By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. What the ATF is
  2. Why it appeared now
  3. How it is structured
  4. ATF and MAESTRO
  5. How to use it
  6. FAQ

TL;DR

  • The Cloud Security Alliance published the Agentic Trust Framework (ATF) on 2 February 2026. It is the first governance specification to apply Zero Trust principles specifically to autonomous AI agents, with a structured maturity model.
  • It was authored by Josh Woodruff (founder of MassiveScale.AI) and Michelle Savage. John Kindervag, who originated the Zero Trust model, wrote the foreword to the companion book rather than co-authoring the framework, a distinction worth preserving.
  • A companion CSA survey of 285 IT and security professionals reported that 84% of organisations could not pass a compliance audit focused on agent behaviour or access controls, and only 23% had a formal agent identity strategy.
  • It is a published industry framework, not a standard: five core elements, four maturity levels, released under CC BY 4.0 on GitHub. Not certifiable, not regulatory, and not auditable in the way ISO/IEC 42001 is.
  • Its practical value is as a gap-assessment instrument and a vocabulary, particularly where you need to explain agent risk to a board that already understands Zero Trust.

What the ATF is, and what it is not

The Agentic Trust Framework extends Zero Trust from network and human-access contexts to autonomous software agents. The core argument is a direct translation: if the Zero Trust axiom is "never trust, always verify," then an agent that has been granted standing authority and operates without per-action verification is a Zero Trust violation by construction, regardless of how well it was authenticated at provisioning time.

Classification

Published framework, industry body, non-normative. The CSA is an industry association, not a standards development organisation in the ISO or IETF sense. ATF conformance is not certifiable and no regulator references it. Treat it as authoritative guidance, in the same tier as CSA's other program guides. Useful, credible, and not a compliance obligation. Compare with CSA's NHI program guide, which occupies the same tier for non-human identity generally.

Why it appeared when it did

The survey data published alongside the framework explains the timing better than the framework text does. Two numbers carry the argument:

  • 84% cannot pass an agent-focused compliance audit. Not "have gaps". Cannot pass. That is a statement about the absence of evidence, not the absence of controls.
  • 23% have a formal agent identity strategy. Which means roughly three quarters of organisations deploying agents are doing so without having decided how agents get identities at all.

Sourcing note: these figures come from a survey of 285 practitioners published by CSA together with Strata Identity, a vendor in this market. They are self-reported, and the sampling and question wording have not been independently reproduced. A third figure from the same survey: only 18% were confident their existing IAM could manage agent identities. They are directionally credible and consistent with what we see in assessments. We would not build a business case on the precise percentages. This is the same caution we would apply to any vendor-published or association-published statistic. See our editorial policy on sourcing.

How the framework is structured

ATF is built from five core security elements, each of which must be present before an agent operates at any level, layered so that identity is established before behaviour is monitored and data is validated before actions are taken. Incident response wraps the others.

Its most distinctive feature is the maturity model. Rather than binary trust, agents progress through four levels named after human career stages, from Intern up to Principal. Agents earn autonomy through demonstrated trustworthiness rather than receiving it by default, promotion between levels requires passing defined gates, and an agent can be demoted at any time, a critical incident triggers immediate demotion to Intern.

Why the career-stage metaphor works better than it should

The naming looks like a gimmick and is not. It gives a security team a vocabulary a business owner already understands: nobody argues that a new intern should have unsupervised production access, and nobody argues that a principal earned their autonomy by default. That translation is the framework's most practically useful contribution, and it is why ATF communicates upward better than more technically rigorous documents.

The gap between having an agent inventory and having agents that could be scored against these levels at all is where almost all real programme work sits, and it is not a tooling problem. It is the organisational work of finding an owner for every agent and removing borrowed credentials. See agent identity standards for the protocol layer underneath.

ATF and MAESTRO

CSA's MAESTRO threat modelling framework is the companion artefact most people should read alongside ATF. Its relevance to identity is that it names agent impersonation as a distinct threat class: an adversary deceiving users or other agents by presenting as a legitimate agent. The prescribed mitigations are trusted agent registries, cryptographic agent identities, and short-lived credentials.

Those three mitigations keep recurring independently across the CSA work, the IETF drafts, and the NIST NCCoE convening. When three efforts with different constituencies converge on the same three controls, that convergence is a stronger planning signal than any single framework's endorsement. See our agent identity standards map for how those controls map to specific protocols.

How to actually use it

ATF is most useful as a gap-assessment instrument and least useful as an implementation plan. A defensible sequence:

  1. Score honestly against the maturity model first. The value is in discovering you are at stage 1, not in the framework's prose. Most organisations are.
  2. Use the Zero Trust lineage to communicate upward. A board that has already funded Zero Trust understands "we granted standing authority to software that acts autonomously" without further explanation. This is the framework's single greatest practical asset.
  3. Map ATF findings onto controls you can actually evidence. ATF itself is not auditable. If you need audit-grade evidence, map to EU AI Act obligations or an ISO/IEC 42001 AI management system, and use ATF to identify what belongs in scope.
  4. Do not wait for edition two. Nothing in the stage 2-to-3 work depends on framework detail that does not yet exist.

Red-team note on first-edition frameworks

Note the commercial interest. ATF was authored by MassiveScale.AI, a consultancy that offers guided implementation, training, and certification against the framework, and published through an association with vendor members. That does not make the framework wrong, most good frameworks are written by people who sell the expertise, but it is a disclosure the framework text does not foreground and you should hold in mind. ATF is a first edition in a fast-moving domain. Expect the taxonomy to shift, expect vendors to claim alignment with it in ways the text does not support, and expect at least one competing agent-governance framework from a different body within eighteen months. None of that makes it unusable. It does mean you should adopt its vocabulary and maturity structure rather than treating its control list as a target state.

Frequently asked questions

Is the CSA Agentic Trust Framework certifiable?

No. The ATF is a published industry framework from an association, not a certifiable standard. There is no accredited certification scheme against it and no regulator references it. If you need certifiable AI governance, ISO/IEC 42001 is the relevant standard; ATF can help you decide what belongs in that scope.

Who wrote the Agentic Trust Framework?

It was published by the Cloud Security Alliance on 2 February 2026 and authored by Josh Woodruff of MassiveScale.AI and Michelle Savage. John Kindervag, who originated the Zero Trust model, wrote the foreword to the companion book rather than co-authoring the framework itself. The specification is released under CC BY 4.0 on GitHub.

What is the difference between ATF and MAESTRO?

ATF is a governance and maturity framework: how to structure an agent governance programme. MAESTRO is a threat modelling framework: what can go wrong. They are complementary, and MAESTRO's naming of agent impersonation as a distinct threat class, with trusted registries and cryptographic identities as mitigations, is the part most directly relevant to identity teams.

Does ATF replace the CSA NHI program guide?

No. The NHI program guide addresses non-human identity broadly, including service accounts, secrets, and workload credentials. ATF addresses autonomous agents specifically, which are one category of non-human identity with distinctive properties. Most organisations need both, and the NHI inventory work is a prerequisite for the agent work.

Is the 84% audit-failure statistic reliable?

It comes from CSA's own survey of 285 IT and security professionals, self-reported, and the sampling methodology and question wording have not been independently reproduced. It is directionally credible and matches what we see in practice, but we would not use the precise figure in a business case without noting its provenance.

Assess your own NHI programme.

Run the free maturity assessment or the OWASP NHI Top 10 self-audit, get your score in the browser, and unlock the full written report.

Deep dive: Agent registries