What is the Agentic Trust Framework (ATF)?
The Cloud Security Alliance open specification applying zero trust to AI agents through maturity levels.
The Agentic Trust Framework (ATF) is a governance specification published on February 2, 2026 by the Cloud Security Alliance, the non-profit that has defined cloud security standards and best practices since 2009, and it applies zero trust principles specifically to autonomous AI agents. The framework rests on a single principle, agentic zero trust: no agent is trusted by default, regardless of stated purpose or claimed capability, and trust must be earned through demonstrated behavior and continuously verified through ongoing monitoring. The ATF is organized around five core security elements and four maturity levels an agent moves through progressively, from an initial deployment under close supervision up to growing autonomy granted only after passing explicit, documented checks. It is published as an open specification under Creative Commons licensing, designed to be implemented with open source tooling companies already have in place, without tying adoption to a specific vendor product or cloud service.
Why the general zero trust principle is not enough
Zero trust as an architectural principle, no identity is trusted by default, continuous verification, least privilege, has existed for years and already applies regardless of agents. The ATF does not reinvent it: it translates it into an operating model with concrete criteria built for a kind of actor the general principle had not yet had to face, an agent that plans its own actions, chooses among different tools and changes behavior at runtime. A dedicated framework is needed because "verify every access" alone does not tell a company when an agent can move from read-only tasks to actions that change production data, or who has to approve that move.
How the maturity levels work
Agents enter the ATF at the lowest level, with minimal permissions and close human supervision, and climb only after demonstrating accuracy and reliability measured over time, passing a security audit proportionate to the target level, showing verifiable positive impact, and having a clean recent operational history. Promotion also requires explicit approval from an authorized stakeholder: autonomy is never granted by default, and it is revocable at any time, with a critical incident able to demote an agent immediately back to the lowest level. The framework also aligns with the threats described by the OWASP Agentic Security Initiative.
Why it matters now
Companies are moving from early pilots with total supervision toward deployments with real autonomy on production systems, and they often do it without a written criterion for deciding when an agent has earned more operating freedom. This is exactly the governance gap that drives the uncontrolled growth of non-human identities inside a company: knowing an agent exists and holds credentials is not enough, a criterion is needed to decide how much it can be trusted today compared to six months ago. The CSA folded the ATF into the CSAI Foundation in April 2026, a signal the framework is now a consolidated reference rather than an isolated experiment.
An enterprise example
A bank introducing an agent to handle customer support tickets starts it at the lowest ATF level: it can only read tickets and draft candidate replies, and every action passes through a human operator. After weeks of measurably error-free operation, a passed security audit and sign-off from an IT lead, the agent moves up a level and can send autonomous responses to low-risk requests, while remaining under continuous monitoring and subject to immediate demotion if a single incident undermines the trust it earned.
Why it matters for decision makers
For whoever has to structure AI agent governance inside a company, the ATF offers something the zero trust principle alone does not: a gradual, verifiable path, with objective thresholds, for deciding when an agent deserves more autonomy and how to strip it away quickly once it stops deserving it. Adopting it does not require a specific product, but it does require deciding in advance what "maturity level" means for each use case, before agents are already in production with permissions nobody has time left to review.
Frequently asked questions
Related terms
- Non-Human Identity (NHI) · A digital identity that belongs to software, not a person: service accounts, pipelines, bots and now AI agents acting on company systems.
- Zero Trust · A security model where no identity, human or machine, is trusted by default: every access is verified and granted with minimum privilege.
- AI governance · The policies, roles and controls governing AI use in a company: system inventory, risk classification, approval flows and monitoring.
- AI red teaming · Systematic attack testing on an AI system, before and after deployment, to find prompt injection, jailbreaks and data poisoning before real attackers do.
- Guardrails · Technical controls that limit what an AI system can say or do: filters, policies, permissions, and a human in the loop where needed.
A term that hits close to home? Let's talk.
CONTACT ME