Trustworthy AI Agent Standards Family — External Standards Alignment

Abstract

This document defines the external-standards alignment model for the Trusted AI Kernel (TAK), Global AI Agent Identification and Governance (GAID), and Job-Specific Intelligence (TAK-JSI) standards family.

The standards family does not replace organization-level AI governance, model evaluation, identity and authorization protocols, credential formats, software testing, or conformity assessment. It composes those bodies of work around an operational assurance subject that is not consistently represented elsewhere: an enduring AI agent identity operating through a materially versioned configuration, qualified for a bounded job and constrained at runtime by live authority, data, oversight, and evidence controls.

The principal augmentation is the end-to-end assurance chain:

enduring agent identity
  -> versioned operating profile
  -> job- and context-specific qualification
  -> runtime authority and autonomy enforcement
  -> attributable action evidence
  -> surveillance, drift detection, and revalidation

This document is informative. Normative requirements remain in the three canonical standards.

1. Scope

This document:

This document does not:

The execution sequence, readiness gates, contribution packages, and go/no-go criteria for external engagement are maintained separately in the informative Standards Contribution Roadmap. This document remains the source of truth for technical overlap, synergy, augmentation, and non-duplication boundaries.

2. Alignment Vocabulary

The following relationship terms are used throughout this document:

Relationship Meaning
adopts Uses an external standard directly for the control or artifact it already defines
profiles Narrows or composes an external standard for an AI-agent-specific use without changing the external standard’s core semantics
augments Defines an additional control or lifecycle relationship that the external work does not presently specify
maps-to Provides a declared correspondence without asserting semantic identity or conformance
adjacent Addresses a related layer but is neither replaced nor normatively extended by this family
out-of-scope Must remain with the cited external authority and must not be redefined here

An implementation statement should not use conforms to, certified to, or an equivalent claim for an external standard when the implementation has only mapped to or profiled part of that standard.

3. Layered Standards Architecture

The family occupies a composition layer between broad governance and protocol implementation:

Layer Primary external work Family relationship
Organization governance and risk ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 42005, NIST AI RMF TAK and TAK-JSI operationalize selected controls for identified agent operating profiles; they do not replace the management system or impact assessment
AI quality, testing, and data ISO/IEC 25059, ISO/IEC TS 42119-2, ISO/IEC 42119-3, ISO/IEC 5259 series TAK-JSI composes quality, test, and data evidence into a job-specific qualification decision and continuing-validity lifecycle
Agentic-AI framework IEEE P3709 and related IEEE agentic-AI projects TAK supplies concrete runtime control, evidence, proactivity, and earned-autonomy requirements suitable for framework clauses and conformance profiles
Identity, authentication, and delegation W3C agent identity work, IETF WIMSE, OAuth, GNAP, SPIFFE, OpenID AIIM GAID profiles established identifiers and credentials while adding subject/operating-state separation, assurance claims, and qualification lifecycle semantics
Credentials and badges W3C Verifiable Credentials, 1EdTech Open Badges GAID profiles credential envelopes for AI-agent claims; it does not define new cryptography or a competing badge transport
Conformity assessment ISO/IEC SC 42 JWG 6, ISO/IEC 42006, ISO/IEC 17065, ISO/IEC 17067 TAK-JSI defines the candidate specified requirements and qualification lifecycle for an AI agent operating profile; accredited assessment remains with recognized conformity-assessment schemes
Runtime interoperability MCP, A2A, HTTP, W3C Trace Context, RFC 9421 TAK and GAID define governance semantics carried across these protocols rather than redefining the protocols
Security and threat knowledge OWASP Agentic Top 10, MITRE ATLAS, CSA MAESTRO, CoSAI TAK maps threats to runtime controls and evaluation cases; threat catalogs remain externally owned

4. NIST Alignment

4.1 NIST AI Risk Management Framework

The NIST AI RMF 1.0 provides the broad GOVERN, MAP, MEASURE, and MANAGE risk functions.

The family:

An AI RMF implementation is organization- and system-oriented. A TAK-JSI qualification is deliberately narrower: it answers whether one identified operating profile has demonstrated fitness for one declared job and context.

