AI Acceptable Use Policy + Agent Commerce Guardrails (L5)
Two open specs to bring sanity to org-readiness: an AI AUP baseline that combats shadow AI without over-restricting, and Agent Commerce guardrails that define what terms/$ limits an agent may auto-approve. From John Williams (FXOps) on the GTM AI Podcast.
The steps
- 01
Adopt the open AI AUP as your v1 baseline
Tool: github.com/fxops-ai
Don't start from zero. The open AUP gives Enablement/HR/Legal a workable baseline they can adapt, beats six months of legal review while shadow AI runs the company.
- 02
Define agent spend + ToS limits
Tool: Agent Commerce spec
For every autonomous agent: max $ per transaction without human approval, allow-list of ToS your agent may auto-accept, escalation path. Codified in a machine-readable spec the agent checks itself against.
- 03
Audit existing agents against both specs
Tool: Manual
Inventory every agent (yours + vendor-deployed). Score each on AUP compliance + Agent Commerce fitness. Anything failing either gets paused until remediated.
- 04
Publish the spec internally + bake into procurement
Tool: Internal wiki
New AI tool intake form requires AUP + Agent Commerce attestation. Vendors that can't answer don't get bought.
Tools in this playbook
- github.com/fxops-ai
- Agent Commerce spec
- Manual
- Internal wiki
Next playbooks
Unfamiliar terms are defined in the AI and Revenue Dictionary. Related frameworks live in the framework library.
