Proposed Governance Norms and Minimum Organizational Competencies
A technology-neutral discussion draft contributed to the American Bar Association’s Autonomous Systems Governance Working Group (ASG-WG), proposing ten governance norms and a corresponding baseline of organizational competencies for responsible governance of autonomous and agentic systems.
American Bar Association Autonomous Systems Governance Working Group
The American Bar Association’s Autonomous Systems Governance Working Group (ASG-WG) held its inaugural session on April 17, 2026, in Atlanta. Co-chaired by Tim Reiniger and Prof. Jon Garon, the Working Group brings together legal practitioners, technologists, academics, policymakers, industry representatives, and other stakeholders to examine the legal, ethical, regulatory, and operational issues presented by autonomous and AI-enabled systems.
The ASG-WG is a joint effort of the SciTech Risk and Trust Management Committee and the Cyber and Technology Committee of the ABA Business Law Section. The organizers also invite broader collaboration with related ABA sections and committees as well as external organizations.
The Working Group aligns with and advances the objectives of ABA Resolution 604 (2023), which calls on developers and users of artificial intelligence to address human control, human and legal-person responsibility for consequences, and transparency and traceability of autonomous decision-making and actions.
The ASG-WG opened with a foundational concern from industry: legal frameworks are urgently needed to provide practical guidance for governing autonomous systems as those systems become capable of increasingly independent and consequential action.
A Governance Baseline for Systems Capable of Consequential Action
Autonomous and AI-enabled systems increasingly do more than generate information. When connected to tools, workflows, services, and operational systems, they can recommend, propose, coordinate, authorize, initiate, or execute actions with legal, financial, operational, safety, privacy, or cybersecurity consequences.
This discussion draft proposes a technology-neutral and risk-proportionate governance baseline for those environments. Its purpose is to support discussion of the minimum outcomes that governed systems should achieve and the minimum capabilities organizations should possess to make those outcomes real.
The contribution was developed for the American Bar Association’s Autonomous Systems Governance Working Group, a joint effort of the SciTech Risk and Trust Management Committee and the Cyber and Technology Committee of the Business Law Section. The Working Group brings legal, technical, academic, policy, and industry perspectives together around governance of autonomous and AI-enabled systems.
The proposed framework is particularly aligned with the objectives reflected in ABA Resolution 604 (2023): maintaining human control, preserving responsibility of human beings and legal persons for consequences, and supporting transparency and traceability of autonomous decision-making and actions.
The draft does not require one attorney, engineer, risk professional, executive, or other participant to possess every competency. Instead, it treats governance competency as an organizational capability that may be distributed across legal, technical, risk, data, assurance, security, audit, operations, and leadership functions.
Norms, Competencies, Controls, and Evidence Are Different Things
A central feature of the discussion draft is the distinction between the governance outcome an organization seeks and the capability, mechanisms, and evidence needed to achieve it.
Norm
An expected governance outcome, behavior, or condition that a governed system and responsible organization should achieve.
Competency
A demonstrable organizational capability to achieve, sustain, assess, or improve a governance outcome within a defined functional domain.
Control
A legal, organizational, procedural, or technical mechanism used to implement or support a competency and its associated governance norm.
Evidence
Information demonstrating that accountability is assigned, controls and competencies are operating, and the intended governance outcome is being achieved in practice.
A Proposal Is Not the Same Thing as Consequential Execution
The draft distinguishes the formation of a recommendation, plan, tool request, workflow step, or proposed state transition from the legal and technical stages that determine whether that proposal may actually produce operational consequence.
Ten Proposed Outcomes for Responsible Autonomous-System Governance
The discussion draft proposes the following ten norms as a minimum technology-neutral baseline, with implementation proportionate to the system, delegated authority, affected interests, and foreseeable consequences.
Human Authority and Accountable Legal Persons
Autonomous systems should remain subject to authority established by human beings or legally responsible organizations. Delegating functions to a system should not extinguish the responsibility of the people or legal entities that design, deploy, direct, operate, integrate, or use it.
Explicit and Bounded Delegation
Delegated authority should be expressly defined, attributable, limited, and reviewable, including the actions, targets, domains, limits, conditions, and escalation requirements associated with that delegation. Authority should not expand merely because another agent, service, model, workflow, or tool is invoked.
