Build1 distinct publisher3 min readPublished
The library maps to ISO 27001 and 42001 rather than asking for a new certificate, which is why trying it costs a scoping meeting. The 22 buyer-side controls are the half that will end up in vendor questionnaires.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Mapping into ISO 27001 and ISO 42001 does a specific job [3]. When an auditor asks how access control applies to software that selects its own tools at runtime, you hand over a control that names agent identity, authority, action guardrails and memory protection, along with the evidence that control expects to see [5]. The stated design principle, set by Vanta CEO Christina Cacioppo, is to avoid publishing a fifteenth framework and instead ship technology-specific controls that bolt onto ISO programs already in flight [8]. Errico's case for the open comment period comes from the same place: agent risk becomes concrete around delegation chains, credential scopes and the systems an agent can reach, and a control written by someone who has watched an agent fail in production is likelier to name evidence that can actually be collected [24].
The yield, counted in rows, is small. Early access was 61 controls across 12 domains, 40 for builders and 21 for users [9]. The builder baseline gained three and the user baseline one [19]. That is roughly 88 contributions per net new control [20]. The source does not say whether the rest landed as rewrites, tightened evidence requirements, or rejections, so the contribution total is not a count of inspectable changes.
The control count is a claim about someone else's audit scope, and two things have to be true before the buyer half does work in yours. Your auditor has to accept the mapping as evidence for the annex control it points at. Your vendor has to answer for inventories, credentials, vendor reviews, monitoring, oversight responsibilities and training on an agent whose internals you cannot inspect [6]. The second condition decides whether those 22 controls become a questionnaire with teeth or a filing exercise.
According to runtimewire, the library establishes what to govern and document and does not appear to include the layer that stops a prohibited action mid-run [13]. A control can require restricted tool access, runtime monitoring or human approval; making the requirement bite still needs identity infrastructure, a policy gateway or monitoring software [14]. The Cloud Security Alliance's AARM working group is drafting the vendor-neutral version of that layer, scoped to excessive privileges, prompt injection, irreversible actions and threats that only emerge across a sequence of individually permitted steps [15]. The last category is the interesting one, because a per-call policy check by construction cannot see it.
The enforcement layer already has sellers. WitnessAI released Agentic Control on June 17 to discover agents and Model Context Protocol servers, apply approved-tool policies and block activity at runtime [16]. NeuralTrust sells gateways, runtime security and agent inventory software, and has announced a $20 million round [17]. Runtimewire reads the release as Vanta defining the checklist enterprises may use to buy and audit agents while runtime vendors compete to enforce the rules [18]. Free controls are a cheap way to define the shape of the thing everyone else has to enforce.
If you already run an ISO 42001 program, evaluating this costs a scoping meeting and an afternoon with the buyer baseline. That price is low enough that the checklist question gets settled by whoever published first.
Ranked by verification strength, evidence, and original report placement.
Herman Errico, a product-security researcher at Vanta, moved Agentic Trust Controls into general availability with 65 open-source controls for organizations building or deploying AI agents.
The late-August release expands the 61-control early-access version Vanta opened in July.
The general-availability library maps to ISO 27001 and ISO 42001, with SOC 2 and NIST Cybersecurity Framework mappings planned.
The general-availability library contains 43 controls for developers and 22 for organizations deploying agents made by outside vendors.
The developer baseline covers areas such as agent identity, authority, action guardrails, memory protection, instruction integrity, adversarial testing and runtime instrumentation.
The user baseline addresses agent inventories, credentials, vendor reviews, monitoring, oversight responsibilities and staff training.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Anthropic's Compliance API now logs the Claude Code sessions running on inherited developer credentials1 distinct publisher
leadership
Enterprise security reviews went from 20 questions to hundreds of rows, and vendors pay first1 distinct publisher
build
Your change-management evidence assumes a human. Claude does not sign commits.1 distinct publisher
invest
Kraken's parent now runs a security model that Washington can switch off1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Issuer-reported, single relay
Count the independent sources and you get one: Runtimewire, reading Vanta's own posts. The 65 controls, the 43-and-22 split, the ISO 27001 and 42001 mappings are all issuer statements about a library anyone could open and count, and nobody in this reporting has counted it. Vanta's participation figures contradict each other across its own updates, which Runtimewire flags rather than smooths over — candour that raises the floor here without substituting for outside confirmation.
Published, not yet in anyone's program
Two hundred and thirty people commenting on a draft is review interest, not adoption. No organization is named as having folded these controls into an ISO program, no auditor is quoted accepting them as evidence, and no procurement questionnaire is shown containing the 22 buyer-side items. The only things in this story you can actually buy and run belong to other companies — WitnessAI's runtime blocker and NeuralTrust's gateways.
Ambition slightly ahead of the record
The framing reaches: Runtimewire opens by telling you Vanta may be writing the checklist enterprises use to buy and audit agents, on the strength of a free list at general availability with no identified user. What keeps the gap small is that the same piece dismantles its own strongest reading — a checklist cannot stop an action mid-run, the enforcement specification is still a working-group draft, and SOC 2 and NIST mappings are promises. The overstatement is in the category-defining verb, not in the numbers.
Free standard, paid adjacency
Vanta hands out the controls and sells the software that administers controls and collects their evidence; a library that becomes the default set of agent questions routes those requirements into the paid product without Vanta ever pricing the standard. Runtimewire states the surrounding arithmetic plainly — an internal project, not a venture, backed by a $150 million Series D at a $4.15 billion valuation. The named enforcement vendors carry their own interest in where the line between paperwork and runtime gets drawn.
Checkable, and unchecked
These are claims anyone could settle in an afternoon — clone the library, count the controls, read the ISO mappings — which is why the confidence sits mid-range rather than low. It does not sit higher because the assessment leans on one outlet relaying one company, and the single number Vanta published twice came out differently both times. The forward-looking parts, the promised SOC 2 and NIST mappings and the runtime specification, are unresolved by construction.