Machine intelligence · Agentic AI · Governed swarm management

Standards and policy library

Standards, protocols, and policy for governed machine intelligence

A standards citation is not a runtime control. This library translates authoritative frameworks, protocols, and policy sources into the evidence, architecture, ownership, and review decisions required for governed agentic systems.

EnterpriseGovernmentPartners

Published Updated Reviewed By LongTermIntelligence.com

Direct answer

How should an enterprise use AI standards and protocols?

#

Use standards and protocols as distinct inputs to an operating system: frameworks organize risk outcomes, management-system standards define organizational disciplines, security taxonomies identify threat classes, protocols define interoperability, telemetry conventions define observability fields, and policy sources create role-specific obligations. None of them replaces architecture, ownership, testing, evidence, or qualified review.

  • Name the exact source, version, and reviewed date.
  • Map each requirement or recommendation to an owner, control, artifact, and decision.
  • Separate voluntary guidance, contractual obligations, regulatory duties, and certification claims.

Source basis: reviewed official references are listed on this page and in the source ledger. Interpretation and implementation guidance retain the stated assurance boundary.

Source types

Eight guides, eight different jobs

The important distinction is what each source governs—and what it does not.

Risk framework

NIST AI RMF

Organizes voluntary risk-management outcomes around Govern, Map, Measure, and Manage.

Review the framework

GenAI profile

NIST AI 600-1

Extends the AI RMF with risks and actions specific to or intensified by generative AI.

Review the profile

Management system

ISO/IEC 42001

Defines requirements for establishing, maintaining, evaluating, and improving an AI management system.

Review the standard

Security taxonomy

OWASP Agentic Top 10

Provides a shared vocabulary for major agentic application risk areas and mitigations.

Review the risks

Interoperability

Model Context Protocol

Standardizes how model applications connect with resources, prompts, and tools.

Review MCP

Telemetry

OpenTelemetry GenAI

Defines interoperable observability signals for model and tool operations.

Review telemetry

Regulation

EU AI Act

Creates a risk-based legal framework whose obligations and dates depend on role and system scope.

Review current timing

Federal policy

OMB M-25-21

Current guidance for covered U.S. federal agency AI use, replacing M-24-10.

Review federal policy

Do not collapse the layers

What each source can and cannot establish

A credible assurance record identifies the source type before making a claim.

Source typeUseful forDoes not establish by itself
Risk frameworkOutcomes, risk vocabulary, governance structureCertification, legal compliance, or implementation quality
Management-system standardOrganization-wide policies, processes, monitoring, continual improvementCertification unless an authorized audit process is completed
Security taxonomyThreat identification, threat modeling, mitigation planningComplete security coverage or a penetration-test result
Protocol specificationInteroperable messages, roles, and capabilitiesAuthorization policy, business approval, evaluation, recovery, or safe deployment
Telemetry conventionPortable traces, metrics, events, and attributesCorrectness, policy enforcement, redaction, or incident response
Law or policyObligations or directives for covered roles and usesUniversal applicability outside its scope or legal advice

Primary-source basis

Official references

Use the named primary sources for current definitions, dates, versions, and scope.

National Institute of Standards and Technology · Official Framework Hub

NIST AI Risk Management Framework

NIST's voluntary framework for incorporating trustworthiness considerations into the design, development, use, and evaluation of AI systems.

Status
Current With Revision Underway
Published
2023-01-26
Reviewed
2026-08-01

Use boundary: Use as risk-management guidance; do not describe alignment as certification or legal compliance.

Open official source

National Institute of Standards and Technology · Official Profile

NIST AI 600-1: Generative AI Profile

A cross-sectoral companion profile for applying the AI RMF to risks that are distinctive to or intensified by generative AI.

Status
Current
Published
2024-07-26
Reviewed
2026-08-01

Use boundary: Use as a companion profile, not as proof that an implementation is compliant or safe.

Open official source

International Organization for Standardization · Official Standard Page

ISO/IEC 42001:2023 — AI management systems

Requirements and guidance for establishing, implementing, maintaining, and continually improving an AI management system within an organization.

Status
Current
Published
2023-12
Reviewed
2026-08-01

Use boundary: Do not claim certification unless an accredited audit and certification process has been completed.

Open official source

OWASP GenAI Security Project · Official Security Taxonomy

OWASP Top 10 for Agentic Applications

A community-developed taxonomy covering ten major agentic application risk areas, from goal hijacking and tool misuse through memory poisoning, cascading failures, and rogue agents.

Status
Current
Published
2025-12-09
Reviewed
2026-08-01

Use boundary: Use as a threat-oriented taxonomy and mitigation aid, not as a certification or guarantee of security.

Open official source

Model Context Protocol · Official Protocol Specification

Model Context Protocol Specification — 2026-07-28

The reviewed MCP specification defines an open protocol for connecting language-model applications with contextual resources, prompts, and tools through host, client, and server roles.

Status
Current Reviewed Version
Published
2026-07-28
Reviewed
2026-08-01

Use boundary: MCP is an interoperability protocol, not a complete agentic control plane, governance program, or security guarantee.

Open official source

OpenTelemetry · Official Specification Hub

OpenTelemetry semantic conventions for generative AI systems

Official semantic-convention material for interoperable telemetry describing generative AI operations.

Status
Evolving
Reviewed
2026-08-01

Use boundary: Record the exact convention version implemented because names and stability levels can evolve.

Open official source

European Commission · Official Regulatory Overview

EU AI Act regulatory framework overview

The European Commission's overview of the AI Act, its risk-based framework, application stages, and implementation resources.

Status
Current
Reviewed
2026-08-01

Use boundary: This is general information, not legal advice; confirm which obligations and dates apply to a specific system and role.

Open official source

European Commission · Official Regulatory Update

AI Omnibus enters into force

The Commission's July 2026 update on the AI Omnibus and amended timing for parts of the AI Act implementation timetable.

Status
Current
Published
2026-07-27
Reviewed
2026-08-01

Use boundary: Use the amended dates rather than older summaries; obtain legal advice for application to a specific organization or system.

Open official source

Executive Office of the President, Office of Management and Budget · Official Federal Policy

OMB Memorandum M-25-21

Federal agency guidance issued April 3, 2025, that rescinds and replaces OMB Memorandum M-24-10 and establishes requirements for agency AI innovation, governance, transparency, and high-impact AI risk management.

Status
Current
Published
2025-04-03
Reviewed
2026-08-01

Use boundary: Applies to covered federal agency use; it is not a universal private-sector compliance standard.

Open official source

Official-source citations establish provenance and scope. They do not establish LongTermIntelligence.com certification, endorsement, legal advice, client outcomes, or a guarantee that a control is effective.

Private local search

Find machine intelligence, agentic AI, swarm management, services, industries, use cases, definitions, or research

Press / to open search when focus is not in a form field.

Search runs locally against the public site index.