Skip to content

Repository files navigation

Agentic Web Governance Pack

Governance artifacts for tool using AI agents, the systems that can take actions across services (search, booking, purchasing, messaging, file operations, workflow automation).

This repository converts my long form essay into decision grade policy deliverables, a one page memo, a risk register, minimum transparency and logging requirements, procurement ready clauses, and a note on competition chokepoints in agent mediated markets. Every adoption number cited in these documents comes from original, reproducible audit data.

Essay. The Invisible Hand Gets Digital Fingers Author. Asish Singh (@asish-singh)

Companion study. The Agentic Web Governance Gap, which grounds these artifacts in audit data from The Agentic Web Index and cites the clauses, risk register, and logging baseline in this pack.

What is inside

  • memo_1page.md The one page overview for executives, policymakers, and procurement leads. The situation, the five controls that matter, and the four documents to request from any agent vendor.

  • risk_register.md Ten structured risks with impact and likelihood ratings, the primary control for each, and the audit evidence that proves the control is real. Copy it into your risk system and assign owners.

  • transparency_logging_requirements.md The minimum disclosures an agent operator owes the public, plus a nine field tool call logging baseline that lets someone who was not in the room reconstruct any incident. Deliberately aligned with emerging open infrastructure conventions.

  • procurement_clauses.md Copy ready contract and RFP language covering permissions, logging and audit, disclosure and third party conduct, incidents, portability, and exit, with notes on which clauses vendors resist and where to hold the line.

  • competition_chokepoints_note.md The five chokepoints forming in agent mediated markets (steering, defaults, pay to play integration, exclusion, lock in), the earliest observable signal for each, and who should act on it.

  • sources.md Primary sources and standards behind every factual claim, with a note on what each is used for.

  • changelog.md Version history for stable citation and review.

Who this is for

AI policy and governance teams, regulators and competition authorities, public sector procurement and oversight teams, enterprise risk and security owners, and researchers studying agent behaviour and market impacts.

How to use

  1. Read memo_1page.md to align on the problem and the control categories.
  2. Use risk_register.md to prioritise controls for your sector, then assign an owner to every row you keep.
  3. Adopt transparency_logging_requirements.md as the minimum baseline for accountability and incident reconstruction.
  4. Copy procurement_clauses.md into an RFP or vendor contract and fill the bracketed choices with counsel.
  5. Use competition_chokepoints_note.md to frame testable questions about steering, exclusion, and lock in.

Design principles

Operational, every recommendation maps to an implementable control or an evidence request. Audit friendly, the pack asks for logs, disclosures, and governance interfaces, never for model internals. Vendor neutral, aligned with open standards rather than any single implementation. Dated, adoption numbers expire quarterly against the current Index edition.

Status

Current version v1.0, July 2026. A living pack, updated as standards, case law, and the quarterly Index evolve.

License

CC BY 4.0 unless otherwise noted. Not legal advice.

Contact

GitHub https://github.com/asish-singh LinkedIn

About

Governance artifacts for tool-using AI agents: risk, transparency, procurement, and competition.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors