Sources & limitations
Source tiers describe authority and rigor. Read each finding with its study design, setting, and qualifications. A reported result is not a guarantee of performance elsewhere.
How to interpret source tiers and evidence →Evidence labels in this briefing
3 graded highlights. Counts describe the labels attached to highlights, not unique sources or confidence in a result.
- T11 Primary authoritative
- T22 Authoritative secondary
Peer review, study design, replication, and uncertainty need to be read separately. Interpret the tiers →
At a glance
Primary Development : OWASP's GenAI Security Project has published the Agent Control Standard (ACS) and a GenAI Security Industry Framework Crosswalk (both OWASP resource pages dated 1 Sep 2026). ACS specifies portable, declarative, runtime-enforced agent controls via middleware hooks: an open spec aimed squarely at runtime agent control.
T1Agentic Evals & Red-Teaming , No new release confirmed today. UK AISI's Inspect remains the reference open framework: 200+ prebuilt benchmarks, native tool-approval, sandboxing, and support for wrapping external agents. Logged as durable capability, not news.
T2Regulatory & Enterprise : Status, not event. The European Commission’s AI Act implementation timeline confirms the bulk of the Act applied 2 Aug 2026; high-risk obligations under Article 6(2) / Annex III remain scheduled for 2 Dec 2027.
T2
1. Agentic RAI & Control (the publication's focus)
OWASP Agent Control Standard (ACS) is the day's substantive item. Its premise is that enterprises "cannot rely on black-box agents," and it stakes out four requirements: agents must be inspectable, traceable, and instrumentable, with the capacity to control behaviour at runtime. Mechanically, ACS defines how agent platforms expose middleware hooks and how safety policies are enforced through them, producing declarative controls intended to be portable across agent frameworks. It descends from OWASP's Feb 2025 Agentic AI – Threats and Mitigations threat model.
Per your standing instruction on vendor framing, sir, the distinction matters: what ACS demonstrates is a specification and a threat-model lineage. What it asserts is cross-framework portability and enterprise-grade trustworthiness. There is as yet no independent evidence of adoption or efficacy: "portable across frameworks" should be read as a design goal pending real integrations. Worth reading in full before you cite it in a governance forum.
Evals harness. UK AISI's Inspect (with Meridian Labs) composes datasets, solvers, and scorers, and, most relevant to control integrity, ships Tool Approval, sandboxing (Docker/K8s/Modal and others), control channels, and early stopping as first-class primitives. It can wrap external agents directly, which makes it the natural harness for testing whether ACS-style controls actually bind under adversarial pressure. That experiment does not appear to have been run publicly; it is a gap someone should fill.
2. Enterprise Governance & Safety
The Crosswalk is the more immediately usable artefact. OWASP's GenAI Security Industry Framework Crosswalk (1 Sep 2026) maps 51 GenAI vulnerabilities drawn from four source lists to controls across 25 frameworks, including NIST, ISO, MITRE ATLAS, and the EU AI Act. For a governance team, this is the translation layer: it turns scattered OWASP guidance into a coverage matrix spanning LLM, agentic, and data-security risk whose mappings still require review, and, more valuably, exposes where coverage is absent. This is precisely the class of primary source our own corpus lacks.
No frontier-lab safety-framework update surfaced today. I note the absence rather than pad the section.
3. Policy & Compute Governance
EU AI Act: tracking status. Per the European Commission’s implementation timeline: the bulk of the Act began applying 2 Aug 2026; GPAI content-transparency duties under Article 50(2) carry a 2 Dec 2026 compliance date for systems placed on the market before 2 Aug 2026; high-risk obligations (Article 6(2) / Annex III) remain 2 Dec 2027. Operationally, the EU AI Office is running a 40-post hiring round, with expressions of interest due 8 Sep, midday CET: a modest but real signal that enforcement capacity is being staffed rather than merely legislated.
No NIST or ISO publication surfaced today, and no compute- or chip-governance development met the evidence bar. Reported as null results.
Sources Catalog & Evidence Verification
- OWASP Agent Control Standard (ACS): 1 Sep 2026. Runtime-enforced, declarative, framework-portable agent controls via middleware hooks. https://genai.owasp.org/resource/agent-control-standard-acs/
- OWASP GenAI Security Industry Framework Crosswalk: 1 Sep 2026. 51 vulnerabilities mapped to 25 frameworks (NIST, ISO, MITRE ATLAS, EU AI Act). https://genai.owasp.org/resource/genai-security-industry-framework-crosswalk/
- OWASP Agentic AI – Threats and Mitigations: 17 Feb 2025. Threat-model reference; lineage source for ACS. https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/
- **UK AISI Inspect evaluation framework**: 200+ benchmarks; tool approval, sandboxing, control channel, external-agent support. https://inspect.aisi.org.uk/
- European Commission AI Act Implementation Timeline: lists 2 Aug 2026 / 2 Dec 2026 / 2 Dec 2027 milestones. https://ai-act-service-desk.ec.europa.eu/en/ai-act/eu-ai-act-implementation-timeline
Evidence integrity note: All five sources were fetched and verified directly earlier in today's session; nothing above is asserted from memory. The RAI corpus returned zero matches across five queries on agentic governance, benchmarks, red-teaming, autonomous-system risk, and tool-use oversight, so this briefing rests entirely on live external verification. Our archive remains bare on exactly the topics you care most about.
That last line, sir, is the one I'd most like to stop writing. Say the word and I'll add all four OWASP/AISI items to the Sources Catalog, so tomorrow's briefing begins with a shelf rather than an apology.