Thanks for the concrete reporting structure. The Reporting Compact's timelines are a real improvement over how most incident sharing works today.
One gap: the draft assumes the agent belongs to an enterprise that can run this process. Scope and Membership lists model developers, deployers, tool providers, researchers, critical-infrastructure operators, and government observers, with no line for a single-person operator holding the signing key with no SOC. That population is growing, and the Reporting Compact and Evidence Preservation both read as written for an organization with a security team.
For that case, the useful object differs. A portable, verifiable attestation the agent carries would let an individual operator produce evidence at the point of interaction, instead of through a submission process built for organizational members. It also needs a defined exit: the operator can pull their own evidence and memory out of any system that held it.
Concrete proposal: add an operator-held evidence profile to Evidence Preservation naming who holds the signing key absent an enterprise custodian, what a finding contains absent a SOC to write the 30-day control-failure analysis, and how a finding gets redacted before it enters the exchange.
I maintain an open-source operator-side enforcement and custody layer for AI agents, with drill evidence on macOS. Happy to draft a short appendix or a field-set PR if useful.
Thanks for the concrete reporting structure. The Reporting Compact's timelines are a real improvement over how most incident sharing works today.
One gap: the draft assumes the agent belongs to an enterprise that can run this process. Scope and Membership lists model developers, deployers, tool providers, researchers, critical-infrastructure operators, and government observers, with no line for a single-person operator holding the signing key with no SOC. That population is growing, and the Reporting Compact and Evidence Preservation both read as written for an organization with a security team.
For that case, the useful object differs. A portable, verifiable attestation the agent carries would let an individual operator produce evidence at the point of interaction, instead of through a submission process built for organizational members. It also needs a defined exit: the operator can pull their own evidence and memory out of any system that held it.
Concrete proposal: add an operator-held evidence profile to Evidence Preservation naming who holds the signing key absent an enterprise custodian, what a finding contains absent a SOC to write the 30-day control-failure analysis, and how a finding gets redacted before it enters the exchange.
I maintain an open-source operator-side enforcement and custody layer for AI agents, with drill evidence on macOS. Happy to draft a short appendix or a field-set PR if useful.