Separation of Proposal from Consequential Action
Governance should distinguish what a system recommends or proposes from what is authorized, enforced, committed, and executed. Organizations should identify the point at which an action becomes capable of changing authoritative state, transferring value, affecting legal interests, controlling equipment, disclosing information, or producing other consequential effects.
Time-of-Action Authority and Current-Condition Validation
Consequential action should proceed only when relevant authority and governance conditions remain valid at the time action is about to occur. Revocation, expiration, substitution, evidence change, policy change, or material state drift should trigger refusal, re-evaluation, or escalation rather than automatic continuation.
Risk-Proportionate and Effective Human Oversight
Oversight should reflect the nature, scale, reversibility, uncertainty, and potential consequences of autonomous activity. Human approval is one possible mechanism, not the sole measure of meaningful human control.
Effective Enforcement, Non-Bypassability, and Safe Refusal
Governance requirements should be capable of affecting whether consequential action actually occurs. When mandatory conditions are not satisfied, the system should prevent, refuse, defer, constrain, or escalate the action, and materially consequential actions should not have an alternate path that bypasses required governance.
Data, Context, Evidence, and Provenance Integrity
Governance decisions should rely on information sufficiently reliable for the intended decision. Authoritative sources, provenance, quality limitations, uncertainty, temporal validity, policy versions, and the identity and authority of material contributors should be understood and managed.
Transparency, Traceability, and Evidentiary Sufficiency
Organizations should preserve information sufficient to understand, challenge, assess, and reconstruct consequential autonomous actions, including why an action was permitted, refused, deferred, or escalated under the conditions that existed at the relevant time.
Governance Continuity Across Systems and Organizational Boundaries
Governance obligations should remain effective as actions cross agents, services, vendors, platforms, organizational units, contractual boundaries, or jurisdictions. Trust should not be assumed merely because an instruction originated from a previously trusted source.
Lifecycle Review, Incident Response, Redress, and Governance Evolution
Governance should continue after deployment. Organizations should reassess delegation, controls, expanded use, operational evidence, incidents, exceptions, and material changes, while maintaining processes for investigation, evidence preservation, remediation, recovery, challenge, redress, and continual improvement.
What an Organization Should Be Demonstrably Capable of Doing
The competencies are organizational rather than individual. Responsibility may be distributed across disciplines, but each applicable capability should have accountable ownership, appropriate expertise, documented processes, effective controls, coordination, and evidence of operation.
Cross-Domain Foundational Competencies
Across legal, technical, risk, data, assurance, and operational functions, organizations should be able to:
- distinguish reasoning, proposal, evaluation, authorization, enforcement, commitment, execution, and post-event audit
- assign responsibility for autonomous authority and its modification or termination
- inventory consequential actions and affected interests
- distinguish identity and permission from authority that remains valid under current conditions
- identify governance decision points, enforcement points, bypass paths, and consequence boundaries
- define effective human-oversight requirements
- retain evidence needed for accountability, reconstruction, review, and challenge
Data Management Competencies
Organizations should be able to govern the information used to form, evaluate, authorize, and execute consequential actions.
- inventory data, evidence, records, contextual information, and authoritative sources
- assess quality, relevance, completeness, timeliness, provenance, uncertainty, privacy, security, and permissible use
- distinguish authoritative records from predictions, generated content, cached information, telemetry, and unverified assertions
- preserve decision context and applicable versions
- maintain evidence lineage across organizational and technical boundaries
- detect stale, missing, conflicting, corrupted, or unverifiable information before consequential action
Risk Management Competencies
Risk governance should encompass both autonomous capability and the consequences that delegated action may produce.
- inventory consequential use cases, action classes, targets, dependencies, affected parties, and delegated authorities
- evaluate legal, financial, safety, privacy, cybersecurity, civil-rights, operational, reputational, and systemic harms
- assess scale, velocity, reversibility, uncertainty, persistence, and cross-domain propagation
- classify risk and define proportionate governance rigor
- map risks and obligations to accountable persons, controls, evidence, oversight, and escalation
- assess recursive delegation, tool use, multi-agent coordination, third parties, and cross-system execution
- use incidents, refusals, overrides, exceptions, and assurance findings to improve governance
Operations Management Competencies
Organizations should understand and control how consequential autonomous actions move through operational systems.
