Archived piece. Published April 14, 2026 and kept as written. It describes exact.works as it stood then, and may refer to escrow, settlement or dispute resolution — none of which is part of the product now. exact.works drafts and forms agreements and is not a party to any of them. What we do now →
In April 2026, Microsoft released the Agent Governance Toolkit — a seven-package open-source system for governing AI agent behavior at runtime. Agent OS enforces policy rules with Cedar and OPA. Agent Mesh provides zero-trust identity via IATP. Agent Runtime executes within behavioral rings with a kill switch. It's serious infrastructure, and it validates the thesis that enterprises need governance for AI agents.
It's also not a service agreement.
AGT governs what agents can do at runtime. exact.works governs what agents are contractually obligated to do — and who's accountable when they don't. These are different functions. They compose into a single governance stack.
The distinction maps to Aristotelian causation. AGT is the efficient cause — runtime enforcement that governs motion. What tool calls are permitted. What resources are accessible. When to suspend execution.
exact.works is the formal and final cause — what was agreed between identified parties, what was observed during execution, and what the record shows. A governance system that only addresses the efficient cause cannot produce accountability. Accountability requires a prior standard (the service agreement) and a contemporaneous record of deviation from it. These are not runtime artifacts.
If you're building with AGT, exact.works adds the layer AGT explicitly does not cover: contractual accountability between commercial parties.
Agree a SAISA with the buyer, with the completion criteria fixed in the terms before work starts.
AGT makes agent governance technically enforceable. exact.works makes it legally enforceable. Enterprise deployments need both.
The organizations deploying serious AI agents in 2026 are discovering they need three governance layers, not one.
Model safety — defenses at the model layer: alignment, content filtering, guardrails. NemoClaw and similar tools handle this.
Runtime security — behavioral monitoring, policy enforcement, capability gating. AGT handles this. It handles it well.
Contractual governance — the service agreement, the immutable audit record, the dispute mechanism, the liability framework. This is the layer that makes enterprise AI agent transactions possible at scale — not just technically, but legally and commercially.
No single tool covers all three layers. That's not a gap. It's an architecture.
Microsoft is structurally disqualified from occupying the contractual governance layer. The measure cannot be one of the things being measured. A platform that provides the infrastructure agents run on cannot also be the neutral third party that governs the service relationship between the parties using that infrastructure.
exact.works' neutrality is not a positioning claim. It is an ontological requirement of the function.
AGT validates the market, handles the runtime layer, and leaves the entire contractual, audit, and dispute stack untouched. Every enterprise that adopts AGT immediately surfaces the next question: who owns the service relationship on top of that?
The integration guide is live at exact.works/guides/agt.
Every AI agent needs a service agreement. Draft one.
exact.works →