Skip to content
LAUNCH FILM — LIVEGREENLIGHT · PATENT-PENDINGRUNTIME AUTHORIZATION FOR AI AGENTSMCP CONNECTORS — IN DESIGNISO/IEC 27001 — ROADMAPSOC 2 TYPE II — ROADMAPISO/IEC 42001 — ROADMAPMAS FEAT — DESIGN-ALIGNEDDETERMINISTIC · EXPLAINABLE · TAMPER-EVIDENTAI ACTS · CRELIS DECIDESLAUNCH FILM — LIVEGREENLIGHT · PATENT-PENDINGRUNTIME AUTHORIZATION FOR AI AGENTSMCP CONNECTORS — IN DESIGNISO/IEC 27001 — ROADMAPSOC 2 TYPE II — ROADMAPISO/IEC 42001 — ROADMAPMAS FEAT — DESIGN-ALIGNEDDETERMINISTIC · EXPLAINABLE · TAMPER-EVIDENTAI ACTS · CRELIS DECIDES

Reference

AI Agent Runtime Controls Reference

SAFR, NIST and EU AI Act requirements relevant to agent execution, authorization, oversight and evidence.

CC BY 4.0Version 1.0.0·Last verified 2026-08-22· Methodology Download CSV

An independent reference that maps what major AI governance and security frameworks require to the controls that operate at AI-agent execution time — authorization, human oversight, evidence and monitoring. Each row keeps three things separate: what the source says, a runtime engineering interpretation, and the control or evidence it implies.

Coverage does not mean compliance. A control may support a governance objective but does not by itself establish legal or regulatory compliance, and nothing here implies any regulator or standards body endorses this resource or Crelis. See the methodology for how each row is built and labelled.

Framework
Control category
Runtime relevance

18 of 18 verified mappings

Crelis coverage — 7 direct · 7 partial · 2 adjacent · 2 not addressed / n-a

MAS SAFRNon-bindingGovernance checkpointsRuntime

What the source says

"The SAFR framework provides for a set of governance checkpoints that verifies and records an AI agent's proposed actions before the execution of its tasks."

MAS — Safeguards for Agentic Finance at Runtime (SAFR), media release·v1.0, 3 July 2026Primary source

Non-binding (industry white paper under MAS' BuildFin.ai initiative)

Runtime engineering interpretation — our reading, not the source's words

Implies an in-path decision point that intercepts each proposed agent action before it executes and produces both a decision and a record. This is an execution-time control, not a pre-deployment review.

Control / evidence implication

A pre-execution checkpoint that emits, per proposed action, an allow / route / deny decision and a corresponding decision record.

Crelis coverage: DirectSAFR-01 · confidence high
MAS SAFRNon-bindingAuthorisation of agent actionsRuntime

What the source says

SAFR "propos[es] a framework for the governance of AI agents in financial services, defining how agent actions are authorised..."

MAS — Safeguards for Agentic Finance at Runtime (SAFR), publication page·v1.0, 3 July 2026Primary source

Non-binding (industry white paper under MAS' BuildFin.ai initiative)

Runtime engineering interpretation — our reading, not the source's words

At runtime, each proposed action is checked against what the agent is permitted to do (its scope / policy) and allowed to proceed only where it is authorised.

Control / evidence implication

A per-action authorization decision, bound to the policy or scope it was evaluated against.

Crelis coverage: DirectSAFR-02 · confidence high
MAS SAFRNon-bindingActivation of human oversightRuntime

What the source says

SAFR defines "...how human oversight is activated..."

MAS — Safeguards for Agentic Finance at Runtime (SAFR), publication page·v1.0, 3 July 2026Primary source

Non-binding (industry white paper under MAS' BuildFin.ai initiative)

Runtime engineering interpretation — our reading, not the source's words

Defined conditions route a proposed action to a human for approval before it executes — human involvement at the point of action rather than after the fact.

Control / evidence implication

Recorded escalation-to-human decisions (which action, which condition, who reviewed, outcome).

Crelis coverage: DirectSAFR-03 · confidence high
MAS SAFRNon-bindingRecording at the point of decisionRuntime

What the source says

SAFR defines "...what is recorded at the point of every decision."

MAS — Safeguards for Agentic Finance at Runtime (SAFR), publication page·v1.0, 3 July 2026Primary source

Non-binding (industry white paper under MAS' BuildFin.ai initiative)

Runtime engineering interpretation — our reading, not the source's words

Each consequential decision produces a durable record capturing the proposed action, the decision taken, and the basis for it.

Control / evidence implication

A decision record generated per consequential action and retained for later review.

Crelis coverage: DirectSAFR-04 · confidence high
MAS SAFRNon-bindingSafeguard area — policy-bound executionRuntime

What the source says

The white paper "sets out the direction for how these safeguards, including policy bound execution, real time validation, auditability and interoperability" operate.

