Widescale adoption of AI agents depends on trust, and trust requires transparency and control. Enterprises cannot rely on black-box agents operating across cloud, SaaS, on-premises and endpoint environments. Agents must be inspectable, traceable and instrumentable—providing visibility into what they are, what they can access, what they did and why, and the ability to control their behavior at runtime.
Now part of the OWASP GenAI Security Project. The Agent Control Standard (ACS) provides the open foundation for putting these principles into practice. It defines how agent platforms expose middleware hooks and how safety policies can be enforced through them, enabling declarative controls that are portable across agent frameworks and enforced at runtime. Together, transparency and standardized control provide the foundation for trustworthy agents at enterprise scale.
