Governance artifacts for tool using AI agents, the systems that can take actions across services (search, booking, purchasing, messaging, file operations, workflow automation).
This repository converts my long form essay into decision grade policy deliverables, a one page memo, a risk register, minimum transparency and logging requirements, procurement ready clauses, and a note on competition chokepoints in agent mediated markets. Every adoption number cited in these documents comes from original, reproducible audit data.
Essay. The Invisible Hand Gets Digital Fingers Author. Asish Singh (@asish-singh)
Companion study. The Agentic Web Governance Gap, which grounds these artifacts in audit data from The Agentic Web Index and cites the clauses, risk register, and logging baseline in this pack.
-
memo_1page.mdThe one page overview for executives, policymakers, and procurement leads. The situation, the five controls that matter, and the four documents to request from any agent vendor. -
risk_register.mdTen structured risks with impact and likelihood ratings, the primary control for each, and the audit evidence that proves the control is real. Copy it into your risk system and assign owners. -
transparency_logging_requirements.mdThe minimum disclosures an agent operator owes the public, plus a nine field tool call logging baseline that lets someone who was not in the room reconstruct any incident. Deliberately aligned with emerging open infrastructure conventions. -
procurement_clauses.mdCopy ready contract and RFP language covering permissions, logging and audit, disclosure and third party conduct, incidents, portability, and exit, with notes on which clauses vendors resist and where to hold the line. -
competition_chokepoints_note.mdThe five chokepoints forming in agent mediated markets (steering, defaults, pay to play integration, exclusion, lock in), the earliest observable signal for each, and who should act on it. -
sources.mdPrimary sources and standards behind every factual claim, with a note on what each is used for. -
changelog.mdVersion history for stable citation and review.
AI policy and governance teams, regulators and competition authorities, public sector procurement and oversight teams, enterprise risk and security owners, and researchers studying agent behaviour and market impacts.
- Read
memo_1page.mdto align on the problem and the control categories. - Use
risk_register.mdto prioritise controls for your sector, then assign an owner to every row you keep. - Adopt
transparency_logging_requirements.mdas the minimum baseline for accountability and incident reconstruction. - Copy
procurement_clauses.mdinto an RFP or vendor contract and fill the bracketed choices with counsel. - Use
competition_chokepoints_note.mdto frame testable questions about steering, exclusion, and lock in.
Operational, every recommendation maps to an implementable control or an evidence request. Audit friendly, the pack asks for logs, disclosures, and governance interfaces, never for model internals. Vendor neutral, aligned with open standards rather than any single implementation. Dated, adoption numbers expire quarterly against the current Index edition.
Current version v1.0, July 2026. A living pack, updated as standards, case law, and the quarterly Index evolve.
CC BY 4.0 unless otherwise noted. Not legal advice.