Alignment Cards
An Alignment Card is a signed contract: the scope an agent is authorized to operate within, expressed structurally enough for a machine to enforce and plainly enough for a CISO to sign.
- Declared intentWhat this agent is authorized to do, in plain language and in signed structured form.
- Permitted tools + scopesExact callable surface. Nothing outside the card is reachable at runtime.
- Data boundariesWhat the agent may read, what it must never write, and which zones are off-limits.
- Escalation contractWhen the agent must hand to a human — and what evidence it must bring.
- Compliance obligationsEU AI Act article bindings, HIPAA roles, sector-specific retention clauses.
- Drift budgetHow much the agent is allowed to deviate from baseline behavior before AIP fires.
