steps

Somebody is on it now.

To do

16 of 25 steps

Planned; nobody has started.

Waiting

4 of 25 steps

Ready, and waiting on a named person's approval or answer.

The full list, with owners, dates and notes, is on the tracker.

04 · In one table

The proposal, as it stands today.

NameOWASP Agent Behaviour Policies (ABP)
One lineAn open, vendor-neutral method and machine-readable format for writing down what an AI agent in a given deployment can do, what it was authorised to do, the gap, and what stands in the way
Proposed leadersDinis Cruz and Nimay Parekh, as people and not as RiskMandate; a third from outside RiskMandate sought
SponsorRiskMandate, through the OWASP Foundation, on the same terms open to anyone
Type and levelDocumentation, with a reference tool; Builder; Incubator. OWASP’s to confirm
HomeA standalone OWASP project, or an initiative inside the GenAI Security Project: both set out
LicencesCC BY 4.0 for documents, Apache-2.0 for code, as published today; checked per asset before transfer
Starts fromThe abp.sgit.ai model v0.12.1, its documentation pack, sixteen template ABPs and the delta build
NeverA score, a mark, an insurance product, a hosted service, or a claim that a document enforces anything
Start here

The charter, then the line.

What the project is for and what it will not claim, then how RiskMandate sits beside it. Argue with either; that is what they are for.