The governance authority layer
What agent governance is, why it can't be a language model's opinion, what its 7 control families prevent, how each of 27 controls maps to a named standard clause, and what failing an audit costs under the EU AI Act.
Published · updated · by Julian Joseph, founder
Get an Agent Trust Gap BriefWhat is the governance authority layer?
Four pages that establish what agent governance is, what its 7 control families prevent, how each of 27 controls maps to OWASP, NIST, ISO and the EU AI Act, and what a failed audit costs under published law.
Who is this section written for?
Anyone who has to answer for an autonomous agent's behaviour: an engineer deciding what to build first, a regulator or auditor checking evidence against a clause, or an executive who needs to know what an unaddressed gap actually costs.
What makes this different from the /research/ section?
Research is descriptive: distributions, failure rates, mechanics. Governance is normative: what the 27 controls are for, which obligation each evidences, and what published law attaches to leaving one unevidenced.
Where do the facts on these four pages come from?
Only aga.py's 27 control definitions, its own adversarial fixture pairs re-run live, the published ARB methodology for disambiguation, and the EU AI Act's own Article 99 text — nothing invented, no client or partner named.
The four pages
| Page | What it establishes |
|---|---|
| What Is Agent Governance? | A deterministic audit of an agent's source and deployment, proven with two adversarial fixtures that read alike but score opposite. |
| The 7 Control Families | Identity, authority, isolation, evidence, supply chain, oversight, governance: what each family prevents and the failure it maps to. |
| Regulator Crosswalk | One row per control: the exact OWASP / NIST / ISO / EU AI Act clause each of the 27 controls evidences. |
| What Failure Costs | EU AI Act Article 99's real penalty tiers, mapped to the controls that evidence each obligation article — no invented figures. |
What Is Agent Governance?
Why an LLM judging code can't replace it — proven with two adversarial fixtures.
Read →What Failure Costs
The published EU AI Act penalty tiers, mapped to the controls that evidence each obligation.
Read →Sources for this section
Across the 27 controls, family weights range from 8% (Documented Governance) to 20% (Authority & Permission Gates) of the total score, and standard references range from 33.3% of controls (EU AI Act, 9/27) to 70.4% (NIST AI RMF, 19/27) — see the regulator crosswalk for every control's exact clause.
/root/apexclaw-audit/aga.py (27 controls, 7 families), its own
aga_fixtures/tricky_clean and aga_fixtures/tricky_dirty (re-run live via
aga_cli.py, 2026-08-24), the published ARB
methodology.json rubric, and Article 99 of the EU AI Act (Regulation (EU) 2024/1689). No figure across these
four pages is invented, no client is named, no partner is named, and no certification is claimed that ApexClaw
does not hold — see /trust/.
Primary standards cited on this page: OWASP Agentic Top 10, NIST AI RMF, ISO/IEC 42001, EU AI Act.
By Julian Joseph, Founder, ApexClaw. Every figure on this page is recomputed at build time from a named source file and date — see the method notes above. Reviewed against the claims policy: sourced, first-party, or labelled.