What Is Settled and What Is Moving
A status map of the doctrine's core constructs, from those that have not changed since first publication to a proposal that is still being tested.
Last updated 15 September 2026, against doctrine v3.6. Placements move only when a changelog entry, a standards mapping or an RFC revision gives a reason for them to move.
Why this page exists. A standard that never records what is unsettled asks to be trusted rather than checked. This page does the opposite. It takes eight constructs of the doctrine and places each one by how much it has moved, with the evidence for the placement written into the figure. A reader who disagrees with a placement can point at the evidence line and say why.
What it is not. This is a statement about the text of the doctrine and its published revisions. It is not a claim about adoption, and it is not a ranking of importance. Law 1 sits in the vexed column because its mechanism is unspecified, not because the principle is in doubt.
The five labels
| Label | Meaning | How a construct earns it |
|---|---|---|
| Settled | Unchanged since first published. | No changelog entry has altered its name, count or substance since the release that introduced it. |
| Stable | Agreed in principle; one detail still being specified. | The principle is unchanged, and the changelog records an acknowledged gap or an open specification against it. |
| Vexed | The principle is held; how to do it is an open question. | The principle has independent support on the Observatory, and the doctrine has recorded that it states the requirement without specifying the mechanism. |
| Evolving | Rewritten at least once; likely again. | The changelog records a rename, a change in count, or a substantive rewording in more than one release. |
| Unstable | Proposed, not yet doctrine; still being tested. | Published as an RFC, open for comment, and revised after review found internal contradictions. |
The placements
| Construct | Status | Evidence |
|---|---|---|
| Law 2, Enforce at Runtime | Settled | Unchanged since v1.5 (April 2026). In v3.6 the doctrine states the primitives it builds on: policy decision and enforcement points per NIST SP 800-207. |
| Law 3, Governance Must Span Systems | Settled | Unchanged since v1.5 (April 2026). Cross-mapped to CISA, OWASP and NIST guidance on the Standards pages. |
| Law 5, Humans Retain the Right to Intervene | Stable | Principle unchanged. v3.2 recorded that the law asserts the right without defining the stakes tiers at which intervention is mandatory. RFC 001 proposes Action Tiering to close the gap. |
| Least Agency (third non-negotiable) | Stable | Shared vocabulary. The OWASP Top 10 for Agentic Applications 2026 used the term publicly in December 2025; the OWASP mapping documents this as convergence, not coinage. |
| Law 1, Agents Are Identities, Not Tools | Vexed | Field convergence on durable agent identities is recorded on the Observatory. v3.2 recorded that Plane 1 states the identity requirement without specifying mechanism: how an identity is provisioned, bound to an accountable principal, and revoked. |
| Law 4, Trust Does Not Travel | Evolving | Renamed and widened in v3.0 (May 2026), when it also received its own architectural plane. In v3.6 the delegation wording on the Architecture and Framework pages was aligned with the law and with RFC 001 C5.2: authority is independently granted at the receiving node, not transferred. |
| The Architecture, five planes | Evolving | Grew from four planes to five in v3.0, with Plane 1 renamed; the companion Framework grew from five pillars to six. In v3.6, Planes 2 and 3 were restated in policy-decision and policy-enforcement terms, and Plane 4's evidence requirement was revised to a reconstructable, tamper-evident transaction record. |
| The Conformance Layer, RFC 001 | Unstable | Not yet doctrine. Adversarial review of revision 1 found three places where its criteria could not all hold at once. Revision 2 is open for comment through 31 October 2026, and the v3.6 changelog records that a revision 3 will carry the structural changes from the September 2026 assessment. |
What the map does not show
Three things are deliberately left off. The Maturity Model was revised in v3.6 and would sit in the evolving column; it is a companion instrument rather than a construct of the doctrine, and RFC 001 proposes rebuilding it. The Threat Surface has not changed since v3.0 and would sit in the settled column; it is mapped entry by entry on the OWASP page. The 6 Framework Pillars track the planes they map to and would duplicate the Architecture row.
How this page is maintained
The map is regenerated on each doctrine release and dated. A construct moves left when a release closes the gap that held it in place, and moves right when a release records a rename, a change in count, or a contradiction found in review. The source of every placement is a page on this site, so the map can be checked against the changelog by anyone, at any time.