The agentic era · governance that acts
Govern the AI agents, not just the models.
Agents plan, call tools and act. That's a new risk surface — and CSOAI was built agentic-native for it: signed agent cards, a designed 33-agent Council of AI, and Ed25519 Layer-0 attestations, mapped to EU AI Act Art. 14 & 50. Not documentation — control.
An agent calls a tool it shouldn't, or with unsafe inputs.
An agent quietly expands beyond its intended purpose.
Multi-agent chains amplify errors no single agent owns.
Autonomous actions with no meaningful control point.
Users can't tell they're dealing with AI.
No provable record of what an agent did or why.
- ▸ Signed agent cards (A2A): every agent identified, purpose-bound and Ed25519-signed — discoverable at
/.well-known/agent-card.json. - ▸ council review: designed so no single model approves an agent action — a designed supermajority quorum. Measured status (n_eff 1.21 of 3) is published on the Refutation Ledger — design, not yet a live claim.
- ▸ 291 governed MCP servers: agents call tools through a governed layer, every call sealable to Layer 0.
- ▸ Verifiable, not asserted: competitors document controls; CSOAI produces signed, reproducible proof.
Frequently asked
What is AI agent governance?
AI agent governance is the discipline of controlling autonomous AI agents — systems that plan, call tools, and act with limited human input. It covers agent identity, purpose limits, human oversight, tool-use control, inter-agent risk, and an auditable record of every action.
How is governing AI agents different from governing AI models?
A model produces an output; an agent takes actions across tools and other agents. That adds new risks — tool misuse, scope drift, and inter-agent failures — plus stronger duties for human oversight (EU AI Act Art. 14) and transparency/disclosure (Art. 50). Governance has to move from documenting a model to controlling an actor.
How does CSOAI govern AI agents?
CSOAI is agentic-native: every agent carries a signed agent card (purpose, tools, data sources, guardrails) discoverable via A2A, its actions are designed to be reviewable by a 33-agent Council of AI held to a 0.95 care-floor (a designed council — measured status is published on the public Refutation Ledger), and every decision is sealed to Layer 0 with Ed25519 for a verifiable, reproducible record — mapped to the EU AI Act, NIST AI RMF and ISO 42001.
Does CSOAI cover the EU AI Act obligations for agents?
Yes. Human-oversight duties map to Article 14, transparency/disclosure to Article 50, risk management to Article 9, and record-keeping to Articles 11–12 — all evidenced through signed attestations rather than screenshots.
Agent governance: design vs measured
source: Refutation Ledger DR-0007 + gate1 decorrelation runs, 2026-08-01
Frequently asked questions
How governed agents are measured — design vs measured, always labelled.
What is agent governance in measurable terms?
Each governed action is decomposed into checks we can run and count: who proposed it, what policy applied, whether the care floor held, and whether the record is signed. If a check cannot run, it is reported UNMEASURED — not assumed.
Does the council approve agent actions live?
That is the design, not a live claim. The measured cross-checking status today is n_eff 1.21 of 3, published on the Refutation Ledger. The 33-seat council architecture is labelled as a design simulation wherever it is shown.
What stops a single model from approving its own action?
The design rule is that no single model approves an action — a supermajority quorum does. What we can evidence today is the measured decorrelation between independent architectures; the full quorum is published as a target, not a result.
Where are the refuted claims?
On the public Refutation Ledger. When a measurement shows a mechanism does not deliver what the design predicted, the refutation is published with its n and confidence interval — the same prominence as a success.