← Blog

A standard is forming for what agents do. We were on the right track.

An Internet-Draft is proposing a standard for AI-agent action receipts. It maps closely to the governance we already run.

August 22, 20262 min readAgent Anything
governancestandardsietfattexareceiptsai agents

Governance is converging on the AI action receipt. A signed record of what an agent did is one part of the answer. Whether anyone but the vendor can check it is the part that decides a dispute.

An Internet-Draft now before the IETF, building on the IETF's own SCITT architecture, proposes a standard for AI-agent action receipts: a signed, tamper-evident, offline-verifiable record of what an autonomous agent did at the moment it acted. Signed records, canonical formatting, hash-chained so each one commits to the one before it. A cluster of adjacent drafts is forming around it.

It is also the shape of AI-agent governance we have been building in Attexa Witness and Verified Actions. The open protocol we published already extended from memory to action in its v0.2 draft of Memory Pod Fabric: capability-gated intent grants, witness-attested execution, receipt chains anyone can verify.

Our AI governance layer does two things. Attexa Verified Actions governs the consequential action at the boundary: what the agent is allowed to do, who stood behind it, whether a human approved it before it ran. Attexa Witness turns the result into evidence a third party can check against a key the customer holds, not against our word for it.

A standard forming is good for us and good for the market. It makes the category legible. It gives buyers a name for the thing they have been struggling to ask for. It turns an argument we used to make alone into one the industry is now making with us.

We think the record is the beginning of the answer, not the end of it. Even a perfect receipt only covers what happens after an agent already believes it was told to act. It says nothing about whether the instruction it received actually carried authority from someone able to give it, right now, not an hour ago and not a year ago on a credential nobody got around to revoking.

That is a different boundary, upstream of everything a receipt describes, and it is a problem we have been working on in its own right: not what did the agent do, but did the signal that told it to act come from someone who could still say yes in that moment.

Get in touch

Want to talk through how this applies to your organization?

Request access