AICM: agent controls with the CSA Agentic Trust Framework and AARM specification
Agent-specific AICM controls (e.g. IAM-18 Agent Access Restriction, AIS-11 Agents Security Boundaries), with the Agentic Trust Framework v1 (earned autonomy tiers) and the AARM runtime-interception specification
AIGE-OBL-CSA-AICM-AGENTIC. Drawn from chapter 08.
Text alternative
- Clause: CSA AICM, Agent controls.
- Duty holder: Not stated.
- Applies from: No date, Voluntary.
- Artefact: Agent-specific control definitions.
- Layers: Layer 01, Layer 04.
- Evidence record: Evidence record v1.
- Record schema: Evidence record.
- No crosswalk topic files this clause yet.
- Id
AIGE-OBL-CSA-AICM-AGENTIC- Instrument
- CSA AI Controls Matrix (AICM) v1.1 controls
- Clause
- Agent controls (AICM v1.1, ATF, AARM)
- Applies from
- No date Voluntary · AICM v1.1 published 2026-06-22, Agentic Trust Framework v1 in February 2026; the "Agentic Control Supplement" of earlier editions could not be matched to a CSA primary document as of 2026-09-24 (to be confirmed)
The artefact that evidences it
Agent-specific control definitions; policy-as-code for agent scope and tools; runtime guardrails.
Patterns that build it
No pattern in the catalogue names this clause on its "Maps to" line yet; the artefact above is the engineering answer.
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-EVAL-001Authorization Boundary (Evaluation environment profile) -
AIGE-CTL-AGENT-002Its own identity (Agent runtime profile) -
AIGE-CTL-AGENT-005Tool allow-list, deny by default (Agent runtime profile) -
AIGE-CTL-AGENT-007Runtime guardrail on every tool call (Agent runtime profile) -
AIGE-CTL-AGENT-015Checkpoints on irreversible actions, failing closed (Agent runtime profile) -
AIGE-CTL-AGENT-017Output and egress filter (Agent runtime profile) -
AIGE-CTL-AGENT-020MCP authorisation (spec 2026-07-28) (Agent runtime profile) -
AIGE-CTL-AGENT-021Replace long-lived secrets with short-lived credentials (Agent runtime profile) -
AIGE-CTL-AGENT-022Delegation, never impersonation (Agent runtime profile) -
AIGE-CTL-AGENT-025Accountability across hops (Agent runtime profile) -
AIGE-CTL-AGENT-026Stopping third-party agents at your boundary (Agent runtime profile)
Source
Chapter 08, section CSA AICM and STAR for AI, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-csa-aicm-agentic.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). AICM: agent controls with the CSA Agentic Trust Framework and AARM specification (AIGE-OBL-CSA-AICM-AGENTIC). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{AICM: agent controls with the CSA Agentic Trust Framework and AARM specification (AIGE-OBL-CSA-AICM-AGENTIC)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic},
note = {Version 0.5.0}
}