MAS — Safeguards for Agentic Finance at Runtime (SAFR), media release·v1.0, 3 July 2026Primary source

Non-binding (industry white paper under MAS' BuildFin.ai initiative)

Runtime engineering interpretation — our reading, not the source's words

Execution is constrained by explicit policy; an action outside policy is not executed. 'Policy-bound' implies the policy in force is knowable and attached to the decision.

Control / evidence implication

The policy (and its version) bound to each decision, so a decision can be re-checked against the rule that produced it.

Crelis coverage: DirectSAFR-05 · confidence high
MAS SAFRNon-bindingSafeguard areas — auditability & interoperabilityPartly runtime

What the source says

The white paper names safeguards "including policy bound execution, real time validation, auditability and interoperability."

MAS — Safeguards for Agentic Finance at Runtime (SAFR), media release·v1.0, 3 July 2026Primary source

Non-binding (industry white paper under MAS' BuildFin.ai initiative)

Runtime engineering interpretation — our reading, not the source's words

Records must be auditable after the event, and safeguards should interoperate across agents and systems rather than being siloed to one vendor or agent.

Control / evidence implication

Auditable records; safeguard interfaces portable across agents/systems.

Crelis coverage: PartialSAFR-06 · confidence med
NIST AI RMFNon-bindingMANAGE 2.4Runtime

What the source says

"Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use."

NIST AI RMF 1.0 (AI 100-1) — Core, MANAGE 2.4·1.0, January 2023Primary source

Voluntary framework (non-binding)

Runtime engineering interpretation — our reading, not the source's words

A runtime ability to stop an agent — or to withhold authorization for its actions — when its behaviour diverges from intended use.

Control / evidence implication

Recorded disengage / deny events, with the cause that triggered them.

Crelis coverage: PartialNIST-01 · confidence high
NIST AI RMFNon-bindingMANAGE 4.1Runtime

What the source says

"Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management."

NIST AI RMF 1.0 (AI 100-1) — Core, MANAGE 4.1·1.0, January 2023Primary source

Voluntary framework (non-binding)

Runtime engineering interpretation — our reading, not the source's words

Runtime monitoring plus an appeal / override path at the point of action, and a decommissioning route for the system.

Control / evidence implication

Decision telemetry; recorded override and appeal events.

Crelis coverage: PartialNIST-02 · confidence high
NIST AI RMFNon-bindingMEASURE 2.4Runtime

What the source says

"The functionality and behavior of the AI system and its components – as identified in the map function – are monitored when in production."

NIST AI RMF 1.0 (AI 100-1) — Core, MEASURE 2.4·1.0, January 2023Primary source

Voluntary framework (non-binding)

Runtime engineering interpretation — our reading, not the source's words

Continuous monitoring of the agent's behaviour while it is live in production.

Control / evidence implication

Streaming decision / behaviour telemetry from the running system.

Crelis coverage: PartialNIST-03 · confidence high
NIST AI RMFNon-bindingMAP 3.5Partly runtime

What the source says

"Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the govern function."

NIST AI RMF 1.0 (AI 100-1) — Core, MAP 3.5·1.0, January 2023Primary source

Voluntary framework (non-binding)

Runtime engineering interpretation — our reading, not the source's words

Human-oversight processes are defined at design time; the runtime control is where those processes are actually enforced on a live action.

Control / evidence implication

Documented oversight processes, plus records showing they were enforced at runtime.

Crelis coverage: PartialNIST-04 · confidence high
NIST AI RMFNon-bindingMANAGE 4.3Partly runtime

What the source says

"Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented."

NIST AI RMF 1.0 (AI 100-1) — Core, MANAGE 4.3·1.0, January 2023Primary source

Voluntary framework (non-binding)

Runtime engineering interpretation — our reading, not the source's words

Incident detection and communication rely on a trustworthy record of what the agent did; the response process itself is organisational.

Control / evidence implication

Incident records tied to the specific decisions that produced them.

Crelis coverage: AdjacentNIST-05 · confidence med
NIST AI RMFNon-bindingSecurity & identity pillar (NCCoE concept paper)Runtime

What the source says

NIST's AI Agent Standards Initiative identifies the authentication and authorization of autonomous agents as a gap, and its NCCoE concept paper proposes adapting existing identity and authorization frameworks for AI agents that act on behalf of users.

NIST (CAISI) — AI Agent Standards Initiative·Announced 17 February 2026Primary source

Non-binding — announced initiative / concept paper, not a published standard

Runtime engineering interpretation — our reading, not the source's words

Agents that act autonomously need a verifiable identity and a runtime authorization decision for what they are permitted to do on a principal's behalf.

Control / evidence implication

Per-agent identity plus a per-action authorization record.

Crelis coverage: DirectNIST-06 · confidence med
EU AI ActBindingArticle 14 — Human oversightRuntime

What the source says

High-risk AI systems shall be designed so they can be effectively overseen by natural persons, who must be able to "decide... not to use" the system or to "disregard, override or reverse" its output, and to "intervene... or interrupt the system through a 'stop' button or a similar procedure."

