
Blog Post
The New Agent Control Standard Names the Controls, Not Their Value
September 21, 2026
The OWASP GenAI Security Project unveiled an Agent Control Standard in early September, donated to the project and aimed at runtime enforcement for agentic systems. It sets out that agents should be inspectable, traceable and instrumentable, with declarative hooks and policy enforcement across frameworks.
It answers which controls belong around an agent. It does not say which to build first, and an organization working through the document in order spends its remediation budget in whatever sequence the specification happens to use.
Which Artifact Answers Which Question?
Three exist now and each answers something different, so treating any of them as a remediation plan produces the wrong ordering.
A risk ranking says which threats matter most across a population. A control standard says what enforcement should look like at runtime. A control objective catalogue says what to implement and how it maps to other frameworks. None of the three prices anything, and a remediation plan requires a price per item.
The Sequencing Question Is Unanswered
Guidance suggesting a catalogue be treated as the framework of record while a risk list and a control standard inform which controls warrant immediate effort is describing an ordering without supplying a method. Somebody still has to decide what immediate means, and the artifacts do not contain the input that decision needs.
What Does the New Ranking Methodology Change?
More than it appears, and it is the most quantification-relevant development in the release.

The 2026 risk list weighted analysis of 6,639 documented real-world incidents at a quarter of the score for the first time, alongside three quarters expert consensus. The change introduces observed frequency into the ordering deliberately, which is a real improvement and also tells you what the ordering now measures.
It measures how often something is seen, partly. It contains no term for what any of it costs when it happens, and no term for what remediation costs. So the list has become a better frequency signal and remains silent on the two other inputs a budget decision needs.
Which Explains a Notable Move
Excessive Agency rising from sixth to third is the largest upward move in the list, and under the new methodology that rise partly reflects incident volume. It says the category is being encountered frequently. It does not say what an instance costs, so an organization reprioritizing on the strength of that move is responding to a frequency observation, which converting a threat list into expected loss addresses.
What Has to Be Added to Get a Plan?
Three terms, none of which any standard can supply because all three are properties of the organization rather than of the technology.
- Severity in your environment: What an instance of each risk would cost given your asset values, data and dependencies.
- Cost per control: Implementation plus ongoing operation, since a control requiring weekly attention costs every week.
- Coverage mapping: Which controls reduce which risks and by how much, since one control frequently addresses several and several frequently address one.
With those three, the standard's control list becomes a ranked plan. Without them it is a list somebody works through in document order, and AI risk quantification, or AIRQ, is the exercise that supplies the missing terms.
Which Part of the Standard Has Direct Quantification Value?
The agent bill of materials, which is the genuinely new capability and the one most likely to be overlooked as a documentation feature.

The standard specifies exposing an agent's composition dynamically through established bill-of-materials formats. The result is an enumerated record of what an agent is made of and what it can reach, in a format other systems can consume, which is precisely the input any agent exposure figure requires and the thing most organizations cannot currently produce.
Why Does That Matter More Than the Enforcement Hooks?
Because enforcement without enumeration constrains an unknown surface. A policy layer preventing certain actions is valuable and it cannot tell you what proportion of the agent's capability it covers. The composition record supplies the denominator, and an enumerated action set is the first requirement any credible figure rests on.
What Else Changed in the Risk List?
One retirement worth noting, because it broadens a scope most programs had drawn narrowly.
System prompt leakage was retired and replaced by a wider category covering hidden context exposure, acknowledging that retrieved documents, agent memory, tool responses and application state carry comparable confidentiality risk. A program that had scoped this to the prompt has been scoped too narrowly, since the same exposure exists wherever content enters the model's working context.
Which Widens What Needs Observing
The prompt is one input among several and the others are harder to see. Tool responses arrive on the return path, memory persists between sessions, and retrieved documents are assembled per request from whatever matched, so none is reviewable in the way a prompt is, and what a tool response carries back covers the least visible of them.
Should the Standard Be Adopted Anyway?
Yes, and separating that from the prioritization question keeps both honest.
A common enforcement vocabulary is worth having on its own terms. It gives vendors something to implement against, gives buyers something to ask for, and gives an auditor a reference other than a supplier's own documentation. None of that requires the standard to rank anything, and criticizing it for not ranking is criticizing a specification for not being a business case.
What Should Be Asked of a Vendor Claiming Conformance?
Which parts, since a standard covering inspectability, traceability, instrumentation and composition disclosure permits partial implementation. A product exposing a composition record and no enforcement hooks conforms to something, and it is a different product from one doing the reverse.