4.2 NIST AI Agent Standards Initiative

The NIST AI Agent Standards Initiative organizes current U.S. work around industry-led standards, community protocols, agent identity, and security evaluation.

The family supplies candidate material for the initiative’s stated gap-analysis and measurement work:

NIST engagement is treated as pre-standardization, measurement, and implementation-validation work. Formal consensus text is expected to progress through the relevant standards-development organization.

5. ISO/IEC Alignment

5.1 ISO/IEC JTC 1/SC 42

ISO/IEC JTC 1/SC 42 is the horizontal ISO/IEC committee for artificial intelligence. The relevant work allocation is:

SC 42 group Family contribution
WG 2 — Data TAK-JSI data eligibility, quality, provenance, stewardship, evaluation-dataset, and change-control requirements
WG 3 — Trustworthiness TAK runtime governance, human oversight, evidence, autonomy regression, and material-change controls
WG 4 — Use cases and applications Cross-sector job qualification use cases demonstrating why model-level benchmarks are insufficient
JWG 2 with SC 7 Operating-profile lifecycle, configuration identification, validation continuity, software testing, and change impact
JWG 6 with ISO/CASCO Conformity-assessment schemes for versioned AI agent operating profiles

The family is not proposed as a replacement for SC 42’s horizontal corpus. It is a compositional profile and potential new-work contribution spanning trustworthiness, testing, lifecycle, data, and conformity assessment.

5.2 Management, Risk, Impact, and Oversight

Reference Synergy Family augmentation
ISO/IEC 42001:2023 AI management-system policy, roles, objectives, controls, monitoring, and improvement Binds applicable organizational controls to an agent operating profile and enforces them at action time
ISO/IEC 23894:2023 AI risk-management processes and contextual tailoring Converts risk treatment into qualification constraints, action gates, oversight floors, and revalidation triggers
ISO/IEC 42005:2025 Lifecycle impact assessment for affected people, groups, and society Connects assessed impacts to job scope, prohibited uses, data eligibility, evidence requirements, and autonomy ceilings
ISO/IEC FDIS 42105 (under development) Human control and monitoring of AI systems Distinguishes requested proactivity from permitted autonomy and makes oversight an enforceable, evidence-dependent ceiling

5.3 Quality, Testing, and Data

Reference Synergy Family augmentation
ISO/IEC 25059:2023 AI-system quality characteristics used to select evaluation objectives Requires each applicable characteristic to be operationalized against job outcomes, failure modes, and acceptance thresholds
ISO/IEC TS 42119-2:2025 Risk-based application of software-testing practices to AI systems Treats the complete operating profile—not only the model or AI component—as the qualification subject and connects test results to qualification validity
ISO/IEC 42119-3 Verification and validation analysis across the AI-system lifecycle Adds job/activity scope, representative tool and data conditions, material-change impact, surveillance, and revalidation status
ISO/IEC 5259 series Data-quality concepts, measures, management, process, and governance Makes data classification, permitted use, provenance, residency, quality, and steward approval part of both qualification and runtime eligibility

5.4 Conformity Assessment

TAK-JSI qualifies an AI agent operating profile. It does not certify a human and does not appropriate the terminology or accreditation model of personnel certification.

Reference Applicability
ISO/IEC 17024:2026 adjacent: useful prior art for scheme definition, assessment, surveillance, recertification, suspension, and revocation, but its object is a person and therefore it is not the direct conformity basis for TAK-JSI
ISO/IEC 17065 profiles: product, process, and service certification is the closer conformity-assessment model for a deployed agent operating profile
ISO/IEC 17067:2013 profiles: scheme-design guidance relevant to evaluation selection, surveillance, attestations, and continuing validity
ISO/IEC 42006:2025 adjacent: establishes credible audit and certification of an organization’s AI management system and can participate in broader product/process/service schemes; it does not by itself qualify an individual agent for a job
SC 42 JWG 6 Preferred ISO/IEC liaison point for an AI-agent operating-profile conformity scheme

A TAK-JSI implementation is expected to preserve the normative distinction among:

Only the last category implies operation under a recognized accreditation and certification scheme.

6. IEEE Alignment

6.1 IEEE P3709

IEEE P3709 is an active project for a framework and technical requirements for agentic AI.

