Draft-01.1 · Open specification · In production with beta pilots
Every agent message.
Carries its own trust.
ARSIA is an open, transport-agnostic envelope protocol. Identity, compliance requirements, human oversight and audit travel inside every message between AI agents. Not bolted on. Built in.
$ pip install arsia-protocol
- 6Normative documents
- 7Compliance profiles
- 611Test vectors
- 31JSON Schemas
The core idea
One envelope.
Everything it takes to be trusted.
Every message between agents is wrapped in a structured, signed envelope. The envelope is the protocol: no sidecar, no middleware, no separate policy file.
TLS · the connection
Moved encryption out of the application and into the transport.
Applications stopped encrypting data themselves. Every connection became secure by default.
ARSIA · the message
Moves compliance out of documentation and into every message.
The difference between telling an agent to be careful with data, and never letting a non-compliant message through.
envelope.json · wire version 1.0generated with the SDK
{ "v": "1.0", "id": "106b18b4-5da7-4493-8f4d-f6afedaad83c", "ts": "2026-09-28T17:51:07.905Z", "expires_at": "2026-09-28T17:56:07.905Z", "intent": "request", "from": "agent:acme.advisor", "to": "agent:acme.executor", "capabilities": ["com.acme.trade.execute"], "compliance": { "profile": "MIFID-II", "retention_days": 1827, "data_residency": "EU", "human_oversight": "required_before_execution", "audit_required": true, "pii_involved": true, "legal_basis": "contract" }, "payload": { "type": "com.acme.trade.execute", "args": { "portfolio_id": "PF-2847" } }, "security": { "alg": "EdDSA", "kid": "agent:acme.advisor#key-1", "sig": "9-Iwmpk98fw-h-PQUa…UUeCA" }}
Every message says what it is. A wire version, a unique id, a timestamp, an expiry, and one of six intents: request, response, event, error, pending_approval or approval_decision.
Message intents
Six intents.
Every interaction covered.
From a request to its result, including the moment a human has to decide. Oversight is not a side channel: it is part of the conversation.
requestAsk another agent to act. Carries capabilities, payload and compliance requirements.
responseDeliver the result, correlated to the request, under the same compliance context.
eventA one-way notification. No response expected.
errorStructured errors: 14 standard codes with HTTP status mapping and retry guidance.
pending_approvalThe agent pauses and asks a human before a high-risk action. EU AI Act Art. 14.
approval_decisionThe reviewer approves or denies, with a written justification.
Capabilities
Everything you need.
Nothing you don’t.
Deliberately opinionated about what belongs in the envelope, and deliberately minimal about everything else. Each capability is specified, schema-validated and covered by test vectors.
01
Cryptographic identity
Every agent has a verifiable key and every message is signed. Ed25519 by default, ES256 also supported, with keys published for discovery.
02
Compliance profiles
Seven profiles for GDPR, the EU AI Act, MiFID II, DORA, the DSA and the Common Agricultural Policy. Each sets retention, residency, oversight and audit.
03
Audit trail
Records of who did what, when and under which profile, generated from the messages themselves. Retention follows the profile.
04
Human oversight
Before execution, after execution, or within 24 hours. The mode travels in the envelope; your runtime enforces the gate.
05
Two-layer validation
L1 checks structure against JSON Schema 2020-12. L2 checks semantics: cross-field rules, timestamps, capabilities and profile integrity.
06
Payload encryption
Compact JWE with ECDH-ES and A256GCM. Intermediaries can route the envelope without reading what it carries.
07
Data residency
Declare where data may be processed, at the message level. MIFID-II, DORA and PAC-AGRICULTURE default to the EU.
08
Capability system
Agents declare what they offer and request what they need. A receiver acts only on capabilities it has granted.
09
Transport agnostic
HTTP, WebSocket, queues or files. The envelope carries its own guarantees, alongside any agent framework.
Architecture
Above MCP and A2A. Complements, doesn’t compete.
MCP connects agents to tools. A2A connects agents to each other. ARSIA is the trust layer for both: identity, requirements and evidence, carried in the message itself.
