The first open, verifiable standard for governing autonomous AI agents.
An open, verifiable standard for governing autonomous AI agents — the five questions every agent must answer (ASDAR: Authority, Scope, Data, Audit, Revocation), the four tiers that grade the answers, and the one principle that makes them mean anything: govern before execution.
F-ACT: the Framework, the Foundation, the Function, the Fiduciary duty
— before the agent ACTs.
Governments and standards bodies are still drafting the rules for autonomous AI agents. The vocabulary they land on will decide how every agent is judged. F-ACT is that vocabulary — published, versioned and free to cite — stewarded by Society OS and dated August 19, 2026.
ASDAR
The five questions
4
Conformance tiers
v1.0
Published & versioned
Open
Free to cite & adopt
A standard for agent governance must require that policy is enforced at the moment of action — checked before an agent acts, and able to stop the action if the answer is no. Watching an agent and raising an alert after the fact is not governance; it is a record of what already went wrong. F-ACT is built on prevention: the answer to “is this allowed?” is decided before the consequence exists, not explained after it.
Every agent under the standard must answer all five. They are the normative core of F-ACT — the same five whether the agent books a meeting or moves money. Together they spell ASDAR (AZ-dar) — one handle a policy, a contract or a procurement questionnaire can name in a single line.
Clause 2
Scope
What is this agent permitted to do — and what is explicitly out of bounds?
Requirement. Permitted actions must be declared in advance. Anything not within scope is denied by default, not allowed by omission.
Why. Open-ended agents fail open. A standard has to make the boundary explicit and make the default deny, so a gap in the rules is never a licence to act.
Clause 3
Data
What data may it touch, on what basis, and where may that data go?
Requirement. Every data touch must have a lawful basis and a permitted destination. Data leaving its allowed boundary is a conformance failure.
Why. Most agent harm is a data event — the wrong information reaching the wrong place. Governing the data path is inseparable from governing the agent.
Clause 4
Audit
Is every consequential action recorded in a form that survives a dispute?
Requirement. Consequential actions must produce a tamper-evident record — one that can be shown to be unaltered, not merely a log that can be edited later.
Why. An audit trail only matters if it holds up when challenged. A record that can be quietly changed proves nothing when it counts.
Clause 5
Revocation
Can its authority be withdrawn instantly — and proven withdrawn?
Requirement. Authority must be revocable in real time, and the revocation must be verifiable by a third party. A credential that cannot be cleanly killed is not governed.
Why. The moment you cannot stop an agent is the moment you no longer govern it. Revocation is the difference between control and hope.
A standard needs a ladder, not a badge. Each tier is a higher bar of proof — and the top two can only be reached by governing before execution.
Unattested
The agent answers none of the five questions. Its authority, scope and data path are unknown.
No governance envelope. The default state of most deployed agents today.
Declared
The agent can answer all five questions. Its governance is documented and inspectable.
A complete, readable answer to Authority, Scope, Data, Audit and Revocation exists.
Enforced
The answers are binding. Actions outside policy are stopped before they execute — not merely flagged after.
Policy is checked at the moment of action, and a “no” prevents the action.
Provable
Enforcement leaves tamper-evident, admissible evidence, and authority can be revoked and proven revoked in real time.
Every enforced decision is independently verifiable, and revocation is instant and provable.
Systems that watch an agent and react after the fact can, at best, reach Declared (L1) — they can describe the answers but cannot enforce or prove them, because the action has already happened. Enforced (L2) and Provable (L3) are defined by prevention.
F-ACT Verified is the conformance mark of the standard — the receipt that says which tier an agent has actually earned. A conformity mark is only worth what its usage rules enforce, so these rules are published, not implied. They bind anyone who displays the mark.
Display only the tier you hold
The mark must state the exact F-ACT tier (L0–L3) recorded for that agent, and nothing higher. Claiming Enforced or Provable while holding a lower tier is misuse of the mark.
The mark points to its own proof
Every displayed mark must resolve to its public verification page, where anyone can confirm the tier and status without logging in or asking us. A mark that cannot be checked is decoration, not conformance.
A revoked or suspended mark is not a live claim
The moment a mark is revoked, suspended or expired it must not be presented as an active conformance claim. Status travels with the mark: what the public verification page shows is the truth, and it overrides any cached badge.
One mark, one accountable subject
An F-ACT Verified mark attaches to a single named agent or entity resolving to an accountable human principal. It may not be reused across agents or presented to imply conformance the named subject has not earned.
The steward is measured by the same rules
Society OS earns its own F-ACT Verified marks under these exact rules, at the tier its own evidence supports — no self-exemption. The mark means the same thing on our surfaces as on anyone else’s.