TAK is suitable as a requirements and conformance contribution addressing:

The intended relationship is augments, not replacement: P3709 provides the broader agentic-AI framework, while TAK supplies implementable runtime-governance requirements.

6.2 IEEE P3833

IEEE P3833 addresses proactive AI agents in multimodal human-computer interaction.

TAK contributes the cross-domain distinction that:

requested proactivity != delegated authority != demonstrated qualification != permitted autonomy

P3833’s multimodal interaction scope remains externally owned. TAK augments proactivity controls by defining the hard ceilings and evidence conditions that a user-experience preference cannot override.

7. W3C and 1EdTech Alignment

7.1 Agent Identity Registry Protocol Community Group

The W3C Agent Identity Registry Protocol Community Group is developing verifiable agent identity infrastructure, including agent credentials, trust negotiation, lifecycle management, and integration with MCP, A2A, OAuth/OIDC, and SPIFFE.

GAID:

7.2 Agent Declaration and Assurance Community Group

The W3C Agent Declaration and Assurance Community Group is developing declarations of agent identity, ownership, software versions, models, operating boundaries, conformance profiles, and runtime bindings.

This is the closest active overlap with GAID. The preferred relationship is a coordinated profile:

ADACG concern GAID contribution
Agent declaration manifest AIDoc minimum fields and public/private disclosure profiles
Ownership and accountability Issuer lineage, owner of record, steward, and namespace authority
Software/model version disclosure Operating-profile reference and material-state fingerprint
Operational boundaries Authorization-class references, qualification scope, prohibited uses, and data constraints
Graduated conformance profiles GAID-Private, GAID-Federated, and GAID-Public
Runtime assurance Current claim status, receipt linkage, validation continuity, and verifier behavior

GAID must not create a parallel universal manifest where an interoperable W3C manifest can carry the same semantics.

7.3 Agent Trust Protocol Community Group

The W3C Agent Trust Protocol Community Group addresses verifiable identity, trust scoring, privacy-preserving interaction, and conformance testing.

GAID can provide verified inputs to trust decisions, but it deliberately does not define a universal scalar trust score. Trust remains contextual: a valid identity or qualification for one job does not imply general trustworthiness or authorization for another.

7.4 Verifiable Credentials and Open Badges

The W3C Verifiable Credentials Data Model 2.0 and 1EdTech Open Badges 3.0 already define portable, signed claim envelopes with issuer, subject, evidence, validity, expiry, status, and verification patterns.

GAID is intended to profile those formats for portable qualification and assurance claims rather than define a competing credential envelope. It augments them with AI-agent-specific semantics:

8. IETF, OpenID, and Workload-Identity Alignment

8.1 IETF WIMSE

The IETF Workload Identity in Multi-System Environments working group defines workload identity architecture, identifiers, credentials, and authentication mechanisms. Current AI-agent work includes:

These drafts are works in progress and are not cited as completed standards.

The family relationship is:

8.2 OpenID Foundation AIIM

The OpenID Foundation AI Identity Management Community Group provides a venue for AI-agent identity use cases, threat modeling, modular roles and scopes, and interoperability with open identity standards.

GAID is positioned as an AI-agent assurance and operating-state profile for established OpenID/OAuth deployments. It does not replace OAuth authorization servers, OpenID providers, tokens, proof-of-possession, or enterprise identity policy.

9. Protocol and Evidence Carriers

External specification Adopted or profiled use
Model Context Protocol Tool discovery and invocation carrier; TAK supplies tool policy, approval, data, and evidence controls behind the transport
Agent2Agent Protocol v1.0 Agent discovery, task, artifact, security-scheme, signed-card, multi-tenancy, and extension carrier; GAID supplies the agent-subject identity, private/public boundary mapping, protected participation graph, and minimized external identity view that A2A deliberately leaves to the implementation, while TAK supplies delegation narrowing
W3C Trace Context Correlation identifiers across agent, tool, model, queue, and delegate boundaries
RFC 9421 HTTP Message Signatures Message integrity and signer binding for cross-boundary evidence
RFC 9449 DPoP Sender-constrained OAuth token use where bearer-token replay is unacceptable
SCITT and transparency-log patterns Verifiable publication and status history for signed claims and receipts
in-toto and SLSA Attestation and provenance patterns for operating-profile components and release evidence
C2PA Provenance for agent-produced content; not a substitute for agent identity or action authorization

The family defines the semantics that these carriers transport. Implementations should preserve the native identifiers and verification material of adopted protocols instead of translating them into opaque, unverifiable prose.