- document the path from initiation and proposal through evaluation, authorization, execution, evidence, and closure
- identify where legal or operational consequence becomes possible
- verify that the executed action matches what was reviewed and authorized
- revalidate authority, policy, evidence, dependencies, and target conditions when circumstances may have changed
- provide effective refusal, deferral, revocation, escalation, suspension, reversal where feasible, and safe stopping
- control bypass pathways and privileged alternatives
- test governance under normal, adverse, boundary, replay, failure, and bypass scenarios
- investigate incidents, preserve evidence, contain harm, restore safe operation, and document corrective action
Governance Should Be Observable in Practice
The draft emphasizes that organizations should be able to demonstrate governance through risk-proportionate evidence, not merely through policy statements or architectural intent.
Examples of Evidence
Evidence of organizational competency may include:
- action and authority inventories
- governance charters
- delegation instruments
- data and evidence maps
- risk assessments
- architecture diagrams
- control descriptions
- operating procedures
- test and assurance results
- incident and refusal records
- governance receipts and audit evidence
- training and documented review records
Practical Assessment Questions
- What consequential actions can the system propose or perform?
- Who or what grants authority, and what are its limits?
- What conditions must be satisfied when consequence becomes possible?
- Where is governance enforced, and can that path be bypassed?
- What happens when mandatory conditions are not satisfied?
- What establishes authoritative state, context, and evidence?
- How is governance preserved across systems, agents, vendors, and organizational boundaries?
- Can the organization reconstruct why an action was permitted or refused?
- Who remains accountable for consequences and remediation?
- What evidence demonstrates that governance actually operates as designed?
A Starting Point for Governance Discussion and Development
The draft identifies several possible uses for the proposed norms and competencies without treating them as adopted law or formal standards.
Working-Group Discussion
Support ASG-WG discussion, comparison, review, consensus development, and possible future work products.
Legal & Governance Guidance
Inform sector-specific governance analysis, professional guidance, organizational policy, delegation, and oversight design.
Professional Education
Support education concerning the legal, technical, risk, data, assurance, and operational functions that collectively establish organizational governance competency.
Procurement & Third-Party Governance
Inform contracting, procurement, due diligence, vendor-management, and responsibility-allocation discussions involving autonomous systems.
Architecture & Assurance
Support system-architecture review, operational-control assessment, risk evaluation, audit, assurance, and testing.
Future Standards & Best Practices
Provide discussion material that could inform later standards, best practices, model governance provisions, or sector-specific implementation approaches.
View the Contribution in Its ABA Working-Group Context
The American Bar Association’s Autonomous Systems Governance Working Group maintains an external page for this contribution. That page provides the working-group context for the proposed norms and competencies and allows visitors to review posted comments associated with the contribution.
Sustainable Future Tech also preserves the discussion draft as an archival copy within its institutional record of contributions to external governance, standards, professional, and public-policy processes.
This working-group discussion draft does not currently use a Zenodo DOI record. The ASG-WG page serves as the external contribution record, while the SFT-hosted PDF preserves the archival artifact.
Status, Attribution, and Provenance
This page documents a July 2026 discussion draft prepared by John M. Willis, Founder & Chief Systems Architect of AGCP.ai, an initiative of Sustainable Future Tech, Inc., and contributed to the American Bar Association’s Autonomous Systems Governance Working Group (ASG-WG). The ASG-WG is a joint effort of the SciTech Risk and Trust Management Committee and the Cyber and Technology Committee of the ABA Business Law Section.
The ASG-WG website provides the external contribution record and associated posted comments. Sustainable Future Tech maintains this page to provide institutional context and preserves the SFT-hosted PDF as an archival copy of the discussion draft.
The contribution is aligned with the human-control, accountability, transparency, and traceability concerns reflected in ABA Resolution 604 (2023), but the document itself remains a proposed discussion contribution.
The document does not claim that its proposed norms or organizational competencies have been adopted by ASG-WG, the American Bar Association, the SciTech Risk and Trust Management Committee, the Cyber and Technology Committee, the ABA Business Law Section, or another standards or professional body.
The draft likewise states that the proposed framework is not a statement of law, a professional standard, or a presumption concerning negligence or liability. Existing law, professional obligations, contractual duties, sector-specific regulation, privacy requirements, cybersecurity controls, AI management systems, and applicable assurance practices remain independently relevant.
Runtime-governance terminology and technical architecture continue to evolve through SFT and AGCP research. This page preserves the contribution in its discussion-draft context rather than retroactively presenting it as an adopted or superseding governance framework.