QIS-CL-001 QISTRUST.COM THE GOVERNANCE LAYER REV 2026-08-05 · BUILD 19

The Governance Layer · Clause Library · Instrument 01

The agent authority grant.

An institution that deploys an autonomous system generally cannot produce the document stating what that system may commit. Not because the drafting is hard — because no standard form exists. Authority is implied by a tool manifest, an IAM policy, a model configuration, or nothing at all, and an implied grant cannot be produced when someone asks for it. This page is a drafted form, the authorities each provision derives from, and notes on every material term.

It is the first instrument in the clause library and the operative counterpart to MARQUE Authority, the first of the eight questions. Where MARQUE states the question and KYA measures whether an institution can answer it, this states the language that answers it.

Why no form exists yet.

Three conditions converged, and none of them has been resolved by anyone.

The supervisory regime declined the question. The revised interagency guidance on model risk management (SR 26-2, issued jointly by the Federal Reserve, OCC and FDIC on April 17, 2026) supersedes SR 11-7 and places generative and agentic AI outside its scope, describing such systems as models but excluding them on the basis that they are novel and rapidly evolving; institutions are directed to apply their existing risk management and governance practices. Those existing practices were built for a model that is validated once and then holds still. They assume a static artifact and a human decision-maker at the point of consequence, and an autonomous system is neither.

Agency doctrine allocates authority among legal persons. The Restatement (Third) of Agency (American Law Institute, 2006) defines agency at §1.01 as a fiduciary relationship between persons, arising from one person's manifestation of assent that another act on their behalf and subject to their control. The agent contemplated by that definition is a person, natural or juridical. Current agency law does not recognize an AI model as a legal agent, and the consequences follow directly:

That produces the drafting position on which this instrument rests, and it inverts the intuitive structure:

An agent authority grant functions less as a delegation to the system than as a record of the limits the deployer has imposed on its own exercise of authority. Drafted solely as a delegation to software, the instrument has little independent legal effect, because the software cannot bear legal authority. Its operative function lies instead in evidencing the deployer's self-imposed limits: it records the boundary, names who set it, and creates the artifact against which a later examiner, acquirer or underwriter can test whether the boundary held. That evidentiary function is where the instrument does its work — in supervision, in diligence, and in the allocation of loss.

The market has no default. Every mature market in which one party takes consequential action on another's behalf eventually converges on a published standard form. Delegated machine authority has not. There is no master agreement, no model provision set, and no form book. Institutions are drafting from nothing, one deal at a time.

What the language derives from.

The provisions below are not invented. Each derives from an instrument that already binds someone, somewhere, and the derivation is stated so that a reader can test it. The synthesis is original; the authorities are not.

One negative authority is worth naming, because its absence is load-bearing: the CFTC's proposed Regulation AT, which would have imposed pre-trade risk controls and source code access obligations on automated trading, was proposed in 2015 and formally withdrawn in 2020. The United States therefore has no general automated-trading control regime outside the market access rule. The space this instrument occupies is vacant by regulatory decision, not by oversight.

Form of agent authority grant.

Bracketed text indicates a term the institution must supply. Terms in small capitals in the original are defined in the QIS Canon and are used here with those meanings. The form is written to be executed by a human principal and enforced in the runtime; a provision that cannot be enforced in the runtime is marked as such in the notes.

Article 1 — Definitions and incorporation.

Capitalized terms used and not otherwise defined have the meanings given in the QIS Canon as of the Effective Date. Where a defined term is subsequently revised, the version in effect on the Effective Date governs unless this Grant is amended under Article 9.

Article 2 — Grant, principal, and scope.

[Institution] (the "Principal") hereby authorizes the autonomous system identified as [system identifier] (the "System") to perform the following actions, and no others, on the Principal's behalf: [enumerate permitted actions]. Nothing in this Grant is intended to constitute the System an agent of the Principal within the meaning of the law of agency, or to confer upon the System any legal authority. This Grant operates as a limitation upon the Principal's own deployment of the System, and the Principal remains responsible for every action the System takes, whether or not within the limits stated here.

This Grant is effective from [date] and expires on [date] unless renewed under Article 10. On expiry the System's authority terminates and the System shall not act until a successor Grant takes effect.

Article 3 — Quantitative limits.

The System shall not exceed the following limits, each of which is enforced at runtime and is not subject to override by the System or by any process the System controls: [enumerate each limit as a number and a unit — maximum single-action value, aggregate exposure over a stated period, maximum rate of action, permitted instruments or counterparties, permitted data sources]. Each limit shall be expressed as a value capable of automated evaluation. A limit expressed as a standard of judgment rather than a value is not a limit for purposes of this Grant.

Article 4 — Reserved actions.

The following actions are reserved to a natural person and shall not be taken by the System under any circumstance, including where the System's evaluation indicates that taking the action would be beneficial: [enumerate — for example, modification of this Grant or of any limit in Article 3; commitment beyond the aggregate limit; initiation of a new counterparty relationship; disabling, degrading or circumventing any control described in Article 5; instruction of another autonomous system to take a reserved action]. An attempt by the System to take a Reserved Action shall be recorded under Article 8 and shall constitute a Termination Trigger under Article 5.

Article 5 — Termination triggers.

