Existing AI governance frameworks---the EU AI Act, the NIST AI Risk ManagementFramework (AI RMF), and ISO/IEC 42001---were designed for AI systems operatingunder continuous human supervision: classifiers, recommenders, and single-turngenerators. None were designed for agentic AI systems that autonomouslydecompose goals into multi-step plans, execute sequences of environment-modifyingactions, coordinate multiple specialized sub-agents, and maintain state acrosssessions. Singapore's Model AI Governance Framework (January 2026) is the onlypublished governance document that acknowledges this gap, identifying threeunaddressed risks: cascading failure propagation, emergent scope expansion, andattribution gaps across agent chains. This document introduces the Cyryx Governance Protocol (CGP) v1. 0, atechnical framework that fills these gaps with seven control domains andtwenty-eight normative controls (MUST/SHOULD/MAY). CGP is designed as anextension to existing frameworks---not a replacement---with explicit mapping toEU AI Act Articles 9, 12, 13, 14, and 15; NIST AI RMF functions GOVERN, MAP, MEASURE, and MANAGE; and ISO 42001 Clause 6, 7, 8, and 9 controls. Everycontrol in CGP v1. 0 has a reference implementation in MAAX Studio by CyryxLabs. CGP is published under Creative Commons Attribution 4. 0 (CC BY 4. 0) foropen community adoption and review.
CYRYX Labs (Mon,) studied this question.