AATS is an open framework for continuously establishing and verifying trust in AI applications and autonomous agents.
Status: v0.9 public working draft. This repository is a proposed specification, not an accredited certification scheme. No certificate or badge may be represented as independently issued until an independent assessor has evaluated the defined scope and signed its decision.
The standard is implementation-neutral. An organization can satisfy AATS with its own identity, policy, enforcement, logging, evaluation, and evidence systems; MC-1 is one possible implementation. AATS applies to a deployed system, including its model, harness, memory, tools, identity, permissions, data, providers, and runtime environment. It does not certify a model in isolation.
- Normative specification
- 25 control domains
- Assurance and certification
- JSON schemas
- Examples
- Governance
- Crosswalk method
MUST, MUST NOT, SHOULD, and MAY are normative terms. A requirement is assessed against a declared system boundary and capability level. MUST is required unless a documented, independently reviewed non-applicability determination proves the capability or resource does not exist in scope. A compensating control requires an explicit assessor decision and cannot silently turn a failure into a pass.
This draft is ColomboAI-led and open for technical comment. Proposed changes follow CONTRIBUTING.md and governance/README.md. Feedback is especially welcome on control testability, privacy-preserving evidence, independence of assessment, and interoperability.
Always spell the standard AATS. AATS Certified denotes a valid independent assurance decision for a specified scope and class. MC-1 Trust Verified denotes a technical verification service and is a separate claim. A readiness score is neither certificate nor assessor opinion.