Policy Cards: Machine-Readable Runtime Governance for Autonomous AI Agents

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autore principale: Mavračić, Juraj
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866914118457360384
author Mavračić, Juraj
author_facet Mavračić, Juraj
contents Policy Cards are introduced as a machine-readable, deployment-layer standard for expressing operational, regulatory, and ethical constraints for AI agents. The Policy Card sits with the agent and enables it to follow required constraints at runtime. It tells the agent what it must and must not do. As such, it becomes an integral part of the deployed agent. Policy Cards extend existing transparency artifacts such as Model, Data, and System Cards by defining a normative layer that encodes allow/deny rules, obligations, evidentiary requirements, and crosswalk mappings to assurance frameworks including NIST AI RMF, ISO/IEC 42001, and the EU AI Act. Each Policy Card can be validated automatically, version-controlled, and linked to runtime enforcement or continuous-audit pipelines. The framework enables verifiable compliance for autonomous agents, forming a foundation for distributed assurance in multi-agent ecosystems. Policy Cards provide a practical mechanism for integrating high-level governance with hands-on engineering practice and enabling accountable autonomy at scale.
format Preprint
id arxiv_https___arxiv_org_abs_2510_24383
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Policy Cards: Machine-Readable Runtime Governance for Autonomous AI Agents
Mavračić, Juraj
Artificial Intelligence
Computers and Society
Multiagent Systems
I.2.11; I.2.1; I.2.4; K.4.1; K.4.3
Policy Cards are introduced as a machine-readable, deployment-layer standard for expressing operational, regulatory, and ethical constraints for AI agents. The Policy Card sits with the agent and enables it to follow required constraints at runtime. It tells the agent what it must and must not do. As such, it becomes an integral part of the deployed agent. Policy Cards extend existing transparency artifacts such as Model, Data, and System Cards by defining a normative layer that encodes allow/deny rules, obligations, evidentiary requirements, and crosswalk mappings to assurance frameworks including NIST AI RMF, ISO/IEC 42001, and the EU AI Act. Each Policy Card can be validated automatically, version-controlled, and linked to runtime enforcement or continuous-audit pipelines. The framework enables verifiable compliance for autonomous agents, forming a foundation for distributed assurance in multi-agent ecosystems. Policy Cards provide a practical mechanism for integrating high-level governance with hands-on engineering practice and enabling accountable autonomy at scale.
title Policy Cards: Machine-Readable Runtime Governance for Autonomous AI Agents
topic Artificial Intelligence
Computers and Society
Multiagent Systems
I.2.11; I.2.1; I.2.4; K.4.1; K.4.3
url https://arxiv.org/abs/2510.24383