I-D Action: draft-marques-asqav-compliance-receipts-07.txt

[email protected]
Newsgroups gmane.ietf.announce
Message-ID <178455611324.180215.13801606819185934004@dt-datatracker-d4d6ff9d9-ql5mb>
Internet-Draft draft-marques-asqav-compliance-receipts-07.txt is now
available.

   Title:   Compliance Profile of Signed Action Receipts for AI Agents
   Author:  Joao Andre Gomes Marques
   Name:    draft-marques-asqav-compliance-receipts-07.txt
   Pages:   106
   Dates:   2026-07-20

Abstract:

   This document defines a multi-jurisdiction compliance profile of the
   signed action receipt format used by AI agents to record machine-
   readable evidence of access-control decisions.  The profile binds
   receipt fields to two regulatory surfaces: on the European Union
   side, Articles 12 and 26 of the EU AI Act (Regulation (EU) 2024/1689)
   and Article 17 of DORA (Regulation (EU) 2022/2554); on the United
   States side, the NIST AI Risk Management Framework, the Colorado AI
   Act, the Texas Responsible AI Governance Act, the New York Department
   of Financial Services Cybersecurity Regulation (23 NYCRR Part 500),
   the HIPAA Security Rule, SEC Rule 17a-4, and the Cyber Incident
   Reporting for Critical Infrastructure Act of 2022 (CIRCIA).  Working
   entirely within the existing wire format, canonicalization
   transformation, and signing algorithms of the underlying receipt
   format, the profile tightens a subset of the OPTIONAL fields to
   REQUIRED, imposes a retention floor, and requires at least one
   timestamping anchor (RFC 3161 or OpenTimestamps).  It registers
   OPTIONAL extension fields for risk and incident classification,
   cross-agent envelope binding, per-action freshness and integrity,
   build provenance, threat-framework taxonomy, server-built enforcement
   attestation, producer-asserted risk acceptance, and producer-asserted
   code authorship, each subject to false-attestation guards where
   applicable, and registers receipt type namespaces for passive-
   telemetry, result-bound observation, risk-acceptance, and code-
   authorship receipts.  The full field set and its normative
   requirements are defined in the body of this document.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-marques-asqav-compliance-receipts/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-marques-asqav-compliance-receipts-07.html

A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-marques-asqav-compliance-receipts-07

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.