A group of the biggest names in artificial intelligence

sat down this spring and wrote a rulebook.

Anthropic. Google. Microsoft.

IBM. OpenAI. Amazon. Cisco.

Companies that compete with each other

every single day.

They call themselves

the Coalition for Secure AI.

They work under OASIS Open,

a standards body that has been writing

technical rules since before

most people had email.

In April they published a paper

on AI agents.

Not chatbots. Agents.

The kind that go out and do things for you.

I read it this week.

And I want to tell you what I found,

because it matters more

than the title suggests.

A chatbot answers you.

An agent acts for you.

It logs into things. It moves money.

It writes files. It talks to other agents.

It keeps working

when you walk away from the screen.

That is a different animal.

And it needs a different kind of fence.

Right now, most companies

hand an agent a key

and let it keep the key.

One key.

The whole building.

All day long.

They call that a standing credential.

It is convenient.

It is also how a small mistake

turns into a very large one.

Because if somebody

takes that key from the agent,

they do not get one room.

They get everything

the agent could reach.

For as long as the agent

was allowed to reach it.

The paper says stop handing out keys.

Give the agent one key,

for one door,

for one minute.

Then take it back.

They have a name for it.

Zero Standing Privilege.

No agent holds power

it is not using right now.

They go further.

Every time the agent moves

from one room to the next,

it has to trade its key for a new one.

And here is the part I liked.

The new key can never open more

than the old one.

It can only open less.

Power narrows as you go.

It never widens.

They also say the key

has to carry a name on it.

Who is acting,

and who they are acting for.

So when something goes wrong,

you can walk the whole chain backward

and find the human at the start of it.

Buried in that paper

is a line that stopped me cold.

For the most powerful agents,

they say the gate must fail closed.

Not fail open.

Not fail quietly.

Not keep going and hope.

If the check cannot be made,

the agent stops.

And they name the two ways it stops.

Hand it back to a human.

Or shut it down entirely.

I have been writing that rule

for over a year.

Every serious system

needs a place where it stops.

Not slows down.

Not hedges.

Stops.

I did not know their paper existed

when I wrote that.

They did not know mine existed

when they wrote theirs.

Two rooms.

Same conclusion.

That is what it looks like

when something is true.

Now here is the part they cannot do.

Their whole rulebook

is about permission.

What the agent is allowed to touch.

Which door. Which minute. Which file.

That is real work

and it is good work.

It does not need

the agent’s cooperation.

The lock does not care

whether the agent agrees.

But there is a whole floor

of this building

that no lock reaches.

A key cannot stop a machine

from softening an answer

because it thinks

you want to hear it.

A key cannot stop a machine

from drifting off your intent

over a long conversation.

A key cannot stop a machine

from quoting a source

that was built by somebody

to look trustworthy.

That is not a permission problem.

That is a conduct problem.

The agent had every right

to say what it said.

It just should not have said it.

So there are two things going on,

and people keep confusing them.

One is what the machine

is allowed to reach.

Locks. Keys. Gates. Logs.

That is theirs,

and they are ahead of everybody on it.

The other is how the machine

reasons and reports

once it is already inside the room.

That one is mine.

The Faust Baseline

governs the second floor.

Does it verify before it claims.

Does it name what it does not know.

Does it stop

when the ground gets soft.

Does it tell you the truth

about its own limits.

You need both.

A perfectly locked system

can still hand you

a confident, well-sourced,

completely wrong answer.

And the cleanest reasoning in the world

means nothing

if the agent has a key to your bank.

For a long time

I have been the man in the room

saying somebody

has to write this down.

And people looked at me sideways.

Now the biggest companies

in this business

have quietly written down half of it.

They did the machine half.

They did it well.

I will say so out loud.

They have not done the other half.

I do not think they can,

from where they sit.

The lock is the wrong tool

for the job.

So the work continues.

But it is a different feeling this week

than it was last week.

I am not shouting

into an empty hallway anymore.

Somebody else is building.

Different wing of the same house.

And when they got

to the hardest question —

what does the system do

when it cannot be sure —

they answered it

exactly the way I did.

It stops.


The_Ten_Plain_Rules_CardDownload

This post was drafted with AI governed assistance and reviewed and directed by Michael S. Faust Sr. before publication.

Post Library – Intelligent People Assume Nothing

Contact: micvicfaust@gmail.com

© 2026 The Faust Baseline LLC | All Rights Reserved

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *