Vanta publishes 65 AI agent controls for the gaps ISO leaves open Vanta has released Agentic Trust Controls, an open-source library of 65 controls for AI agent governance, expanding its early-access version from 61 controls and mapping to ISO 27001 and ISO 42001. The library, led by product-security researcher Herman Errico, includes 43 controls for developers and 22 for organizations deploying third-party agents, with SOC 2 and NIST Cybersecurity Framework mappings planned. Vanta co-founder and CEO Christina Cacioppo said the project aims to provide technology-specific controls that integrate with existing ISO programs rather than creating a new framework. Vanta publishes 65 AI agent controls for the gaps ISO leaves open Herman Errico's open-source project separates governance for builders and buyers, while leaving runtime enforcement to other tools. By RuntimeWire Staff /author/runtimewire-staff ยท Published Primary source: Vanta https://trustcontrols.ai/ Why it matters Vanta is defining the checklist enterprises may use to buy and audit AI agents, giving it influence over a security category while runtime vendors compete to enforce the rules. Herman Errico https://www.linkedin.com/in/hermanerrico?ref=runtimewire , a product-security researcher at Vanta https://www.vanta.com/resources/vanta-announces-series-d?ref=runtimewire , has moved Agentic Trust Controls https://trustcontrols.ai/?ref=runtimewire into general availability with 65 open-source controls for organizations building or deploying AI agents. The late-August release expands the 61-control early-access version Vanta opened in July and maps the library to ISO 27001 and ISO 42001, with SOC 2 and NIST Cybersecurity Framework mappings planned. The distinction between building and buying agents drives the structure. The general-availability library contains 43 controls for developers and 22 for organizations deploying agents made by outside vendors. The developer baseline covers areas such as agent identity, authority, action guardrails, memory protection, instruction integrity, adversarial testing and runtime instrumentation. The user baseline addresses agent inventories, credentials, vendor reviews, monitoring, oversight responsibilities and staff training. Agentic Trust Controls is an internally sponsored Vanta project rather than a separately financed startup or paid product. That makes the people behind it central to understanding the release. Errico previously founded Blendgate, a marketplace for buying and selling technology-consulting services. He later became the public lead for Vanta's work on security libraries and AI governance. Vanta wants a control set, not the 15th standard Errico's approach follows a principle set by Vanta co-founder and CEO Christina Cacioppo https://www.humanx.co/us/speakers/christina-cacioppo?ref=runtimewire : avoid creating another framework that security teams must maintain beside the ones they already use. The project is intended to provide technology-specific controls that can be added to existing ISO programs. That choice also reflects Cacioppo's path into compliance software. She founded Vanta in 2018 after leading product management for Dropbox Paper, where the SOC 2 process exposed how much enterprise security work still depended on manual reviews. Before Dropbox, she worked on Union Square Ventures' investment team and studied economics and management science and engineering at Stanford. Cacioppo initially described Agentic Trust Controls as 61 controls across 12 domains: 40 for builders and 21 for users, as she wrote in the project's early-access announcement https://www.linkedin.com/posts/ccacioppo this-week-we-open-sourced-agentic-activity-7481381422424039425-WY1C?ref=runtimewire . Vanta then invited security engineers, auditors, researchers and agent developers to comment on the library. Errico later said 230 experts submitted more than 350 contributions over three weeks in his project update https://www.linkedin.com/posts/hermanerrico today-we-make-agentic-trust-controls-available-activity-7480996890247843841-2V09?ref=runtimewire . Earlier updates cited more than 200 experts and 304 contributions over two weeks, so the participation totals depend on when Vanta took the count. The final baseline added four controls, producing the 43-and-22 split. Errico has argued that practitioner participation matters because agent risks become concrete around delegation chains, credential scopes and the systems an agent can reach. A control written by someone who has watched an agent fail in production is likelier to specify evidence that can actually be collected, rather than settling for a broad policy statement. A checklist cannot block an agent The open library establishes what organizations should govern and document. It does not appear to provide the technical enforcement layer required to stop a prohibited action while an agent is running. A control can require restricted tool access, runtime monitoring or human approval, while the organization still needs identity infrastructure, a policy gateway or monitoring software to make that requirement effective. Errico is working on that separate technical problem through Autonomous Action Runtime Management, or AARM. The Cloud Security Alliance's AARM working group https://cloudsecurityalliance.org/research/working-groups/autonomous-action-runtime-management-aarm?ref=runtimewire is developing a vendor-neutral specification for systems that intercept, authorize and audit agent actions before execution. Its scope includes excessive privileges, prompt injection, irreversible actions and threats that emerge across a sequence of individually permitted steps. Commercial vendors are already selling products aimed at that enforcement layer. WitnessAI's Agentic Control https://witness.ai/resources/witnessai-introduces-agentic-control-to-secure-and-govern-ai-agents-and-mcp-servers/?ref=runtimewire , released on June 17, discovers agents and Model Context Protocol servers, applies approved-tool policies and blocks activity at runtime. NeuralTrust https://neuraltrust.ai/?ref=runtimewire markets gateways, runtime security and agent inventory software; the company announced a $20 million funding round on June 17. Those products can implement pieces of the governance program that Vanta's open control set describes. The open-source strategy fits Vanta's business Vanta sells software for managing controls, collecting evidence and proving compliance. A broadly adopted agent-control library could shape the requirements customers bring into that software, even if the library remains free and vendor-neutral. It also puts Vanta closer to security teams as they decide whether AI agents belong in existing governance programs or require separate tooling. Vanta has the balance sheet to fund that work without turning Agentic Trust Controls into a standalone venture. In July 2025, Vanta raised a $150 million Series D at a $4.15 billion valuation. Cacioppo said the funding would support broader work in continuous trust and AI-driven security operations. Vanta did not present that round as financing for Agentic Trust Controls, which arrived roughly a year later. The project's useful test will come when auditors and security teams ask for proof. A control stating that an agent's authority is limited has little value without evidence showing which credentials it held, which policy was evaluated and whether a prohibited action was blocked. Agentic Trust Controls gives builders and buyers a shared list of questions. Errico's harder task is ensuring those questions produce technical safeguards and audit records rather than another tab in the compliance spreadsheet.