Governed Autonomy and the Blueprint Alliance

Twelve founding members, expanding an earlier blueprint, arrived at six principles that each have a counterpart in this doctrine. The question worth asking next is what an implementation would have to show to be judged against them.

On 22 September 2026 a cross-industry coalition named the Blueprint Alliance was announced, with twelve founding member companies spanning identity, AI, data, applications, infrastructure and cybersecurity, and strategic advisors from outside the technology industry. The coalition describes its output as an open, multi-vendor reference architecture for securing AI agents, expanded from a blueprint first introduced in March 2026. Its stated scope is the governance layer once agents are deployed, complementing work on model security and supply-chain integrity.

This page is a mapping, not a review. It maps the six principles, four core challenges and eight capability areas stated in the public announcement onto this doctrine's constructs, and records where the doctrine's proposed conformance criteria sit alongside them.

What was read. This page is based on the coalition's public announcement, read in full. The blueprint document itself is distributed through a registration form and was not reviewed. Nothing here characterizes its contents, diagrams or requirements beyond what the announcement states. Where this page and the blueprint disagree about the blueprint, the blueprint is right.

The six principles

The announcement states that the founding members "aligned toward a shared set of principles for securing AI agents." Left column is the announcement's wording, verbatim. The announcement does not cite this doctrine, and this mapping does not suggest otherwise.

Blueprint Alliance principleWhere it lands in this doctrine
"treating every agent as a first-class identity"Law 1, Agents Are Identities, Not Tools; Plane 1, Agent Identity & Lifecycle
"scoping access to the task rather than granting standing access"Least Agency, stated under Law 1 and as the third of the Non-Negotiables: no more authority than the mission demands
"keeping delegation traceable"Law 4, Trust Does Not Travel; Plane 5, Multi-Agent Trust & Delegation
"monitoring runtime behavior continuously"Law 2, Enforce at Runtime; Plane 3, Policy & Compliance Engine
"enabling containment that is instant and reversible"Law 5, Humans Retain the Right to Intervene; Plane 4, Human Oversight, Audit & Traceability
"ensuring governance adapts at the speed AI moves"The first Non-Negotiable: governance must move at the speed of execution, not bookend it

One Law has no single-principle counterpart: Law 3, Governance Must Span Systems. It appears instead in the coalition's structure and its interoperability commitment, covered below.

The four core challenges

The announcement organizes the architecture around four questions. Each maps to one or more Planes.

Question (verbatim)Capability areas named in the announcementWhere it lands in this doctrine
Where are my agents?AI agent development, discovery, and identity; AI agent security posture managementPlane 1; Pillar 1, Agent Identity. The announcement's requirement that every agent have "an accountable human owner or operational team" is the lifecycle ownership Plane 1 carries.
What can they do?Access policies; GovernancePillar 2, Mission Definition and Pillar 3, Behavioral Policy; delegation "as agents spawn sub-agents and act on behalf of humans" is Plane 5
What are they doing?Runtime authorization and monitoring; Resource accessPlane 2, Execution & Tool Governance and Plane 3; Pillar 4, Runtime Enforcement. Enforcement "inline through gateways that sit in the execution path" is Law 2 stated as a placement.
How do I respond?Response and enforcement; Access recoveryPlane 4; Pillar 5, Human Oversight & Intervention. Restoring a contained agent "through re-attestation and staged re-enrollment" returns it to Plane 1.

The announcement states that all eight capability areas rest on two foundations, "execution context and risk signals," fed by runtime telemetry, logging and observability. In this doctrine that connective role is split between Plane 3, which consumes context at decision time, and Plane 4, which holds the record.

Where the two converge

The closest convergence is on delegation and containment. The announcement names three failure conditions the architecture is meant to close: shadow agents that multiply, credentials that "cross trust boundaries," and agents that "execute beyond their intended scope." Those are, respectively, the absence of Plane 1, the problem Law 4 exists to name, and the condition Least Agency is written to prevent.

The second convergence is structural. The coalition's interoperability commitment, cross-vendor signal sharing across MCP, OCSF, SSF and CAEP so that "a threat signal raised by one runtime monitor triggers real-time action across all connected control planes," is Law 3 and the second Non-Negotiable (enforcement must be a fabric, not a fragment) pursued as an engineering program across vendors. A reference architecture assembled by twelve vendors is itself an argument that no single product spans the systems an agent touches.

What this doctrine provides alongside it

The announcement describes principles, challenges, capability areas and a commitment to publish joint interoperability results and reference integrations. The doctrine's contribution at the same layer is a proposed set of criteria stated so that an implementation can be tested against them and can fail. RFC 001, The Conformance Layer proposes twenty-nine such criteria. It is a proposal open for comment, not doctrine; the doctrine in force is v3.6.

Read against the six principles, the relevant RFC 001 criteria are:

PrincipleRFC 001 criterion (proposed)
Scope access to the taskC1.3: an agent's authority is granted per mission, expires with the mission, and does not persist across missions or into dormancy.
Keep delegation traceableC5.1: trust is established at every handoff and never carried across one. C5.2: authority is never inherited from an invoking agent; a subagent's authority is granted independently, scoped to its own mission. These ask a narrower question than traceability: not only whether a delegation can be followed afterward, but what authority is permitted to exist on the far side of it.
Monitor runtime behavior continuouslyC3.2: policy is evaluated during execution, at each governed action, not once at session start. C3.8: an action whose applicable criteria cannot be evaluated does not proceed, which covers the window when the monitor itself is unavailable.
Containment that is instant and reversibleC4.1: a revocation, override or halt is honored before the agent's next commit. C5.4: on detection, the governing system halts every downstream consumer of the affected agent's output, not only the agent.
Treat every agent as an identityC1.1: every action appears in the record, attributed to exactly one agent, in every system the agent touches. C1.2: agent-originated actions are distinguishable from human-originated actions without inference.
Governance at the speed AI movesCX.1, the Simultaneity Criterion: every applicable criterion holds for a single action within that action's decision window, and the parameters evaluated are identical to the parameters committed.

A reference architecture and a conformance layer answer different questions: the first says which capabilities belong where, the second says what must be true for a given action to count as governed. They are designed to be used together. An implementation built to the blueprint could be assessed against RFC 001's criteria, and RFC 001 is open for comment through 31 October 2026 for exactly that kind of test.

Primary sources