# Agent Control Standard: an open spec for blocking agent actions

> A shared spec puts a permit, deny or modify decision in front of every agent action.

- **Severity:** Info: Research, tools, evals or lab claims with no direct exposure. Context, not an alert.
- **Category:** Tool
- **Published by:** OWASP GenAI Security Project
- **Disclosed:** 2026-09-10
- **Research by:** Rock Lambros (Zenity), Michael Bargury (Zenity)
- **Primary source:** https://labs.zenity.io/post/the-agent-control-standard-lands-at-owasp
- **Page:** https://theinjection.dev/items/owasp-agent-control-standard/

The Agent Control Standard is an open specification, now hosted by the OWASP GenAI Security Project, that lets a guardian agent permit, deny or modify an AI agent's tool calls and other actions before they run.

## What happened

The Agent Control Standard (ACS) moved to the OWASP GenAI Security Project, as announced by Rock Lambros on September 10, 2026. ACS grew out of the Agent Observability Standard and was co-created by Michael Bargury, CTO of Zenity.

## How it works

An observed agent exposes hooks at key points: user input, tool calls, knowledge retrieval, memory writes, code execution and sub-agent calls. A separate guardian agent receives each event and returns a verdict to permit, deny or modify it before it runs. Version 0.1 ships documentation, requirements, schemas, OpenTelemetry and OCSF definitions and Agent Bill of Materials requirements, and runtime enforcement across platforms is still on the roadmap.

## Who is affected

Teams building or securing AI agents that want one vendor-neutral way to observe and gate agent actions.

## What to do

Review the spec and schemas on GitHub if you are designing agent guardrails or audit logging, and consider mapping your hooks to it.

## Sources

1. [Zenity Announcement](https://labs.zenity.io/post/the-agent-control-standard-lands-at-owasp)
2. [ACS on GitHub](https://github.com/genai-security-project/agent-control-standard/)
