<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.sato-soos-idp" target="https://datatracker.ietf.org/doc/html/draft-sato-soos-idp-05">
   <front>
      <title>The Intent Declaration Primitive (IDP) for Agentic AI Systems</title>
      <author initials="" surname="Sato" fullname="Tom Sato">
         <organization>MyAuberge K.K.</organization>
      </author>
      <date month="June" day="30" year="2026" />
      <abstract>
	 <t>   Every action an AI agent takes is a decision.  Right now, none of
   those decisions are signed.

   AI agents operating in automated workflows take actions without any
   normative mechanism for expressing why those actions are being taken.
   Access tokens declare what an agent is permitted to do; no existing
   standard declares what the agent believes it is doing, on what
   reasoning basis, and with what level of confidence, at the moment of
   action.  This document defines the Intent Declaration Primitive
   (IDP): a structured per-transition declaration submitted by an AI
   agent to the Governing Enforcement Component (GEC) at each action
   step of an execution loop.  The IDP is committed to a tamper-evident
   Event Log before the action executes, enabling post-hoc review of
   agent reasoning, richer authorization policy evaluation, and enriched
   denial responses that guide agent behaviour.  The IDP also provides
   the technical basis for compliance with EU AI Act Article 12 logging
   requirements for high-risk AI systems.

   Version -05 adds: the intake_endorsement operation (Section 4.6)
   through which the GEC endorses a submitted EOD before the first
   SENSE delivery, making the EOD a GEC-signed artifact and preventing
   unendorsed IDPs from proceeding; the PD-EOD (Prompt-Derived EOD)
   branch (Section 4.7) for IDPs derived from natural-language prompts
   rather than structured input, with scope-bounding rules and HEM
   notification requirements; the mandate_reference field (Section 4.1)
   linking each IDP to an SPO URI for structural validation; confidence_
   level calibration guidance (Section 7) including the CONFIDENCE_
   MISCALIBRATION_WARNING trigger; RETRY_CONTINUATION normative
   strengthening with backward reference to AEP-02&#x27;s what_changed
   requirement; and four new Security Considerations addressing prompt
   injection at intake, EOD scope manipulation, confidence_level
   inflation attacks, and COMMITMENT_GAP exploitation.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-sato-soos-idp-05" />
   
</reference>
