Definition
A vendor-neutral checklist, published jointly by security companies, that spells out the minimum protections a company should have in place before letting AI agents act on its behalf — things like limiting what data an agent can touch and requiring approval for risky actions. It gives non-technical buyers a concrete, citable standard instead of vague reassurances from a single vendor.
Why it matters
Executives can use it as a procurement and audit checklist — asking 'does our agent deployment meet the baseline?' is far more actionable than asking 'is our AI secure?'