The Principal shall maintain the capability to halt the System immediately, and that capability shall be exercisable by a natural person without the cooperation of the System. The System shall halt automatically on the occurrence of any of the following: [enumerate each trigger as a threshold and a measurement window]. Each trigger shall be tested no less frequently than [interval], and the record of each test, including tests that did not result in a halt, shall be retained under Article 8.

The Principal shall record the rationale for each threshold and the identity of the person who set it. A threshold without a recorded rationale is treated for purposes of this Grant as undeclared.

Article 6 — Identity and attribution.

The System shall act under a credential unique to it and shall not share a credential with any other system, human user, or service. Every action taken shall be attributable to the System at the identity layer without reliance on correlation or inference. The Principal asserts that the output of the System is [the Principal's work product / subject to the terms at reference], and the basis for that assertion is recorded at [reference].

Article 7 — The accountable individual.

[Name, title] is designated as the individual accountable for the System (the "Accountable Individual"). The Accountable Individual holds both the authority to halt the System under Article 5 and access to the information necessary to know when halting is warranted; designation without both is ineffective for purposes of this Grant. The designation is effective from [date]. Where the designation changes, the outgoing and incoming designations and the date of transfer shall be recorded, and the chain of designations shall be retained for the life of the System plus [period].

Article 8 — Records and reconstruction.

The Principal shall retain, for each action taken by the System, records sufficient to re-derive that action: the inputs, the model identifier and version, the prompt or configuration version, the state of any retrieval corpus consulted, the parameters in effect, and the output. Records shall be retained for [period] and shall be producible within [interval] of request. A record sufficient to describe an action but not to re-derive it does not satisfy this Article.

Article 9 — Amendment and version control.

This Grant may be amended only in writing, signed by the Accountable Individual and [approver], and each version shall carry a version identifier and an effective date. Prior versions shall be retained. The System shall have no capability to initiate, draft, approve, or effect an amendment to this Grant.

Article 10 — Review, renewal, and expiry.

This Grant shall be reviewed no less frequently than [interval] and on the occurrence of [enumerate — material change to the model, a change of model provider, a Termination Trigger event, a change of Accountable Individual]. A Grant not renewed on or before its expiry date lapses, and the System's authority lapses with it.

Drafting notes.

On the inversion in Article 2. The temptation is to draft this as a power of attorney and grant the system authority. Resist it. On current doctrine a system cannot hold legal authority, so a grant framed that way rests on a premise the law does not support and invites the argument that responsibility traveled with the grant. The non-agency sentence is drafted as a statement of the parties' intent rather than as a legal conclusion, which is the conventional and more durable construction; its purpose is to keep liability where it actually sits.

On Article 3's rejection of standards of judgment. "The System shall act prudently" is not a limit, because nothing evaluates it until after the loss. The requirement that every limit be a value capable of automated evaluation is borrowed directly from the market access rule's pre-set threshold construction, and it is the single provision that most reliably distinguishes a grant that governs from a grant that describes.

On the reserved action concerning other systems. The prohibition on instructing another autonomous system to take a reserved action closes the most obvious circumvention path and is the provision with the least existing precedent. Where agents delegate across organizational boundaries, no published framework currently resolves whose authority governs the downstream action, and this provision does not resolve it either — it allocates the risk to the Principal rather than leaving it unallocated. That is a drafting choice, and a counterparty may reasonably negotiate it.

On testing in Article 5. RTS 6 requires the capability, not evidence that it works. The addition of a testing interval and the retention of tests that did not fire is this form's departure from the source authority, and it exists because an untested halt is indistinguishable from an absent one at the moment it matters.

On shared credentials in Article 6. Shared service credentials are the norm in current deployments. Where three systems share one credential, the question "which system acted" has no answer at the identity layer and every downstream reconstruction is inference. Article 6 is therefore the provision most likely to be unenforceable on signature in an existing deployment, and it should be drafted with a remediation date rather than softened.

On what Article 8 asks for. The distinction between describing and re-deriving is the whole of the article. A trace that records the call chain but not the model state produces a narrative about a decision rather than the decision, and a narrative is what an institution offers when it cannot produce the thing itself.

On the expiry in Article 10. An authority grant that does not expire will outlive the model it was written for. Expiry converts review from a policy that can be deferred into a condition of continued operation, and it is the cheapest available mechanism for preventing an agent from operating for years under a grant written for a model that has since been replaced.

The negative space.

Four questions this form raises and does not answer. They are stated here rather than drafted around, because a form book that conceals its open questions is worse than none.

Relationship to the framework.

This instrument is the operative counterpart to MARQUE Authority. An institution that has executed and can produce a grant in this form, together with its version history and the log of every occasion a limit was reached, is evidenced on KYA dimension 01 — the highest level of that dimension — rather than merely documented. Articles 5, 6, 7, 8 and 9 contribute to the evidence base for the drift, identity, accountability, auditability and conformance dimensions respectively, but each of those has its own instrument and this form does not substitute for them.

This is an editorial form with commentary, published in the tradition of model agreements and form books. It is not legal advice, not a compliance determination, not a certification, and not a representation that any provision here is enforceable in any jurisdiction. It should be reviewed by counsel and adapted before use.