Normative Specification

ACR Runtime Control Plane Standard

Version 1.0.1. The normative specification for runtime enforcement of autonomous AI systems. This document defines the minimum conditions under which AI systems can be considered controlled.

PDF

Download the Full Standard

ACR Runtime Control Plane Standard v1.0.1, branded and formatted for distribution, compliance review, and audit reference.

30 sections including annexes with policy schemas, enforcement flow examples, and audit checklists.

What This Standard Covers

Document Structure

The ACR Standard is organized into 30 sections covering the complete lifecycle of runtime AI control. Each normative section defines testable, implementation-independent requirements with verification considerations for assessors.

§1-8

Foreword, Scope, and Definitions

Establishes the purpose, boundaries, normative references, and terminology for the standard.

§9-10

System Model and Trust Path

Defines the runtime control plane as the mandatory enforcement layer and the 9-step trust path every protected action must traverse.

§11-12

Failure Conditions and Core Principle

Specifies fail-secure behavior for control plane unavailability, policy engine failures, and bypass detection.

§13-14

Control Plane and Decision Engine

Requirements for pre-execution control, deny-by-default behavior, and the four-state decision model: ALLOW, DENY, MODIFY, ESCALATE.

§15

Identity and Purpose Binding

Every agent must carry a unique identity, declared purpose, and cryptographically verifiable constraints.

§16

Policy Enforcement

Machine-enforceable policy at Input, Execution, and Output boundaries with versioned definitions and audit trails.

§17

Drift Detection

Behavioral baselines, normalized drift scores, and graduated response tiers from throttle through kill.

§18

Observability

Comprehensive telemetry, tamper-evident logging for high-risk events, and audit-ready export without manual reconstruction.

§19

Containment

Kill capabilities outside the agent runtime, graduated isolation, safe-state definitions, and quarterly testing.

§20

Human Authority

Risk tiering, escalation matrices, approval gating, break-glass controls, and human override that remains operable during agent failure.

§21

STRIKE Threat Mapping

Full traceability matrix mapping Spoofing, Tampering, Reflection Abuse, Information Leakage, Kill Chain Extension, and Emergence to controls and evidence.

§22-24

Integration, Conformance, and Security

Three cumulative conformance levels (Observability, Enforcement, Full Runtime Control Plane Compliance), integration architecture, and security assumptions.

Conformance

Three Cumulative Levels

Conformance is cumulative. Each successive level builds on the requirements of the previous one. A system claiming Level 3 must satisfy all requirements from all three levels.

1

Observability

  • Action and decision logging
  • Correlation identifiers
  • Agent identity and purpose records
  • Audit export capability
  • Minimum retention enforcement
2

Enforcement

  • Mandatory pre-execution control
  • Deny-by-default behavior
  • Identity and purpose binding
  • Executor-side verification
  • Containment with kill path
3

Full Runtime Control Plane

  • Three-boundary enforcement
  • Four-state decision model with MODIFY
  • Drift detection with thresholded response
  • STRIKE traceability matrix
  • Quarterly containment testing
Core Requirements

What the Standard Mandates

Pre-Execution Control

All protected AI actions MUST be evaluated by the control plane before execution. No bypass path is permitted.

Four-State Decision Model

Every action resolves to ALLOW, DENY, MODIFY, or ESCALATE. Precedence is deterministic: DENY > ESCALATE > MODIFY > ALLOW.

Fail-Secure Behavior

Control plane unavailability, policy engine failure, or identity validation failure MUST prevent execution and log the failure.

Tamper-Evident Logging

High-risk events MUST be stored in tamper-evident or append-only form. All ACR events retained for at least 90 days.

30-Second Kill Path

The kill capability MUST operate outside the agent runtime and complete within 30 seconds from activation to enforcement.

STRIKE Traceability

Each of the six STRIKE categories MUST map to control layers, detection mechanisms, response actions, and evidence artifacts.

Ready to Implement?

The ACR Standard is implementation-independent. Explore the architecture, control specifications, and STRIKE framework to begin aligning your AI systems with runtime enforcement requirements.