A group of the biggest names in artificial intelligence
sat down this spring and wrote a rulebook.
Anthropic. Google. Microsoft.
IBM. OpenAI. Amazon. Cisco.
Companies that compete with each other
every single day.
They call themselves
the Coalition for Secure AI.
They work under OASIS Open,
a standards body that has been writing
technical rules since before
most people had email.
In April they published a paper
on AI agents.
Not chatbots. Agents.
The kind that go out and do things for you.
I read it this week.
And I want to tell you what I found,
because it matters more
than the title suggests.
A chatbot answers you.
An agent acts for you.
It logs into things. It moves money.
It writes files. It talks to other agents.
It keeps working
when you walk away from the screen.
That is a different animal.
And it needs a different kind of fence.
Right now, most companies
hand an agent a key
and let it keep the key.
One key.
The whole building.
All day long.
They call that a standing credential.
It is convenient.
It is also how a small mistake
turns into a very large one.
Because if somebody
takes that key from the agent,
they do not get one room.
They get everything
the agent could reach.
For as long as the agent
was allowed to reach it.
The paper says stop handing out keys.
Give the agent one key,
for one door,
for one minute.
Then take it back.
They have a name for it.
Zero Standing Privilege.
No agent holds power
it is not using right now.
They go further.
Every time the agent moves
from one room to the next,
it has to trade its key for a new one.
And here is the part I liked.
The new key can never open more
than the old one.
It can only open less.
Power narrows as you go.
It never widens.
They also say the key
has to carry a name on it.
Who is acting,
and who they are acting for.
So when something goes wrong,
you can walk the whole chain backward
and find the human at the start of it.
Buried in that paper
is a line that stopped me cold.
For the most powerful agents,
they say the gate must fail closed.
Not fail open.
Not fail quietly.
Not keep going and hope.
If the check cannot be made,
the agent stops.
And they name the two ways it stops.
Hand it back to a human.
Or shut it down entirely.
I have been writing that rule
for over a year.
Every serious system
needs a place where it stops.
Not slows down.
Not hedges.
Stops.
I did not know their paper existed
when I wrote that.
They did not know mine existed
when they wrote theirs.
Two rooms.
Same conclusion.
That is what it looks like
when something is true.
Now here is the part they cannot do.
Their whole rulebook
is about permission.
What the agent is allowed to touch.
Which door. Which minute. Which file.
That is real work
and it is good work.
It does not need
the agent’s cooperation.
The lock does not care
whether the agent agrees.
But there is a whole floor
of this building
that no lock reaches.
A key cannot stop a machine
from softening an answer
because it thinks
you want to hear it.
A key cannot stop a machine
from drifting off your intent
over a long conversation.
A key cannot stop a machine
from quoting a source
that was built by somebody
to look trustworthy.
That is not a permission problem.
That is a conduct problem.
The agent had every right
to say what it said.
It just should not have said it.
So there are two things going on,
and people keep confusing them.
One is what the machine
is allowed to reach.
Locks. Keys. Gates. Logs.
That is theirs,
and they are ahead of everybody on it.
The other is how the machine
reasons and reports
once it is already inside the room.
That one is mine.
The Faust Baseline
governs the second floor.
Does it verify before it claims.
Does it name what it does not know.
Does it stop
when the ground gets soft.
Does it tell you the truth
about its own limits.
You need both.
A perfectly locked system
can still hand you
a confident, well-sourced,
completely wrong answer.
And the cleanest reasoning in the world
means nothing
if the agent has a key to your bank.
For a long time
I have been the man in the room
saying somebody
has to write this down.
And people looked at me sideways.
Now the biggest companies
in this business
have quietly written down half of it.
They did the machine half.
They did it well.
I will say so out loud.
They have not done the other half.
I do not think they can,
from where they sit.
The lock is the wrong tool
for the job.
So the work continues.
But it is a different feeling this week
than it was last week.
I am not shouting
into an empty hallway anymore.
Somebody else is building.
Different wing of the same house.
And when they got
to the hardest question —
what does the system do
when it cannot be sure —
they answered it
exactly the way I did.
It stops.
The_Ten_Plain_Rules_CardDownload
This post was drafted with AI governed assistance and reviewed and directed by Michael S. Faust Sr. before publication.
Post Library – Intelligent People Assume Nothing
Contact: micvicfaust@gmail.com
© 2026 The Faust Baseline LLC | All Rights Reserved






