A free, vendor-neutral standard for running AI agents in production. It defines the Agent Record, the accountabilities behind every agent, the operating cadence that keeps an estate under control, and three levels of conformance.
Agent registries arrived in 2026. Microsoft Agent 365, Workday's Agent System of Record and ServiceNow will each hand an enterprise a list of every agent running inside it. That list answers two questions: what exists, and what it can reach.
It does not record who is accountable for what an agent produces. It does not hold what the agent costs per successful outcome, the evidence that justified promoting it to production, the thresholds that trigger its review, or the criteria that retire it.
So the estate grows faster than the controls around it. IBM's June 2026 study of two thousand CIOs and CTOs found two-thirds accountable for AI systems they do not fully control, and seven in ten saying business teams deploy faster than IT can track. Grant Thornton's 2026 survey found 78 per cent of executives without strong confidence they could pass an independent AI governance audit inside ninety days. Enterprise scans routinely turn up dozens of agents running with no owner attached.
The registry tells you what is running. The Standard tells you what is worth running.
Conformance is a state held, not a report produced. Three cumulative levels: Visible, every production agent carries a Record; Accountable, every Record names its accountabilities; Stewarded, the estate runs the operating cadence. Self-declared at v1.0. The conformance requirements →
Accountable for an estate growing faster than the controls around it, and for answering the board's question: how many agents, and who owns each one.
The named person behind a production agent. The Record defines what they answer for; the cadence defines when they answer for it.
Holding budget or risk for systems finance cannot yet see. The Record carries cost per successful outcome and the criteria that retire an agent.
It does not define how agents are built, or which models and platforms are used. It does not assess whether an individual agent is safe, secure, lawful or fair to deploy; those questions come first and are answered elsewhere. It does not confer compliance with any framework it maps to. And it does not replace an agent registry: it defines what a registry is for.
The entry point is a one-week diagnostic: pick the five production agents that matter most, and attempt to complete an Agent Record for each. Where the Record cannot be completed, the gap is the finding. The Five-Agent Test →
Related: The Pilot Trap carries the argument · Concepts defines the vocabulary · Research carries the evidence.