Agent Compliance and Regulation
Agent compliance is proving that an agent acted within law and policy — not by promising it will, but by bounding what it may do and recording what it did. Compliance is demonstrated from the record: who authorised an action, which policy governed it, and what happened. An agent whose actions cannot be reconstructed is non-compliant by default, because "the system decided" satisfies no regulator and no auditor.
Compliance is a record, not a promise
Regulators do not accept intentions; they accept evidence. The compliant pattern is to encode the rule in the policy plane, bound the agent’s authority to it, and record every action with its basis — so compliance is something you show from the log rather than something you assert in a policy document nobody can check.
Questions
Can an agent make a regulated decision?
It can apply a stated rule and recommend; adverse or high-stakes decisions escalate to an accountable human, with the agent’s basis recorded for review.
What does an auditor look at?
The record: the authority behind each action and the policy that governed it — which is why the record, not the model, is the compliance artifact.
Where this lives in the estate
FlashyOS — policy plane and record as the compliance artifacts
Keep reading
By Michael Gord · published 2026-10-04 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.