Cyryx Labs
Applied Research
Governance / CGP-2026-001

CGP: Cyryx Governance Protocol for Agentic AI Execution

Version 1.0 — Technical Report CGP-2026-001

Published
June 29, 2026
Version
1.0
Author
CYRYX Labs
License
CC BY 4.0
Evidence states

Publication is not implementation, conformance, or certification.

verified

Publication record

The Zenodo record, bibliographic metadata, DOI, source file, publication date, and license were reviewed for this release.

Reviewed 2026-08-03

qualified

Current implementation

No current, reviewable implementation package is linked here for every protocol control. The publication abstract is not implementation evidence.

qualified

Protocol conformance

CGP levels define protocol requirements. This page does not assert that MAAX Studio or a client system currently meets a level.

withheld

Third-party certification

No third-party CGP certification or independent compliance determination is claimed.

Website summary of the publication

DOI 10.5281/zenodo.21045760

Existing AI governance frameworks — the EU AI Act, the NIST AI Risk Management Framework (AI RMF), and ISO/IEC 42001 — were designed for AI systems operating under continuous human supervision: classifiers, recommenders, and single-turn generators. None were designed for agentic AI systems that autonomously decompose goals into multi-step plans, execute sequences of environment-modifying actions, coordinate multiple specialized sub-agents, and maintain state across sessions. Singapore's Model AI Governance Framework (January 2026) is the only published governance document that acknowledges this gap, identifying three unaddressed risks: cascading failure propagation, emergent scope expansion, and attribution gaps across agent chains.

This document introduces the Cyryx Governance Protocol (CGP) v1.0, a technical framework with seven control domains and twenty-eight normative controls (MUST/SHOULD/MAY). CGP is presented as an extension to existing frameworks — not a replacement — with mappings to selected provisions in the EU AI Act, NIST AI RMF, and ISO/IEC 42001. The published abstract includes author assertions about MAAX Studio implementation; this website does not treat those assertions as current implementation, conformance, certification, or client-outcome evidence. CGP is published under Creative Commons Attribution 4.0 (CC BY 4.0) for open community adoption and review.

agentic AIAI governanceEU AI ActNIST AI RMFISO 42001autonomous agentsgoverned execution
Protocol architecture

Seven control domains. Twenty-eight normative controls.

CGP is presented as an extension to existing governance frameworks, with explicit operating controls for agentic execution.

CD1

Mission Authorization

4 controls / 3 MUST

CD2

Scope Boundary Enforcement

4 controls / 4 MUST

CD3

Checkpoint Integrity

4 controls / 3 MUST

CD4

Command Gate System

4 controls / 3 MUST

CD5

Decision Attribution

4 controls / 4 MUST

CD6

Evidence Chain

4 controls / 4 MUST

CD7

Cost Governance

5 controls / 4 MUST

Framework mapping

Designed to extend, not replace.

The paper maps each CGP domain to relevant provisions in the EU AI Act, NIST AI RMF, and ISO/IEC 42001.

CGP domainEU AI ActNIST AI RMFISO/IEC 42001
CD1 — Mission AuthorizationArt. 14, Art. 9GOVERN 1.1, MAP 1.5Clause 6.1, Annex A-6.2
CD2 — Scope BoundaryArt. 9, Art. 13MAP 3.5, MEASURE 2.5Annex A-8.4, Clause 8.1
CD3 — Checkpoint IntegrityArt. 9.4MANAGE 2.2, MANAGE 3.1Annex A-8.5, Annex A-9.1
CD4 — Command GatesArt. 9, Art. 15MEASURE 2.1, MEASURE 2.3Annex A-8.3, Annex A-8.6
CD5 — Decision AttributionArt. 12, Art. 14.4GOVERN 6.1, GOVERN 6.2Annex A-8.2, Clause 7.5
CD6 — Evidence ChainArt. 12, Art. 17GOVERN 6.2, MEASURE 2.8Clause 9.1, Annex A-8.7
CD7 — Cost GovernanceNot explicitly addressedGOVERN 4.1, MANAGE 4.1Annex A-8.4, Clause 9.1
Conformance model
CGP-L1 / Baseline

Agentic Baseline

All MUST controls in CD1, CD3, CD5, and CD6

CGP-L2 / Governed

Governed Execution

All MUST controls across all seven domains

CGP-L3 / Enterprise

Enterprise Agentic Governance

All MUST and SHOULD controls plus third-party review

These levels describe protocol requirements. CGP v1.0 is not a third-party certification or an independent compliance determination.

Publication record

Open, citable, versioned.

License
CC BY 4.0

Suggested citation

CYRYX Labs. (2026). CGP: Cyryx Governance Protocol for Agentic AI Execution (Version 1.0, Technical Report CGP-2026-001). Cyryx Labs LLC, United States of America. https://doi.org/10.5281/zenodo.21045760