Know who is acting
Link each AI system and agent to an organization, accountable owner, version, and revocable identity.
Every AI should be identifiable. Every agent should be accountable. Every action should be authorized. Every AI system should be continuously verifiable.
MC-1 Trust is in development. The AATS public working draft and proposed certification program do not imply that an agent has been certified.Deployed agents gain memory, tools, credentials, data access, providers, and delegated authority. Each connection can change after a point-in-time evaluation.
MC-1 Trust is being designed as an implementation of the ColomboAI-led, implementation-neutral AATS working draft, linking identity, runtime policy, evidence, assessment, and revocation.
Link each AI system and agent to an organization, accountable owner, version, and revocable identity.
Scope tools, data, resources, delegated authority, and expiry before actions are attempted.
Agent Guard and Guard Edge are intended to apply policy at tool and runtime boundaries.
Collect source, timestamp, control, owner, and integrity proof for each assessment input.
Model, provider, prompt, tool, permission, and memory changes should trigger fresh review.
Trust Passports, registry entries, and APIs are planned to expose scoped, current claims.
Tenant-scoped agent registration, encrypted evidence submission, assessment, advisory decisions, and certificate lookup are implemented in source behind deployment and operator gates. They do not establish an active independent certification program. Data mapping, permission graphs, automated evidence connectors, Trust Passports, and execution-boundary integration remain on the roadmap; availability will be stated per capability after rollout.
Map systems, owners, data paths, authority, and changes.
Run local AATS readiness checks and integrate verification into agent workflows.
Review scoped evidence and test results without unrestricted infrastructure access.
AATS defines proposed control requirements for AI applications and agents. Independent implementations and public review are central to its design.