A2A’s enterprise guidance covers transport security, standard web authentication, authorization, data minimization, observability, audit, and API management. Its core leaves identity outside A2A payload semantics and leaves authorization boundaries implementation-defined; its multi-tenancy identifier is opaque routing, not agent identity. Consequently, GAID profiles A2A through its standard extension points rather than changing the A2A task or transport model. The profile adds the enterprise identity concerns A2A does not normatively define: canonical agent subjects, private-to-public aliases, full source-side multi-agent custody, public-only boundary projection, and signed commitments to withheld participation.

10. Distinctive Augmentation

The family addresses a gap left when adjacent standards are implemented independently.

10.1 Identity Is Not Operating State

An agent can retain its enduring identity while its model, instruction bundle, tools, retrieval sources, memory policy, provider routing, qualification, or autonomy posture changes. GAID binds both without conflating them.

10.2 Capability Is Not Qualification

A model benchmark, system card, declared skill, successful demonstration, or broad capability evaluation can contribute evidence. None alone establishes that the complete operating profile is qualified for a job under representative tools, data, policy, and consequence boundaries.

10.3 Qualification Is Not Authorization

TAK-JSI establishes a ceiling on permissible autonomy. TAK still requires live principal authority, route and workflow grants, tool policy, data eligibility, and mandatory oversight for every action.

10.4 Proactivity Is Not Autonomy

Proactivity expresses initiative and interaction preference. Autonomy expresses permitted execution latitude after hard constraints and evidence have been evaluated. Increasing proactivity cannot raise the autonomy ceiling.

10.5 Validation Does Not Survive Material Change Silently

Qualification and assurance claims are bound to a fingerprinted operating profile. A material change places affected claims into revalidation unless the applicable scheme contains evidence that the change is immaterial.

10.6 Evidence Closes the Lifecycle

Action receipts and operational surveillance feed subsequent qualification and autonomy decisions. The standards family therefore connects pre-deployment evaluation to runtime behavior and post-deployment revalidation rather than treating testing as a one-time gate.

11. Standards-Contribution Profile

A contribution derived from this family should contain:

The complete artifact matrix and staged readiness criteria are defined in the Standards Contribution Roadmap.

The preferred contribution allocation is:

Contribution Primary venue Form
Agent harness, authority, proactivity, and autonomy controls IEEE P3709; ISO/IEC SC 42 WG 3/JWG 2 Requirements clauses and conformance profile
Agent identity, operating-state, and assurance manifest W3C ADACG and Agent Identity Registry groups; OpenID AIIM Use cases, schema profile, lifecycle requirements, and test vectors
Workload identifier, delegation, and signed action evidence IETF WIMSE and related OAuth work Focused protocol requirements or profile contributions
Job-specific operating-profile qualification NIST measurement work; ISO/IEC SC 42 WG 3/WG 4/JWG 6 Evaluation framework, use cases, and conformity-scheme proposal
Qualification badge portability W3C VC and 1EdTech Open Badges communities Credential profile, JSON-LD context, and verification tests

For ISO/IEC, a formal new-work proposal should follow the ISO proposal process through the relevant national body or other authorized proposer and should identify a project leader, market need, affected stakeholders, relationship to existing work, and an initial draft or outline.

12. Implementation and Claiming Guidance

An implementation using this alignment model should:

13. Open Standardization Questions

The following questions require multistakeholder resolution:

These questions are intentionally not resolved by unilateral DPF implementation. They identify where standards-body consensus is required.

14. Summary

The family complements a mature but segmented standards landscape. Its contribution is the composition contract that makes an AI agent’s identity, current operating state, job qualification, runtime authority, autonomy posture, evidence, and revalidation status mutually consistent and verifiable.

The standards should therefore progress through coordinated contributions:

This positioning preserves existing protocol and conformity-assessment authorities while filling the operational gap between organization-level governance, model evaluation, identity, and consequential autonomous action.