ACF Doctrine
Glossary
The key terms of the ACF framework, defined. The doctrine, queryable and citable.
- ACFAgentic Commerce Framework
- First open governance standard for autonomous AI agents. Defines the 4 principles, 4 autonomy levels, 6 maturity dimensions, the DDAO role and 17 methodological cards.
- ACF-00
- Agent Mandate
- Formal document bounding an autonomous agent's decision perimeter, escalation thresholds, technical safeguards and traceability obligations. Cf. ACF-12.
- ACF-12ACF-03
- Article 49
- AI Act article creating a public register of high-risk AI systems. The deployer or provider must register the system before putting it into service. The registration content must be consistent with the internal decision register.
- ACF-05ACF-11
- Autonomy level
- ACF® scale N0 → N3 qualifying an agent's action latitude: N0 assistance, N1 supervised recommendation, N2 conditional execution, N3 autonomous execution.
- ACF-01
- Controller
- Under the GDPR, the entity determining the purposes and means of the processing of personal data. An autonomous AI agent does not erase the controller qualification — it operationalises it.
- ACF-13
- Criticality
- ACF® measure of the potential impact of an agentic decision on the business, legal, human or financial dimension. The ACF-02 matrix crosses dimension × business impact to produce a low/medium/high/critical score.
- ACF-02ACF-11
- DDAODelegated Decision Agent Officer
- ACF®-defined governance role acting as legal guardian of one or more autonomous AI agents. The DDAO approves the mandate, arbitrates out-of-threshold escalations and carries operational accountability for the agent. Not to be confused with the Chief Data & AI Officer (CDAIO), who creates value from AI: the DDAO is its accountability counterpart, independent as the DPO is from the data controller.
- ACF-12
- Decision Register
- Time-stamped, immutable log recording every decision taken by an autonomous agent, with structured inputs, output, applied doctrine version and rationale. Cf. ACF-05.
- ACF-05
- Decision Sovereignty
- ACF® principle P1. The organisation retains ultimate accountability for the decisions taken by its AI agents. Operational delegation never entails responsibility delegation.
- ACF-00
- Deployer
- Under the AI Act, the entity using an AI system under its authority (other than for personal use). The deployer carries its own obligations (notably Articles 26 and 27 for high-risk systems).
- ACF-11
- Doctrinal Traceability
- ACF® principle P2. Every automated decision must be reconstructible after the fact by pointing to the doctrine, rules and data that produced it.
- ACF-05
- DPIAData Protection Impact Assessment
- Impact assessment required by Article 35 GDPR for processing operations at high risk to rights and freedoms. Often mandatory for high-risk AI agents.
- ACF-11
- GPAIGeneral Purpose AI
- Category introduced by the AI Act (Art. 51-55) covering general-purpose foundation models. An agent relying on a GPAI inherits Article 53 obligations and — if the GPAI is systemic-risk — Article 55 obligations.
- ACF-11
- Kill switch
- Human takeover mechanism allowing an agent to be frozen, redirected or revoked at any time. Multi-level: immediate suspension, deferred suspension, permanent revocation. Cf. ACF-07.
- ACF-07ACF-14
- Provider
- Under the AI Act, the entity that develops or has developed an AI system and places it on the market or puts it into service under its own name. The provider carries most of the obligations for high-risk systems.
- ACF-11
ACF doctrine v1.0 · fingerprint bf0b6d8e4731. Source of truth: the official ACF MCP server.