PublishedGuidanceLAST REVIEWED · 30 AUG 2026
AATS control model
How the proposed AI & Agentic Trust Standard evaluates deployed systems.
Control domains
AATS v0.9 is a public working draft. Its 25 domains cover identity, accountability, permissions, data privacy and isolation, memory, models, providers, tools, agent-to-agent trust, containment, instruction security, action controls, oversight, observability, changes, behavior, adversarial tests, incidents, supply chain, reliability, and continuous assurance.
Capability gates
- Level 0: Informational AI.
- Level 1: Read-only agent.
- Level 2: Tool-using agent.
- Level 3: Write-capable agent.
- Level 4: High-impact autonomous agent.
- Level 5: Critical autonomous system.
Proposed assurance states
ACTIVE, DEGRADED, REVIEW REQUIRED, SUSPENDED, REVOKED are proposed assurance states. A transition should carry cause, timestamp, owner, and evidence reference. Unknown or unassessed must never be displayed as ACTIVE.
Was this page helpful?