Agent Control Standard: an open spec for blocking agent actions
A shared spec puts a permit, deny or modify decision in front of every agent action.
· OWASP GenAI Security Project · Research by Rock Lambros (Zenity), Michael Bargury (Zenity)

The Agent Control Standard is an open specification, now hosted by the OWASP GenAI Security Project, that lets a guardian agent permit, deny or modify an AI agent's tool calls and other actions before they run.
01What happened
The Agent Control Standard (ACS) moved to the OWASP GenAI Security Project, as announced by Rock Lambros on September 10, 2026. ACS grew out of the Agent Observability Standard and was co-created by Michael Bargury, CTO of Zenity.
02How it works
An observed agent exposes hooks at key points: user input, tool calls, knowledge retrieval, memory writes, code execution and sub-agent calls. A separate guardian agent receives each event and returns a verdict to permit, deny or modify it before it runs. Version 0.1 ships documentation, requirements, schemas, OpenTelemetry and OCSF definitions and Agent Bill of Materials requirements, and runtime enforcement across platforms is still on the roadmap.
03Who is affected
Teams building or securing AI agents that want one vendor-neutral way to observe and gate agent actions.
04What to do
Review the spec and schemas on GitHub if you are designing agent guardrails or audit logging, and consider mapping your hooks to it.
Sources 2 links, all fetched
- 1labs.zenity.ioZenity Announcement
- 2github.comACS on GitHub