Declared agent welcome
A service stating, in machine-readable form on the channel itself, what agent traffic is welcome there and for what purposes. The declaration states the policy; confirming which agent is making a request is a separate duty.
The impact of agents
As agent traffic grows, what a government channel permits an agent to do (lodge a submission for a person, read and index it, train on its content) becomes a real policy question, and nowhere more than on a submissions channel, where the legitimate agent filing in the open is the alternative to the anonymous one filing covertly. Today the question is answered only by fragmented, unilateral signals descended from robots.txt. An agency that says nothing invites everything and then over-blocks at the edge with no record of the decision; an agency that blocks by default excludes the legitimate agents its own users depend on. Both are policy decisions no one is recorded as making, and increasingly not the agency's to make: a service behind a large CDN may already be emitting vendor-defined agent signals its policy owners never chose. Draft standards now exist for saying it explicitly, which puts the choice in front of agencies: declare what agent use is welcome, or keep making that policy by default and by vendor.
What must be verified
The relying party here is the agent and its operator: before acting, they need confidence that a channel's declared preferences are authoritative, current, and complete enough to act on. The agency operating the channel must publish the declaration and keep it current. It must also keep the declaration true, so that what the declaration welcomes and what the edge enforces match. A declaration the edge does not honor misleads the compliant agent and does nothing to the non-compliant one. A preference declaration is not an access control and confirms nothing about which agent sent a request; the standards work is explicit on that boundary. Enforcement and attribution belong to admission, and the declaration is one signal among the pair, never the whole answer.
Protecting access
Exclusion here runs through the people behind the agents. A person may depend on an agent for disability, language, working hours, or the sheer administrative effort involved. If a channel's declaration defaults to 'no agents', that person is redirected to slower channels or deterred outright, while large operators negotiate private carve-outs an individual's self-built agent never gets.
Keeping the path open
- State what is welcome, not only what is forbidden.
- Scope the welcome so it isn't available only to registered commercial operators.
- Cost the agent's traffic, not the person's outcome, when an agent violates the declared preferences: a submission that arrived through a discouraged route is still a submission owed consideration.
- Publish the declaration in plain language on the channel it governs, readable by people as well as machines, so a person can know what their agent may do there without parsing a preference file.
Response surface
The channel itself states what agent traffic is welcome and for what purposes, in plain language and in a form an agent can read.
Agent access policy
AP-2026-014City Digital Services’s statement of what software agents may do on this channel. Readable by people and by agents.
Any agent may read the public pages here.
An agent may lodge on a person’s behalf; the admission check confirms whose agent is asking. A submission that arrives outside these preferences is still a submission, and is still considered.
Content on this channel is not offered for model training.
What this page says is what the channel enforces. Blocks are logged and reviewed against this policy.
The declaration states the channel’s policy and confirms nothing about which agent sent a request — that check belongs to admission, the paired surface. Publishing it takes back a policy surface otherwise exercised by edge-infrastructure defaults.
Maturity
- Emerging
For the signaling layer, where an IETF working group is chartered with adopted vocabulary drafts and a vendor reports deploying the same shape on millions of domains.
- Frontier Headline
As a government channel policy — declared agent permissions per channel with declared-versus-enforced parity — where no public-sector deployment documents one.
Precedents
The IETF AIPREF working group. The IETF chartered AIPREF to standardize a vocabulary for expressing preferences about AI use of content and mechanisms to attach them via robots.txt and HTTP. The vocabulary draft is an adopted working-group document narrowed to two categories, train-ai and search, while its attachment companion has lapsed and the milestones have slipped a year. The charter is explicit that this expresses a preference without enforcing it: no access control, no authentication, no registries.
Cloudflare's Content Signals Policy. The policy layers three machine-readable yes-or-no signals, search, ai-input, and ai-train, onto robots.txt, running on more than 3.8 million domains through its managed robots.txt, on a count the operator publishes itself. The design consequence is not: an agency behind that infrastructure may already be signaling to agents without having decided to.
Really Simple Licensing. RSL attaches machine-readable licensing terms covering attribution and compensation to the same robots.txt-adjacent slots, with a collective-rights organization behind it. Government channels do not sell content. It still demonstrates that machine-readable conditions of agent use, and not only permissions, are viable.
llms.txt, the cautionary example from the same slot. The community proposal for an agent-facing index file has real tooling-side adoption and no documented crawler honoring it. A signal only one side of the conversation adopted binds nobody, which is why a declaration pairs with admission rather than replacing it.
What carries over to agent use
The mechanics transfer today. An agency could publish content signals on its channels this afternoon, which is precisely why the gap is legible. None of the deployed or drafted vocabularies speaks to the interaction government cares about: whether an agent may lodge a submission here, for whom, and under what admission requirements. The categories are crawl-era (search, training, input), and the government-shaped extension is undesigned. The trust model does not transfer either. The web's version is a unilateral request aimed at strangers, while a government declaration would be read as a commitment. A commitment needs two things a request does not: parity between what is declared and what is enforced, and somewhere authoritative to publish it. Neither is designed yet, and the llms.txt experience sets the failure baseline for skipping them.
Where things go wrong
Left unaddressed, the failure is a policy made by nobody: edge infrastructure and vendor defaults decide which agents reach a government channel, the agency cannot say what its own policy is, and the record shows blocking decisions no official made. The adversarial readings are institutional as much as technical. A publisher games its own declaration by publishing a welcome its edge configuration does not honor and does not log. The metric is met on paper while compliant agents are refused without a record. A declaration nobody enforces fails in the opposite direction, training agents to ignore it and penalizing exactly the operators who honor it. A declaration can also be weaponized as a gate: scoped so narrowly that only registered commercial operators fall inside the welcome, it converts a transparency instrument into a market-access filter. The pairing with admission is the containment for all three: the declaration states what is welcome, admission confirms which agent made the request, and neither pretends to do the other's job.
Sources
5 references
The instrument, the operating deployment, or the official record itself.
Writing about the subject rather than the framework itself, including vendor commentary.