Mission Authorization
4 controls / 3 MUST
Version 1.0 — Technical Report CGP-2026-001
DOI 10.5281/zenodo.21045760
Existing AI governance frameworks — the EU AI Act, the NIST AI Risk Management Framework (AI RMF), and ISO/IEC 42001 — were designed for AI systems operating under continuous human supervision: classifiers, recommenders, and single-turn generators. None were designed for agentic AI systems that autonomously decompose goals into multi-step plans, execute sequences of environment-modifying actions, coordinate multiple specialized sub-agents, and maintain state across sessions. Singapore's Model AI Governance Framework (January 2026) is the only published governance document that acknowledges this gap, identifying three unaddressed risks: cascading failure propagation, emergent scope expansion, and attribution gaps across agent chains.
This document introduces the Cyryx Governance Protocol (CGP) v1.0, a technical framework that fills these gaps with seven control domains and twenty-eight normative controls (MUST/SHOULD/MAY). CGP is designed as an extension to existing frameworks — not a replacement — with explicit mapping to EU AI Act Articles 9, 12, 13, 14, and 15; NIST AI RMF functions GOVERN, MAP, MEASURE, and MANAGE; and ISO 42001 Clause 6, 7, 8, and 9 controls. Every control in CGP v1.0 has a reference implementation in MAAX Studio by Cyryx Labs. CGP is published under Creative Commons Attribution 4.0 (CC BY 4.0) for open community adoption and review.
CGP is presented as an extension to existing governance frameworks, with explicit operating controls for agentic execution.
4 controls / 3 MUST
4 controls / 4 MUST
4 controls / 3 MUST
4 controls / 3 MUST
4 controls / 4 MUST
4 controls / 4 MUST
5 controls / 4 MUST
The paper maps each CGP domain to relevant provisions in the EU AI Act, NIST AI RMF, and ISO/IEC 42001.
| CGP domain | EU AI Act | NIST AI RMF | ISO/IEC 42001 |
|---|---|---|---|
| CD1 — Mission Authorization | Art. 14, Art. 9 | GOVERN 1.1, MAP 1.5 | Clause 6.1, Annex A-6.2 |
| CD2 — Scope Boundary | Art. 9, Art. 13 | MAP 3.5, MEASURE 2.5 | Annex A-8.4, Clause 8.1 |
| CD3 — Checkpoint Integrity | Art. 9.4 | MANAGE 2.2, MANAGE 3.1 | Annex A-8.5, Annex A-9.1 |
| CD4 — Command Gates | Art. 9, Art. 15 | MEASURE 2.1, MEASURE 2.3 | Annex A-8.3, Annex A-8.6 |
| CD5 — Decision Attribution | Art. 12, Art. 14.4 | GOVERN 6.1, GOVERN 6.2 | Annex A-8.2, Clause 7.5 |
| CD6 — Evidence Chain | Art. 12, Art. 17 | GOVERN 6.2, MEASURE 2.8 | Clause 9.1, Annex A-8.7 |
| CD7 — Cost Governance | Not explicitly addressed | GOVERN 4.1, MANAGE 4.1 | Annex A-8.4, Clause 9.1 |
All MUST controls in CD1, CD3, CD5, and CD6
All MUST controls across all seven domains
All MUST and SHOULD controls plus third-party review
These levels describe protocol requirements. CGP v1.0 is not a third-party certification or an independent compliance determination.
Suggested citation
CYRYX Labs. (2026). CGP: Cyryx Governance Protocol for Agentic AI Execution (Version 1.0, Technical Report CGP-2026-001). Cyryx Labs LLC, United States of America. https://doi.org/10.5281/zenodo.21045760