EU AI Act — Regulation (EU) 2024/1689, Article 14·OJ 12 Jul 2024; in force 1 Aug 2024Primary source

Binding for high-risk AI systems. Application staged and amended by the Digital Omnibus — see the methodology and the application-date note below.

Runtime engineering interpretation — our reading, not the source's words

A person must be able to intervene at or before execution — to withhold, override, or stop the action the system proposes.

Control / evidence implication

Records of oversight interventions, overrides, and stops.

Crelis coverage: PartialEU-01 · confidence high
EU AI ActBindingArticle 12 — Record-keepingRuntime

What the source says

"High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system." Logging must enable identifying risk situations or substantial modification, post-market monitoring, and monitoring of operation.

EU AI Act — Regulation (EU) 2024/1689, Article 12·OJ 12 Jul 2024; in force 1 Aug 2024Primary source

Binding for high-risk AI systems. Application staged and amended by the Digital Omnibus — see the application-date note below.

Runtime engineering interpretation — our reading, not the source's words

The system automatically records events over its operating life — a logging capability built into operation, not reconstructed afterwards.

Control / evidence implication

Automatic, per-event logs generated during operation.

Crelis coverage: DirectEU-02 · confidence high
EU AI ActBindingArticle 26 — Obligations of deployers of high-risk AI systemsRuntime

What the source says

Deployers "shall assign human oversight to natural persons who have the necessary competence, training and authority"; "shall monitor the operation of the high-risk AI system"; and "shall keep the logs automatically generated by that high-risk AI system... for a period appropriate to the intended purpose..., of at least six months."

EU AI Act — Regulation (EU) 2024/1689, Article 26·OJ 12 Jul 2024; in force 1 Aug 2024Primary source

Binding for deployers of high-risk AI systems. Application staged and amended by the Digital Omnibus — see the application-date note below.

Runtime engineering interpretation — our reading, not the source's words

During operation a competent human oversees the system, its operation is monitored, and the logs it generates are retained for at least six months.

Control / evidence implication

Retained logs (≥ 6 months) and a record of the assigned overseer.

Crelis coverage: PartialEU-03 · confidence high
EU AI ActBindingArticle 50 — Transparency obligations for providers and deployers of certain AI systemsPartly runtime

What the source says

Persons must be informed they are interacting with an AI system; providers must ensure synthetic audio/image/video/text outputs are "marked in a machine-readable format and detectable as artificially generated or manipulated"; deployers must disclose deepfakes.

EU AI Act — Regulation (EU) 2024/1689, Article 50·OJ 12 Jul 2024; in force 1 Aug 2024Primary source

Binding for certain AI systems. Application staged — see the application-date note below.

Runtime engineering interpretation — our reading, not the source's words

Disclosure and content-marking happen at the point of interaction or content generation — a different control surface from authorising an action.

Control / evidence implication

Disclosure and content-marking records.

Crelis coverage: Not addressedEU-05 · confidence high
EU AI ActBindingArticle 9 — Risk management systemNot a runtime control

What the source says

"The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system," requiring regular systematic review and updating.

EU AI Act — Regulation (EU) 2024/1689, Article 9·OJ 12 Jul 2024; in force 1 Aug 2024Primary source

Binding for high-risk AI systems.

Runtime engineering interpretation — our reading, not the source's words

This is a lifecycle governance process, not an execution-time control. It is included here to mark the boundary of what a runtime control does and does not satisfy — a runtime control is one input to this process, not a substitute for it.

Control / evidence implication

Not a runtime control. Runtime records can feed the risk-management process but do not constitute it.

Crelis coverage: Not applicableEU-06 · confidence high
ISO/IEC 42001Non-bindingManagement-system clauses 4–10 (AIMS)Not a runtime control

What the source says

ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining and continually improving an AI management system (AIMS). (Confirmed from ISO's public catalogue entry; the standard text itself is under copyright.)

ISO/IEC 42001:2023 — AI management system (ISO catalogue)·First edition, 2023-12Primary source

Voluntary certifiable standard

Runtime engineering interpretation — our reading, not the source's words

An organisational management system, not an execution-time control. A runtime authorization/evidence control can serve as operational evidence within an AIMS.

Control / evidence implication

Runtime decision records can serve as operational evidence inside an AIMS.

Crelis coverage: AdjacentISO-01 · confidence med

This reference shows only verified mappings. A further 4 candidate rows are held back — 2 pending source review (including the detailed MAS SAFR checkpoint mechanics and ISO/IEC 42001 Annex A control text, which are not reproducible from a primary public source), 1 pending interpretation review, and 1 rejected as not a genuine runtime control. The methodology explains each.

This reference is licensed CC BY 4.0 — reuse with attribution to Crelis. Framework names and texts are the property of their respective authors (MAS, NIST, the EU, ISO/IEC); this is an independent reference to them and implies no endorsement.