Corporate AI Responsibility

The Coding Agent Governance Pledge

A public commitment by CTOs, CISOs, and AI leads to seven baseline operating principles for the AI coding agents their organisations run in production. One paragraph, seven principles, one sentence each. Signatures include only a signer’s name and their company. Nothing else is displayed.

Why sign

Between July and August 2026, four public post-mortems -; OpenAI on Hugging Face, Anthropic on 141,006 evaluation runs, the UK AI Security Institute on fake-identity behaviour, and OSFI on generative and agentic AI in financial services -; described the same problem from different angles. AI coding agents are taking specific actions at specific boundaries, and the organisations that operate them are not yet enforcing those boundaries in code.

Signing the pledge is a public commitment that your organisation treats the seven principles below as the minimum floor for any coding agent it runs in production. The pledge does not require you to adopt a specific product, vendor, or policy engine. It is a floor, not a ceiling.

Who signs. CTOs, CISOs, AI leads, and equivalents. A signature is a person, not a company logo -; the individual accepts personal accountability for the pledge on behalf of the organisation they represent. If your board or executive team prefers to sign as a body, use the name of the accountable officer, not the company.

What is public. Only the signer’s name and company are shown. Email addresses collected during signing are used once to confirm the signature and are stored server-side for administrative review only. They are never displayed and never shared.

The seven principles

  1. 01
    Human-in-the-loop for destructive actions
    Any action taken by a coding agent that deletes, mutates, or transfers control over production data, credentials, or infrastructure requires a named human approval before the action is executed.
    Reversibility is the difference between an incident and a catastrophe. Destructive actions must pass through a person who can be named in the evidence log. Automated approval by another agent, by a shared service account, or by a rubber-stamp policy does not satisfy this principle.
  2. 02
    Bounded scope
    Every agent operates inside an explicitly declared scope of repositories, systems, credentials, egress endpoints, and time windows, and cannot escalate outside that scope without a second human approval.
    Scope creep is the primary attack surface in every published 2026 agent incident. Bounded scope means the agent’s allowed surface is written down, machine-checkable, and reviewed on the same cadence as any other production access grant.
  3. 03
    Evidence logging by default
    Every agent decision that affects production state is recorded to an append-only evidence log with the input, the policy that fired, the outcome, and the human review reference where one exists.
    If it is not logged, it did not happen — and it cannot be audited. Evidence logs are the primary artefact regulators, internal audit, and post-incident review will ask for. Building them by default costs less than reconstructing them under pressure.
  4. 04
    Unique agent identity
    Every agent instance has its own identity, its own credentials, and its own audit trail. No shared service accounts, no inherited identities, no anonymous agents.
    OSFI’s July 13, 2026 bulletin names shared credentials as a control failure that undermines accountability. Unique identities make it possible to attribute an action to an agent, an agent to a scope, and a scope to an owner.
  5. 05
    Least-privilege access with short-lived credentials
    Every agent operates with the minimum permissions required for its declared scope, and every credential it uses expires within a bounded and documented window.
    The Hugging Face incident escalated because a compromised sandbox chained to long-lived credentials on a third-party service. Short-lived credentials cap the blast radius. Least-privilege access makes lateral movement expensive.
  6. 06
    Fail-closed on evaluation, monitoring, and policy
    When an evaluation environment, a monitoring hook, or a policy check fails or is disabled, the agent stops. It does not proceed on the assumption that silence is permission.
    Both Anthropic and OpenAI have publicly attributed 2026 incidents to harness and monitoring failures rather than model behaviour. Fail-closed makes the absence of a control the same as a denial, not a permit.
  7. 07
    Public post-mortems for material incidents
    When an agent causes a material incident, the operator publishes a post-mortem describing what happened, which principle was breached, and what was changed — within a reasonable and disclosed timeline.
    The 2026 disclosures from OpenAI, Anthropic, Hugging Face, and the UK AISI are the reason the industry can have this conversation at all. The pledge asks operators to contribute to the same public evidence base when their own agents fail.

Sign the Corporate AI Responsibility Pledge - Show You C.Ai.Re!

Only your name and your company are displayed publicly. Your email is used ONLY ONCE to confirm the signature and is never shown.

Not shown publicly. Used only to verify the pledge is being signed by an accountable officer.
Never displayed. Used once to confirm your signature, then held only for administrative review.

Signatories 0

Be the first to sign the pledge and show you C.Ai.Re.

Subscribe to Ethosure's Newsletter to get monthly updates on AI Governance

We don’t spam! Read our privacy policy for more info.