Skip to content

Reporting & framework relationships

An ATF report should identify:

  • Agent, version, owner and purpose.
  • Current and target level.
  • Requirement results by element.
  • MUST gaps and SHOULD exceptions.
  • Evidence and testing depth.
  • Open incidents and findings.
  • Promotion-gate position.
  • Decision, conditions, approvers and review trigger.

Do not report a level without its scope and basis.

Portfolio views can show:

  • Agents assessed versus registered.
  • Current and target level distribution.
  • Readiness by element.
  • Agents held below requested authority.
  • Common MUST gaps.
  • Weak evidence or overdue tests.
  • Incidents, demotions and promotion reviews.

A portfolio average must not conceal a high-authority agent with a failed containment requirement.

Prefer:

The selected agent was assessed against ATF Specification 0.9.1 for a target of L2 Junior. The current record supports maintaining L1 pending completion of action-boundary testing and the Security Validation gate.

Avoid:

  • “ATF certified.”
  • “Zero trust compliant” without scope and evidence.
  • “Safe for autonomous operation.”
  • “All agentic risks eliminated.”

ACRS characterises capability risk: what the system can do and how much impact that capability creates. ATF governs how authority is earned and constrained.

A high ACRS position should increase assurance and testing depth and may justify a lower initial ATF level. It does not mechanically decide a requirement result or promotion.

MAESTRO identifies layer-specific agentic threats. ATF establishes zero-trust governance controls that help prevent, detect and contain them.

Use MAESTRO findings to challenge ATF requirements. For example, tool and orchestration threats should inform action-boundary, attribution, injection-defence and containment tests.

GTSAF provides the wider assurance baseline across governance, data, models, security, people, suppliers and operations. ATF focuses on runtime trust for a named agent.

Crosswalks support traceability and evidence reuse; they do not create automatic equivalence.

  • NIST AI RMF provides the broader risk-management outcomes.
  • ISO/IEC 42001 provides the organisational AI management system.
  • ISO/IEC 42005 examines impacts on people and society.
  • EU AI Act and NAGF determine applicable legal and regulatory obligations.

ATF does not replace any of these. The agent may need all of them.

  • Is requested autonomy proportionate to capability risk?
  • Do threat findings change the target level or testing plan?
  • Is every cross-framework evidence reuse verified for this agent?
  • Are incident and demotion trends visible to accountable governance?
  • Does the report distinguish conformance assessment from certification?