ACF Doctrine

Glossary

The key terms of the ACF framework, defined. The doctrine, queryable and citable.

ACFAgentic Commerce Framework
First open governance standard for autonomous AI agents. Defines the 4 principles, 4 autonomy levels, 6 maturity dimensions, the DDAO role and 17 methodological cards.
ACF-00
Agent Mandate
Formal document bounding an autonomous agent's decision perimeter, escalation thresholds, technical safeguards and traceability obligations. Cf. ACF-12.
ACF-12ACF-03
Article 49
AI Act article creating a public register of high-risk AI systems. The deployer or provider must register the system before putting it into service. The registration content must be consistent with the internal decision register.
ACF-05ACF-11
Autonomy level
ACF® scale N0 → N3 qualifying an agent's action latitude: N0 assistance, N1 supervised recommendation, N2 conditional execution, N3 autonomous execution.
ACF-01
Controller
Under the GDPR, the entity determining the purposes and means of the processing of personal data. An autonomous AI agent does not erase the controller qualification — it operationalises it.
ACF-13
Criticality
ACF® measure of the potential impact of an agentic decision on the business, legal, human or financial dimension. The ACF-02 matrix crosses dimension × business impact to produce a low/medium/high/critical score.
ACF-02ACF-11
DDAODelegated Decision Agent Officer
ACF®-defined governance role acting as legal guardian of one or more autonomous AI agents. The DDAO approves the mandate, arbitrates out-of-threshold escalations and carries operational accountability for the agent. Not to be confused with the Chief Data & AI Officer (CDAIO), who creates value from AI: the DDAO is its accountability counterpart, independent as the DPO is from the data controller.
ACF-12
Decision Register
Time-stamped, immutable log recording every decision taken by an autonomous agent, with structured inputs, output, applied doctrine version and rationale. Cf. ACF-05.
ACF-05
Decision Sovereignty
ACF® principle P1. The organisation retains ultimate accountability for the decisions taken by its AI agents. Operational delegation never entails responsibility delegation.
ACF-00
Deployer
Under the AI Act, the entity using an AI system under its authority (other than for personal use). The deployer carries its own obligations (notably Articles 26 and 27 for high-risk systems).
ACF-11
Doctrinal Traceability
ACF® principle P2. Every automated decision must be reconstructible after the fact by pointing to the doctrine, rules and data that produced it.
ACF-05
DPIAData Protection Impact Assessment
Impact assessment required by Article 35 GDPR for processing operations at high risk to rights and freedoms. Often mandatory for high-risk AI agents.
ACF-11
GPAIGeneral Purpose AI
Category introduced by the AI Act (Art. 51-55) covering general-purpose foundation models. An agent relying on a GPAI inherits Article 53 obligations and — if the GPAI is systemic-risk — Article 55 obligations.
ACF-11
Kill switch
Human takeover mechanism allowing an agent to be frozen, redirected or revoked at any time. Multi-level: immediate suspension, deferred suspension, permanent revocation. Cf. ACF-07.
ACF-07ACF-14
Provider
Under the AI Act, the entity that develops or has developed an AI system and places it on the market or puts it into service under its own name. The provider carries most of the obligations for high-risk systems.
ACF-11

ACF doctrine v1.0 · fingerprint bf0b6d8e4731. Source of truth: the official ACF MCP server.