What matters in AI.

Subscribe

Learn / AI agents

Definition · AI agents

Agent Control Standard

The Agent Control Standard (ACS) is an OWASP open specification for runtime governance of AI agents. It lets a separate Guardian Agent inspect what an agent is about to do and allow, deny, or modify it before it happens, through middleware hooks, with an auditable trace and a bill of materials.

Last reviewed

Key points

  • The OWASP GenAI Security Project unveiled ACS on September 1-2, 2026, alongside the 2026 LLM Top 10, as its community passed 30,000 members. It was donated to the project as a new initiative.
  • ACS is the enforcement counterpart to a risk taxonomy: where the Top 10 says what can go wrong, ACS standardizes how an enterprise stops or constrains an agent at runtime.
  • It works through middleware hooks. A separate Guardian Agent reviews an agent's actions and answers allow, deny, modify, ask, or defer before the action runs.
  • An Agent Bill of Materials (AgBOM) inventories an agent's models, tools, and dependencies in CycloneDX, SPDX, or SWID form.
  • ACS is at specification version 0.1, so it is an architecture to plan around and pilot, not a control to deploy today.

The Agent Control Standard (ACS) is an OWASP open specification for runtime governance of AI agents. It is not another list of risks. It standardizes the mechanism an enterprise uses to stop or constrain an agent while it runs: a separate Guardian Agent sits in front of the agent’s actions and decides, before each one, whether it is allowed.

How it works

Two parties speak ACS. The Observed Agent is the system being governed, and it sends a hook request before it acts. The Guardian Agent answers with one of five dispositions: allow, deny, modify, ask (route to a human or service approver), or defer. Hooks fire at points in the agent’s lifecycle, such as before a tool call, around a session, or on memory reads and writes. ACS-Core, the mandatory baseline, covers the hooks, the wire format, and an audit chain; Trace, Inspect, and cryptographic signing are optional conformance profiles. The specification extends existing standards rather than inventing new ones: JSON-RPC 2.0 for the wire, OpenTelemetry and OCSF for tracing, and CycloneDX, SPDX, and SWID for the software bill of materials that ACS calls an Agent Bill of Materials (AgBOM).

Why it matters

Enterprises cannot trust a black-box agent. The OWASP GenAI Security Project states that for agents to be adoptable they must be inspectable, traceable, and instrumentable, so an operator can know what an agent did and why and constrain what it is allowed to do beforehand. The Top 10 for LLM Applications names the risks, such as excessive agency, where an agent holds more permission than a task needs. ACS is the control layer that would have stopped the resulting action. Because it is expressed as declarative, framework-portable hooks, it offers one way to govern agents across fragmented orchestration layers rather than a bespoke integration per platform.

Where definitions disagree

There is not yet a settled answer to how much of agent security ACS actually covers. The specification’s own reference implementation is candid that two gaps sit “above the fold”: its wire is not authenticated and its default failure posture is fail-open, meaning a Guardian that crashes or is unreachable lets the agent proceed as if nothing had asked. ACS-Core requires channel authentication and a session audit chain, but the reference Guardian implements none of the authentication: nothing signs or verifies an envelope, and it logs a per-session hash chain it never publishes on responses. The specification itself notes that “nobody verifies a self-declared claim in v0.1.0”. The Cloud Security Alliance frames ACS as the complementary enforcement layer to a risk taxonomy, but warns that because it is still at version 0.1, adoption by framework and platform vendors is unresolved.

Questions and answers

What is the OWASP Agent Control Standard (ACS)?

ACS is an OWASP open specification for runtime governance of AI agents. It standardizes how an agent platform exposes middleware hooks so a separate Guardian Agent can inspect what an agent is about to do and allow, deny, modify, or route it to an approver before it happens, keeping an auditable trace and an Agent Bill of Materials. The OWASP GenAI Security Project unveiled it on September 1-2, 2026.

How is the Agent Control Standard different from the OWASP Top 10 for LLM Applications?

The Top 10 for LLM Applications is a risk taxonomy: it tells a security team what can go wrong, ranking risks like prompt injection and excessive agency. ACS is a technical specification for runtime enforcement: it standardizes how an enterprise actually stops or constrains an agent once a risk is identified. The two are complementary, and OWASP released them together.

What is an Agent Bill of Materials (AgBOM)?

An AgBOM is a machine-readable inventory of an agent's components: its models, tools, MCP servers, knowledge sources, and memory stores. ACS serializes it as CycloneDX, SPDX, or SWID so an organization can see what an agent can reach and enforce policy against that inventory.

Is the Agent Control Standard ready to deploy?

No. The specification is at version 0.1. The Cloud Security Alliance advises treating it as an architecture to plan around and pilot against rather than a control to deploy today; its practical value depends on whether major agent framework and platform vendors adopt it.

Sources

  1. Agent Control Standard (ACS)OWASP GenAI Security Project, 1 Sep 2026
  2. Agent Control StandardOWASP GenAI Security Project
  3. OWASP's 2026 LLM Top 10 and New Agent Control StandardCloud Security Alliance AI Safety Initiative, 4 Sep 2026
  4. OWASP GenAI Security Project Releases 2026 Top 10 for LLM Applications, Debuts Agent Control Standard and New Resources for Securing Generative and Agentic AIPR Newswire, 2 Sep 2026
  5. OWASP Agent Observability StandardOWASP Foundation
  6. Control Made It Into the Name: The Agent Control Standard Lands at OWASPZenity