Home The signal Anatomy of an agent Reference architecture Risk-Tiers Guardrail stack Governance in action Best practices Standards and crosswalk Implementation From the field Roadmap Companion toolkit Straight answers Glossary References
15 · References

Sources used in this page

Everything cited above, with links. Where a source has a commercial interest in the category it covers, that is flagged.

STANDARDS ISO · NIST · OWASPIMDA · EU AI Act ANALYST McKinsey · Gartnercited per claim only VENDOR · FLAGGED Microsoft · AnthropicIBM · protocol specs Nineteen sources, every one linked commercially interested sources are marked, because they sell into the category they describe Research current as at August 2026 the crosswalk is a scoping aid, not a certified mapping
  1. McKinsey. State of AI trust in 2026: shifting to the agentic era. Survey of roughly 500 organizations, fielded December 2025 to January 2026. Source of the 33% governance-readiness figure.
  2. Gartner. Applying uniform governance across AI agents will lead to enterprise AI agent failure, May 2026. Source of the prediction that 40% of enterprises will demote or decommission agents by 2027 after governance gaps surface in production. Cited for that claim only.
  3. Gartner. Hype Cycle for Agentic AI, 2026, including the guardian agents category used in the guardrail section.
  4. OWASP GenAI Security Project. OWASP Top 10 for Agentic Applications (ASI01 to ASI10), 2026 edition. The failure-mode table maps directly to these categories.
  5. IMDA Singapore. Model AI Governance Framework for Agentic AI (PDF), launched 22 January 2026. Four-dimension structure and the agent identity and accountability requirements.
  6. Ministry of Digital Development and Information, Singapore. Launch announcement for the agentic AI governance framework.
  7. NIST. AI Risk Management Framework. The Govern, Map, Measure, Manage structure used in the control mapping.
  8. Cloud Security Alliance. Research note on the NIST AI Agent Standards Initiative, covering the CAISI program launched February 2026 and the forthcoming SP 800-53 control overlays for single and multi-agent systems.
  9. Cloud Security Alliance. Agent Identity Governance Framework, used in the identity and entitlement component.
  • Anthropic. MCP authorization specification. OAuth 2.1, protected resource metadata (RFC 9728), resource indicators (RFC 8707), PKCE, mandatory audience validation, and the explicit prohibition on token passthrough. Vendor source.
  • A2A Project. Enterprise-ready A2A: security and authorization. Mandated HTTPS and header-borne credentials, required authorization checks on protocol operations, and the areas left implementation-defined.
  • OpenTelemetry. GenAI semantic conventions registry. Source for the stability position: agent operations including invoke_agent and execute_tool remain at Development.
  • NIST. AI 600-1, Generative AI Profile. Over two hundred suggested actions across twelve GenAI risk categories, mapped to the AI RMF functions used in the crosswalk.
    1. Microsoft. Governing agent identities, Microsoft Entra ID Governance. Orphaned-agent detection, lifecycle automation and time-bound access packages. Vendor source.
    2. Microsoft. Get ahead of agent sprawl: manage and govern AI agents at scale. Vendor source.
    3. Linux Foundation. A2A protocol surpasses 150 organizations and lands in major cloud platforms. Source of the v1.0 and adoption figures.
    4. A2A Project. Agent2Agent protocol specification, including the roadmap for registry, interoperability and security best practice.
    5. Anthropic. Model Context Protocol specification. The tool and context interface referenced throughout the integration section. Vendor source.
    6. Anthropic. Effective context engineering for AI agents. Compaction, structured note-taking and subagent context isolation. Vendor source.
    7. OpenTelemetry. Inside the LLM call: GenAI observability with OpenTelemetry, plus the semantic conventions work extending to multi-agent tasks, teams and memory.
    8. IBM. Agentic AI governance playbook. Vendor source.
    9. European Commission. Regulatory framework for AI (EU AI Act). High-risk obligations for standalone Annex III systems moved to December 2027 under the Digital Omnibus, and to August 2028 for Annex I embedded products.
    10. ISO. ISO/IEC 42001, AI management systems. The management-system spine behind the standards register.

    Research current as at August 2026. Analyst predictions are cited as published and are forward-looking; each is used only for the specific claim its source supports. Vendor-published material is flagged because those organizations sell into the category they describe. The standards crosswalk is a scoping aid produced by the author, not a certified mapping, and ISO/IEC 42001 in particular is an organizational management-system standard rather than a technical agent architecture. Regulatory timelines change: the EU position stated here reflects the Digital Omnibus deferral of standalone high-risk obligations to 2 December 2027 and product-embedded high-risk systems to 2 August 2028. Confirm the current position with counsel before making a compliance commitment.

    Where would you start?

    If you are standing up an agent platform, tightening the controls on one you already have, or preparing for an audit that now includes agents, I am happy to look at it with you.