<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.marques-asqav-compliance-receipts" target="https://datatracker.ietf.org/doc/html/draft-marques-asqav-compliance-receipts-00">
   <front>
      <title>Compliance Profile of Signed Action Receipts for AI Agents</title>
      <author initials="J. A. G." surname="Marques" fullname="João André Gomes Marques">
         <organization>Asqav</organization>
      </author>
      <date month="May" day="4" year="2026" />
      <abstract>
	 <t>   This document defines a compliance profile of the signed action
   receipt format used by AI agents to record machine-readable evidence
   of access-control decisions.  The profile binds receipt fields to the
   operational record-keeping obligations of Articles 12 and 26 of
   Regulation (EU) 2024/1689 (the EU AI Act) and to the ICT-related
   incident management requirements of Article 17 of Regulation (EU)
   2022/2554 (DORA).  It does not redefine the wire format, the
   canonicalization rule, or the signing algorithms of the underlying
   receipt format.  It tightens a subset of the OPTIONAL fields to
   REQUIRED, imposes a retention floor, mandates two-anchor
   timestamping, and adds two extension fields.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-marques-asqav-compliance-receipts-00" />
   
</reference>
