02 · The Agent Control Standard
The ABP describes and records. ACS is a wire through which a control can act.
ACS joined the OWASP GenAI Security Project on 1 September 2026. Its README calls it a wire specification that lets a separate Guardian Agent inspect what an agent is about to do and permit, deny or modify it. Read on 8 October: version 0.1.3 (changelog dated 9 September 2026), Apache-2.0 for code and schemas, CC BY-SA 4.0 for prose. The brief of 8 October asked for an overlap matrix with ACS and the Agentic Top 10; this is the first reading of it, from public pages, for the maintainers to correct.
| Agent Behaviour Policies (proposed) | Agent Control Standard | Top 10 for Agentic Applications |
| Purpose | Write down what one agent in one deployment can do, what it was authorised to do, the gap, and what stands in the way | A runtime protocol through which a separate guardian can allow, deny, modify, ask or defer an agent’s next action | A list of the ten risk categories for agentic applications, December 2025 |
| Artefacts | Grant, mandate, delta and barrier records; a 23-primitive grammar; template ABPs; a build that derives the delta | A handshake, a JSON-RPC envelope, a minimum hook set, five dispositions; trace, inspect (an Agent Bill of Materials), provenance, crypto and audit profiles; a reference implementation | A document, ASI01 to ASI10, CC BY-SA 4.0 |
| Enforces | Nothing. It says what does | Yes: it is the channel a control acts through | No |
| Assesses | Yes: which capabilities are outside the mandate, and which of those nothing bounds | Not its stated purpose; the Agent Bill of Materials lists what the agent has | It informs an assessment |
| Where it lives | Proposed; not yet at OWASP | Inside the GenAI Security Project, under its governance | Inside the GenAI Security Project |
| How they would meet | An ABP row whose barrier is an ACS guardian names the hook and the disposition: before send.message.world, toolCallRequest → ask. ACS’s Agent Bill of Materials and an ABP’s grant describe overlapping ground; whether one can be derived from the other is the first question to put to the maintainers. The Agentic Top 10 supplies the risk each row is evidence about. |
What we do not say. No ABP–ACS integration exists, and nothing here claims interoperability. The initiation brief recorded observations about ACS’s reference implementation as it was reviewed; they are time-sensitive, they have not been re-checked at a commit, and we do not repeat them. Any statement about ACS on this site will name the version and commit it was read at.
The experiment we propose, on a system we are entitled to run and on nobody else’s: one synthetic agent deployment, one restriction (a person approves before any external email), ACS as the enforcement. Record the ABP row, the evidence of the capability, the hook and disposition, the failure behaviour, and four tests: it allows what it should, it stops what it should, a known bypass, and an outage of the guardian. Then the paths it does not cover. No conformance is claimed without a defined profile and results.
The note to the maintainers (M03, drafted, not sent): We are proposing an OWASP project for Agent Behaviour Policies, a per-deployment record of what an agent can do, what it was authorised to do, and what stands in the way. ACS looks like the natural runtime barrier for many of its rows. Before we describe that relationship anywhere, could you tell us whether we have read ACS correctly, whether the Agent Bill of Materials could carry or derive an ABP grant, and whether you would review a small experiment that uses ACS to enforce one ABP restriction?
A disclosure for the review. ACS’s creators are named in its governance file; one of them also sits on OWASP’s Project Committee, which reviews new projects. That is a reason to raise the overlap ourselves, early, and in the application.