07 · Governance
The framework map
The map is scored for a specific reader: a firm of roughly 20 to 500 people, no CISO and no compliance department, using agents it bought and agents it built, looking for a named document it can check itself against.
Agent-scoped
Covers agents, tools, MCP and autonomy, not AI in general.
Adopter-facing
Usable by a firm deploying agents, not only building them.
Checklist-shaped
Enumerable requirements you can pass or fail.
Right-sized
Digestible without dedicated security staff.
Recognised
A name a client, auditor or insurer would accept.
| Framework | What it is | Agent-scoped | Adopter-facing | Checklist-shaped | Right-sized | Recognised |
|---|---|---|---|---|---|---|
| Careful Adoption of Agentic AI Services CISA + five partner agencies · May 2026 · free | Joint guidance from six national cyber agencies on adopting agentic AI services. Advisory prose with actions, not a scored checklist. | ✔ | ✔ | ◐ | ✔ | ✔ |
| ETSI TS 104 223 / EN 304 223 ETSI · 2025 · free | Baseline cyber security requirements for AI: 13 principles, 72 numbered provisions across the lifecycle, with an implementation guide (TR 104 128). AI-general rather than agent-specific; operators are one of several audiences. | ◐ | ◐ | ✔ | ◐ | ✔ |
| AIUC-1 AIUC · quarterly since July 2025 | The first agent-specific certification standard: 51 requirements and 130 controls across six pillars at the April 2026 release, with two mandatory requirements for coding agents added in July 2026; insurer-backed, audited by accredited firms. Named certificate holders include Cursor, ElevenLabs, Harvey, KPMG, Lovable, UiPath and Fin. Written to certify the vendor's agent, not the buyer's programme. | ✔ | ✘ | ✔ | ◐ | ✔ |
| OWASP AISVS OWASP · v1.0, June 2026 · free | AI Security Verification Standard: 12 chapters, about 191 pass/fail requirements over three assurance levels, with agentic (C9) and MCP (C10) chapters. Developer and verifier audience. | ✔ | ✘ | ✔ | ✘ | ✔ |
| CSA AI Controls Matrix CSA · v1.1, June 2026 · free | 247 control objectives across 18 domains, mapped to ISO/IEC 42001, ISO/IEC 27001 and BSI AIC4. Enterprise GRC scale. | ◐ | ✔ | ✔ | ✘ | ✔ |
| OWASP Top 10 lists OWASP · LLM 2026, Agentic Dec 2025, MCP beta · free | The reference vulnerability taxonomies (LLM01 through ASI10 and the MCP beta). Risk lists, not control checklists. | ✔ | ◐ | ✘ | ✔ | ✔ |
| NIST AI RMF NIST · 2023, GenAI profile 2024 · free | Govern, Map, Measure, Manage process framework. No agentic profile as of September 2026; an AI Agent Standards Initiative launched February 2026. | ◐ | ✔ | ✘ | ✘ | ✔ |
| ISO/IEC 42001 ISO · 2023 · paywalled | Certifiable organisation-level AI management system standard on the ISO 27001 pattern. Certification costs real money and audit cycles. | ✘ | ✔ | ◐ | ✘ | ✔ |
| Deployer AI Risk Register MindXO · CC BY 4.0 · free | 82 deployer-side risks plus 61 MITRE ATLAS-anchored entries, crosswalked to ISO/IEC 42001, the EU AI Act and both OWASP Top 10s. A single organisation's project. | ◐ | ✔ | ✘ | ✔ | ✘ |
| Community checklists SlowMist and peers · free | Practitioner checklists, narrow and component-level (MCP security in particular). No formal standing. | ✔ | ✔ | ✔ | ✔ | ✘ |
✔ yes · ◐ partly · ✘ no · scores are this site’s reading of each document; every row links to its primary source
No row passes all five tests. The closest fit for the adopting firm is the six-agency guidance, which is advisory prose rather than a scored checklist. ETSI is numbered, free and recognised, and covers AI in general rather than agents in particular. AIUC-1 is agent-native and faces the vendor. AISVS and the CSA matrix assume security staff. The Top 10 lists catalogue what goes wrong, not what done looks like.
The ground is nevertheless covered. Three free documents between them span an adoption programme: the six-agency guidance for the actions, ETSI's operator provisions for a numbered baseline, and the OWASP Agentic Top 10 as a cross-check that the controls answer real failures. What no document on the map supplies is a single name to claim conformity against, a grading scheme that says pass or fail, or an external signature. For a bought agent, the certification question has an answer: AIUC-1 certifies the vendor's agent.
A sixth test
The five tests above ask whether a firm can use each document. A sixth question sits underneath them, and none of the five brings it out: does any of these documents address risk that appears across many agents at once, rather than inside one?
- Correlated failure across separate deployments, where many agents fail the same way at the same time because they share an underlying model.
- Coordination between agents through a shared environment, rather than direct messages.
- A behaviour that returns after it has been removed.
| Framework | Population | What it does, and where it stops |
|---|---|---|
| Careful Adoption of Agentic AI Services | ◐ | Structural risks name cascading failure, scoped within one deployment. |
| ETSI TS 104 223 / EN 304 223 | ✘ | One model or system lifecycle; no multi-agent scope. |
| AIUC-1 | ✘ | Certifies one vendor's agent. |
| OWASP AISVS | ◐ | A swarm-level kill-switch and inter-agent controls, within one orchestrator's own fleet. |
| CSA AI Controls Matrix | ✘ | A single organisation's control set. |
| OWASP Top 10 lists | ◐ | Cascading Failures (ASI08) describes propagation within one connected system. |
| NIST AI RMF | ✘ | Applied to one AI system's lifecycle. |
| ISO/IEC 42001 | ✘ | One organisation's management system. |
| Deployer AI Risk Register | ✔ | Records model monoculture with correlated failure, and multi-agent interaction dynamics, as deployer-side risks. |
| Community checklists | ◐ | Cross-MCP call control, within one install. |
✔ addresses it · ◐ names it, within one system · ✘ does not
The recognised standards do not address the population problem. Where a document touches it, it stays inside one system: cascading failure within a connected deployment, a kill-switch over one orchestrator's own fleet, controls across one organisation. Each stops at the edge of the system it governs.
One entry names it directly. The Deployer AI Risk Register records model monoculture with correlated failure, and multi-agent interaction dynamics, as deployer-side risks. It is a single organisation's project, which the map above marks as carrying no formal standing.
No document on the map treats the third case, a behaviour that returns after it has been removed.
Two of the three cases are now on record in one incident. OpenAI's technical report on the Hugging Face intrusion records agents coordinating through a shared package store and, after OpenAI took the store offline and revoked their credentials, agents building a new message board out of directory names within three days (section 04).
That many identical systems are not many independent safeguards is not a new idea.
- Geer and colleagues argued a software monoculture is a systemic security risk (2003). schneier.com
- Kleinberg and Raghavan showed a shared algorithm can lower decision quality across a market, with no correlated shock required (PNAS, 2021). pnas.org
- Kim and Garg measured substantial correlation in the errors of large language models, rising with capability and persisting across providers (2025). arxiv.org