AATS v0.9 · PUBLIC WORKING DRAFT

AI & Agentic
Trust Standard.

AATS is an open framework for continuously establishing and verifying trust in AI applications and autonomous agents. The proposed requirements are independent of MC-1.

Read the working draft ↗Discuss participation →
This working draft is open for technical review. AATS is not represented as an adopted industry standard or an available certification.
CONTROL MODEL

Twenty-five domains.
One changing system.

Controls cover the whole deployed system: identity, data, models, providers, tools, action authority, runtime behavior, and recovery. Proposed tests and evidence expectations are in the draft catalog.

  1. AATS-01AI system identity
  2. AATS-02Human accountability
  3. AATS-03Agent authorization
  4. AATS-04Least privilege
  5. AATS-05Data privacy
  6. AATS-06AI data isolation
  7. AATS-07Memory governance
  8. AATS-08Model governance
  9. AATS-09Provider governance
  10. AATS-10Model routing integrity
  11. AATS-11Tool security
  12. AATS-12Agent-to-agent trust
  13. AATS-13Agent containment
  14. AATS-14Prompt and instruction security
  15. AATS-15Autonomous action controls
  16. AATS-16Human oversight
  17. AATS-17Observability
  18. AATS-18Change management
  19. AATS-19Behavioral assurance
  20. AATS-20Adversarial evaluation
  21. AATS-21Incident detection
  22. AATS-22Incident response
  23. AATS-23Supply chain trust
  24. AATS-24Reliability
  25. AATS-25Continuous assurance
Read control requirements →
CAPABILITY GATES

Greater authority
requires stronger evidence.

The proposed gates scale requirements with an agent’s ability to read, use tools, write, or affect critical systems. Proposed classes are AATS-AI, AATS-Agent, AATS-Autonomous, AATS-Critical, and AATS-Enterprise.

  1. LEVEL 0Informational AI
  2. LEVEL 1Read-only agent
  3. LEVEL 2Tool-using agent
  4. LEVEL 3Write-capable agent
  5. LEVEL 4High-impact autonomous agent
  6. LEVEL 5Critical autonomous system
CONTINUOUS CERTIFICATION DESIGN

Status should change
when evidence changes.

The proposed states are ACTIVE, DEGRADED, REVIEW REQUIRED, SUSPENDED, REVOKED. Each transition requires an attributable cause and evidence. A numeric readiness score alone never substitutes for an independent assessment.

AATS PRINCIPLE

Open specification

Requirements and test methods should be implementable without ColomboAI software.

AATS PRINCIPLE

Independent evaluation

Evaluators need scoped evidence, reproducible tests, and their own auditable access.

AATS PRINCIPLE

Public governance

Versioning, RFCs, conflicts, and technical stewardship will be documented before v1.0.

Read governance proposal →
AATS — AI & Agentic Trust Standard | ColomboAI