Does a Community Standard Carry Regulatory Weight?
Not directly, and the distinction matters before anybody presents conformance as compliance.
European conformity assessment for high-risk systems depends on standards the legislation itself recognizes, published through a formal process. A community specification is not one of those, however well constructed, so implementing it does not establish conformity with anything statutory. Its value is practical rather than legal.
Where Does It Help With an Obligation?
On evidence rather than on conformity. An obligation requiring records of what a system did is easier to satisfy where traceability was implemented to a published specification, because the record exists in a defined shape somebody else can read. So the standard does not satisfy the requirement and it makes satisfying the requirement cheaper, and evidence that travels between regimes is where that saving accrues.
Which Way Should the Mapping Run?
From obligation to control rather than from standard to obligation. Starting with the standard and asking which rules it helps with produces a defensible-looking map with no ordering. Starting with the obligations that apply to you and asking which parts of the standard produce the required evidence produces a shorter list with a reason attached to each item. An AI data fabric records the interactions either direction depends on.
What Should Be Done This Month?
Three things, and the first is the cheapest use of the release.
Read the risk list as a frequency signal and note where it disagrees with your own assessment, since a disagreement indicates either a local factor the list cannot see or a weighting you should revisit. Ask whichever agent platforms you use whether they can produce a composition record, since that is the input everything downstream needs. Then price the top few risks in your own environment rather than adopting the published order, because the published order was never intended to carry a severity term. An AI Interaction Data Fabric supplies the composition and reach from observed activity where a platform cannot.
A Specification Is Not a Business Case
A control standard says what enforcement should look like, a risk list says which threats appear most often, and a control catalogue says what to implement. None prices anything, so none produces the ordering a remediation budget needs. The new methodology weighting thousands of real incidents at a quarter of the score makes the risk list a better frequency signal and leaves severity and remediation cost absent, so a category rising several places is telling you it happens often rather than what it costs. Three terms have to be added, and all three are local rather than published. The part of the standard with the most direct quantification value is the composition record, since enforcement without enumeration constrains a surface nobody has measured. Kovrr's AIRQ supplies severity and control coverage against your own estate.
To see agent risks ranked by exposure removed rather than by published position, book a demo mapped to your own estate.
Agent Control Standard FAQs
Speak to an ExpertWhat does an agent control standard answer?
Which controls belong around an agent at runtime, covering inspectability, traceability, instrumentation and policy enforcement across frameworks. It does not say which to build first, so an organization working through the document in order spends its remediation budget in whatever sequence the specification happens to use. Three artifacts now exist, since a risk ranking says which threats matter across a population and a control objective catalogue says what to implement, and none of the three prices anything.
What did the new ranking methodology change?
The 2026 risk list weighted analysis of 6,639 documented real-world incidents at a quarter of the score for the first time, alongside three quarters expert consensus. The change introduces observed frequency into the ordering deliberately, which is a real improvement and also defines what the ordering measures. It contains no term for what any risk costs when it happens and no term for what remediation costs, so it is a better frequency signal and silent on the other two inputs.
Why did Excessive Agency move up the list?
It rose from sixth to third, the largest upward move in the 2026 list, and under the new methodology that rise partly reflects incident volume. It says the category is being encountered frequently rather than saying what an instance costs. An organization reprioritizing on the strength of that move is therefore responding to a frequency observation, which needs a severity term and a remediation cost before it becomes a budget decision.
What has to be added to turn a standard into a plan?
Three terms, all properties of the organization rather than the technology. Severity in your environment, meaning what an instance of each risk would cost given your asset values, data and dependencies. Cost per control, covering implementation plus ongoing operation since a control requiring weekly attention costs every week. And coverage mapping, since one control frequently addresses several risks and several frequently address one.
Which part of the standard has direct quantification value?
The agent bill of materials. The standard specifies exposing an agent's composition dynamically through established bill-of-materials formats, which produces an enumerated record of what an agent is made of and what it can reach in a format other systems can consume. That is precisely the input any agent exposure figure requires, since enforcement without enumeration constrains a surface nobody has measured.
What else changed in the risk list?
System prompt leakage was retired and replaced by a wider category covering hidden context exposure, acknowledging that retrieved documents, agent memory, tool responses and application state carry comparable confidentiality risk. A program that had scoped this to the prompt has been scoped too narrowly, and the other inputs are harder to observe, since tool responses arrive on the return path, memory persists between sessions and retrieved documents are assembled per request.