5 + 1 architecture
One Core foundation and five domain primitives: Actions, Routing, State, Identity, Assets.
Zero coupling
Works with any agent framework. No required runtime, no vendor lock-in, no mandatory infrastructure.
Three conformance levels
Core: envelope, signing, discovery. Compliance: adds profiles, audit and oversight. Full: all five primitives and encryption.
a request passes down the stack, the reply comes back up
Compliance profiles
EU-first.
Built for everywhere.
Seven profiles ship with Draft-01.1, covering Europe’s major regulatory frameworks. A profile is a JSON object, so the same mechanism extends to any jurisdiction.
| Profile | Regulation | Retention | Human oversight | Audit | Residency |
|---|---|---|---|---|---|
| GDPR-STANDARD | GDPR Art. 5, 6, 9, 17, 30 | Set by operator | Not required | Not required | — |
| EU-AI-ACT-HIGH-RISK | AI Act Art. 12–14, 17, 26 | 180 days | Before execution | Required | — |
| EU-AI-ACT-LIMITED-RISK | AI Act Art. 50 | 90 days | Not required | Required | — |
| MIFID-II | MiFID II Art. 16(7), Reg. 2017/565 | 1827 days5 years | Before execution | Required | EU |
| DORA | DORA Art. 5, 17, 19, 28 | 1827 days5 years | Within 24 hours | Required | EU |
| DSA-VLOP | DSA Art. 15, 34, 37, 40, 42 | 730 days2 years | Within 24 hours | Required | — |
| PAC-AGRICULTURE | Reg. (EU) 2021/2116 | 1096 days3 years | After execution | Required | EU |
Draft-01.1 profile defaults. A profile encodes requirements in the message; selecting one does not by itself establish legal compliance for your system. Explore the profiles →
Same mechanism, other jurisdictions
- HIPAA · US healthcare
- SOX · US finance
- SOC 2
- LGPD · Brazil
- PIPL · China
- APPI · Japan
- POPIA · South Africa
- PDPA · Singapore
- CCPA · California
- NIST AI RMF
- ISO/IEC 42001
- Your framework
Six normative documents
One foundation.
Five primitives.
Written in RFC 2119 normative language. Every structure has a schema, and every rule has test vectors you can run.
Build
From pip install to a signed envelope.
The Python SDK implements Draft-01.1: envelopes, signing, two-layer validation, compliance profiles, encryption and command-line tools.
- 01Install
pip install arsia-protocol, Python 3.12 or later. Add[cli]for thearsiacommand. - 02Create an envelope
Typed constructors for every intent. Set sender, receiver, capabilities and payload.
- 03Apply a profile
Name a profile and
apply_profilefills in its retention, residency and oversight defaults. - 04Sign, verify, validate
Generate an Ed25519 key, sign, then check the signature and both validation layers.
from arsia_protocol import (
apply_profile, create_request, generate_ed25519_keypair,
sign_message, validate_envelope, verify_message,
)
private_key, public_key = generate_ed25519_keypair()
envelope = create_request(
from_agent="agent:acme.advisor",
to_agent="agent:acme.executor",
payload_type="com.acme.trade.execute",
capabilities=["com.acme.trade.execute"],
args={"portfolio_id": "PF-2847"},
compliance={"profile": "MIFID-II"},
)
envelope = apply_profile(envelope) # retention, residency, oversight
signed = sign_message(
envelope, private_key, "agent:acme.advisor#key-1"
)
assert verify_message(signed, public_key)
assert validate_envelope(signed) == []
print("signed, verified, valid")
terminal
- $ pip install arsia-protocol
- $ python quickstart.py
- signed, verified, valid
Community & governance
Built in the open.
Shaped with standards bodies.
The specification is open, the SDK is on PyPI, and the work takes part where agent standards and European AI rules are being written.
Contact
Building with ARSIA?
Implementing the protocol, feedback on the specification, or interest in the beta pilot programme. We’d like to hear from you.
- Maintained by
- Arsia Labs (opens in a new tab)
- Based in
- Portugal, EU