ApexClaw
HomeGovernance
GOVERNANCE

The governance authority layer

What agent governance is, why it can't be a language model's opinion, what its 7 control families prevent, how each of 27 controls maps to a named standard clause, and what failing an audit costs under the EU AI Act.

Published · updated · by , founder

Get an Agent Trust Gap Brief

What is the governance authority layer?

Four pages that establish what agent governance is, what its 7 control families prevent, how each of 27 controls maps to OWASP, NIST, ISO and the EU AI Act, and what a failed audit costs under published law.

Who is this section written for?

Anyone who has to answer for an autonomous agent's behaviour: an engineer deciding what to build first, a regulator or auditor checking evidence against a clause, or an executive who needs to know what an unaddressed gap actually costs.

What makes this different from the /research/ section?

Research is descriptive: distributions, failure rates, mechanics. Governance is normative: what the 27 controls are for, which obligation each evidences, and what published law attaches to leaving one unevidenced.

Where do the facts on these four pages come from?

Only aga.py's 27 control definitions, its own adversarial fixture pairs re-run live, the published ARB methodology for disambiguation, and the EU AI Act's own Article 99 text — nothing invented, no client or partner named.

The four pages

PageWhat it establishes
What Is Agent Governance?A deterministic audit of an agent's source and deployment, proven with two adversarial fixtures that read alike but score opposite.
The 7 Control FamiliesIdentity, authority, isolation, evidence, supply chain, oversight, governance: what each family prevents and the failure it maps to.
Regulator CrosswalkOne row per control: the exact OWASP / NIST / ISO / EU AI Act clause each of the 27 controls evidences.
What Failure CostsEU AI Act Article 99's real penalty tiers, mapped to the controls that evidence each obligation article — no invented figures.

What Is Agent Governance?

Why an LLM judging code can't replace it — proven with two adversarial fixtures.

Read →

The 7 Control Families

What each of the 7 families prevents, and the failure mode it maps to.

Read →

Regulator Crosswalk

27 controls, one row each, mapped to the exact clause of every standard.

Read →

What Failure Costs

The published EU AI Act penalty tiers, mapped to the controls that evidence each obligation.

Read →

Sources for this section

Across the 27 controls, family weights range from 8% (Documented Governance) to 20% (Authority & Permission Gates) of the total score, and standard references range from 33.3% of controls (EU AI Act, 9/27) to 70.4% (NIST AI RMF, 19/27) — see the regulator crosswalk for every control's exact clause.

/root/apexclaw-audit/aga.py (27 controls, 7 families), its own aga_fixtures/tricky_clean and aga_fixtures/tricky_dirty (re-run live via aga_cli.py, 2026-08-24), the published ARB methodology.json rubric, and Article 99 of the EU AI Act (Regulation (EU) 2024/1689). No figure across these four pages is invented, no client is named, no partner is named, and no certification is claimed that ApexClaw does not hold — see /trust/.

Primary standards cited on this page: OWASP Agentic Top 10, NIST AI RMF, ISO/IEC 42001, EU AI Act.

By Julian Joseph, Founder, ApexClaw. Every figure on this page is recomputed at build time from a named source file and date — see the method notes above. Reviewed against the claims policy: sourced, first-party, or labelled.