A control crosswalk maps what you actually do to govern agents against every framework you will be asked about.
Buyers, auditors and regulators each arrive with a different framework. The underlying controls barely change — identity, authorization, approval, evidence, revocation. This table maps twelve controls across the four frameworks that matter in 2026, so one governance model answers all four conversations.
Get an Agent Trust Gap BriefThe control crosswalk
One row per control. Each column is a framework a buyer, auditor or regulator may hold you to. Mappings are our interpretation for planning purposes, published so they can be checked and argued with — not an assertion of compliance and not legal advice.
| Control | OWASP Agentic 2026 | NIST AI RMF | ISO/IEC 42001 | EU AI Act |
|---|---|---|---|---|
| Agent identity & ownership Every agent has a cryptographic identity and a named human owner | ASI03 Identity & Privilege Abuse | GOVERN 2.1 — roles and responsibilities | A.9.2 — roles, responsibilities and authorities | Art. 26 — deployer obligations, human oversight assignment |
| Least privilege / scoped tools Agents hold only the tool permissions their mission requires | ASI02 Tool Misuse & Exploitation | MAP 5.1 — context and constraints | A.6.1 — AI system impact assessment | Art. 14 — human oversight design |
| Deterministic policy gate A deny-by-default check runs before execution, not after | ASI01 Agent Goal Hijack | MANAGE 2.2 — mechanisms to supersede or deactivate | A.8.2 — system operation controls | Art. 9 — risk management system |
| Payload-bound human approval Consequential actions need single-use, expiring approval tied to an exact payload | ASI09 Human–Agent Trust Exploitation | MANAGE 2.1 — documented decision authority | A.9.3 — human oversight | Art. 14(4) — ability to intervene or interrupt |
| Signed execution receipts Each consequential action emits a signed, hash-chained record | ASI04 Agentic Supply Chain | MEASURE 2.8 — traceability and transparency | A.7.3 — records of AI system operation | Art. 12 — automatic logging / record-keeping |
| Replay & reconstruction Any action can be reconstructed end to end for review | ASI08 Cascading Failures | MEASURE 2.13 — monitoring and incident tracking | A.8.4 — event logging and review | Art. 19 — log retention |
| Revocation & kill switch One agent, or all agents, can be stopped immediately | ASI10 Rogue Agents | MANAGE 2.4 — deactivation mechanisms | A.8.5 — incident response | Art. 14(4)(e) — stop button |
| Autonomy budget / spend ceiling Hard, fail-closed limits on actions, rate and spend | ASI02 Tool Misuse & Exploitation | MANAGE 1.3 — risk tolerance and limits | A.6.2 — resource and operational limits | Art. 9(2) — foreseeable misuse mitigation |
| Memory & context integrity Agent memory and retrieved context are validated before use | ASI06 Memory & Context Poisoning | MEASURE 2.7 — robustness and security | A.7.2 — data quality and provenance | Art. 10 — data governance |
| Inter-agent authorization Agent-to-agent calls are authenticated and scoped | ASI07 Insecure Inter-Agent Communication | MAP 4.1 — third-party and dependency risk | A.10.2 — third-party and supplier controls | Art. 25 — value-chain responsibilities |
| Sandboxed execution Generated or tool-invoked code runs isolated and non-privileged | ASI05 Unexpected Code Execution | MANAGE 2.3 — incident containment | A.8.3 — operational security | Art. 15 — accuracy, robustness, cybersecurity |
| Independent verification Consequential controls are verified by something other than the actor | — | MEASURE 3.1 — independent assessment | A.9.4 — internal audit | Art. 17 — quality management system |
Interpretation These mappings are ApexClaw's reading of published framework text, last verified 2026-08-06. Frameworks evolve; check the primary sources below before relying on any row.
What each framework actually is
OWASP Top 10 for Agentic Applications 2026
Published 9 December 2025. Ten risks, ASI01–ASI10, specific to systems where agents plan, hold memory, call tools and coordinate. Extends rather than replaces the LLM Top 10. The closest thing to a shared vocabulary this category has.
The ten risks →NIST AI RMF
A voluntary, risk-based framework organised as Govern, Map, Measure, Manage. No certification exists. Notable in the US: Texas TRAIGA provides an affirmative defence for organisations that comply with it.
NIST for agents →ISO/IEC 42001
An auditable AI management system standard with genuine third-party certification via a two-stage audit. Management-system shaped rather than agent-shaped.
EU AI Act
Binding law. The Digital Omnibus deferred Annex III high-risk obligations to December 2027, but most transparency and deployer obligations took effect 2 August 2026.
What still applies →The honest gap
None of the three major frameworks — EU AI Act, NIST AI RMF, ISO/IEC 42001 — was designed for agentic systems. They were written for models and management systems, not for software that plans, holds memory, calls tools and spends money on your behalf. Singapore's January 2026 framework is reported to be the only governance document that addresses autonomous agents directly.
That gap is why this crosswalk exists and why it is published rather than sold. A control model everyone can check is worth more to this category than one nobody can see.
Primary sources: OWASP Top 10 for Agentic Applications 2026 · EU AI Act vs NIST AI RMF vs ISO/IEC 42001 comparison · EU AI Act Digital Omnibus deadline changes · CSA: NIST standards for autonomous systems. Last verified 2026-08-06. Not legal advice.
Common questions
Which AI standards can you be certified against?
ISO/IEC 42001 offers accredited third-party certification. NIST AI RMF and the OWASP Agentic Top 10 have no certification path.
What is a control crosswalk?
A mapping showing how one control satisfies requirements across several frameworks, so evidence is produced once and reused.
Does the EU AI Act require certification?
High-risk systems face conformity assessment. It is a legal obligation rather than a framework you opt into.
Is the OWASP Agentic Top 10 a standard?
It is a risk taxonomy and the closest thing to shared vocabulary the category has. It is not certifiable.
Where should we start?
NIST AI RMF for structure, because it costs nothing and other regimes point back at it.
Standards do not name agents; they bind their effects. The crosswalk exists so a team can prove one control set answers every regime at once.