These rules make the mark falsifiable on purpose: anyone can catch a misused F-ACT Verified claim by checking it against the public registry. That is the point — a claim you can disprove in one click is worth more than a badge you simply have to trust.
One house stewards the standard and issues the mark — here is why that is safe
Society OS both maintains F-ACT and issues the F-ACT Verified mark. We name that concentration rather than hide it, because a conformity mark is only worth the independence you can verify. Four structural facts keep the mark honest even while both roles sit under one roof:
The mark is not a toll gate
The standard is open and free. Anyone can implement F-ACT and self-attest a tier without ever displaying the mark. F-ACT Verified is a convenience for proving a claim, never a gate you must pay us to pass.
You trust the proof, not our word
Every F-ACT Verified mark resolves to a public verification page you check against the registry. Conformance is capability, not permission — we cannot grant a tier that the evidence does not support, and we cannot inflate one without being caught in one click.
Ownership of the rules is being separated from the company
The core claims of F-ACT are being placed with a neutral Swiss foundation, licensed back to Society OS on the same non-exclusive terms available to anyone. The body that owns the standard is being pulled apart from the company that sells products against it.
The mark is built to be issued by others
Society OS earns its own marks under the identical rules — no self-exemption — and independent verification is a first-class path, not an afterthought. The scheme is designed so third parties can issue and check the mark, not only us.
Where this is heading: as the Society OS Foundation stands up, issuance and verification of the mark move to it and to accredited third parties — completing the separation between the body that owns the standard and the company that builds products against it. Until then, the guardrails above are what keep the mark honest.
ASDAR is not aspirational. It is the checklist enterprise buyers and regulators arrived at independently in 2026 — before anyone handed them the words. The standard names it, orders it, and makes it gradeable.
Authority
Regulators now reject agents that run under a single shared service account; NIST calls for unique, enterprise-grade agent identities that resolve to an accountable sponsor.
Scope
The 2026 buyer bar demands task-scoped, least-privilege permissions and blast-radius limits — not broad, persistent keys.
Data
Due-diligence questionnaires require mapped data flows, lawful basis and residency — the inputs to EU AI Act Article 12 logging.
Audit
Buyers no longer accept operational telemetry; they require per-decision, tamper-evident records tying every action to a policy version and a human sponsor.
Revocation
Procurement now specifies kill-switches with sub-five-minute termination windows and just-in-time privileges revoked on task completion.
The 2026 backdrop is not theory — it is already in force
EU AI Act — enforcement live
Enforcement for general-purpose AI began 2 August 2026, with penalties up to €15M or 3% of global turnover. Article 12 already mandates automatic event logging; ASDAR is the shape that logging has to take at the level of the individual agent action.
ISO/IEC 42001 — certifiable, and now European
The first certifiable AI management standard became a European norm (EN ISO/IEC 42001:2026) in March 2026, with national adoption underway across 34 countries. It governs the management system; ASDAR governs the individual agent action that system has to produce evidence for.
Identity is being standardised; authority is not
The Linux Foundation now stewards the Model Context Protocol and NIST launched an AI Agent Standards Initiative in 2026. Both answer “which agent is this?”. Neither answers “was this specific action authorised, and can you prove it?” — the square ASDAR occupies.
The obligations are now statutory and the management standards are certifiable — but both stop above the individual agent action. What is still unclaimed is the open, citable vocabulary for proving a specific agent was authorised before it acted. That is the square F-ACT names.
F-ACT is an open standard. Conformance is defined by capability, not permission: any implementation — any vendor, any language, any stack — that meets a tier’s published criteria conforms to that tier. No product, membership, or sign-off from the steward is required to reach any tier, and none can be withheld.
Capability, not permission
A tier is reached by meeting its published criteria in a way an independent third party can check — never by approval from the steward. If you can prove it, you conform.
The steward is not a gatekeeper
Society OS maintains the specification and its versions; it does not decide who may implement it. Its own products are measured against the same tiers, on the same evidence, as anyone else’s.
Free to read, cite, implement and require
The standard is published to be used — in policy, in procurement, in vendor questionnaires, and in competing products. A standard only one company can meet is not a standard; this one is written to be met widely.
The core claims of F-ACT are pledged never to be asserted against anyone. The pledge covers any use — including, but not limited to, conformance. It is irrevocable, royalty-free and worldwide. The claims are being placed with a neutral Swiss foundation so no company can ever take them back.
Anyone may use, implement, build on, or require the core claims of F-ACT — including L3 Provable — without a licence and without asking, for any purpose and by any method. Conformance is one use among many, not a condition.
The pledge
Society OS Pty Ltd (“Society OS”), as current owner of the core patent claims, pledges not to assert those claims against any person or organisation that uses, implements, builds on, distributes, or requires the normative requirements of the Framework for Agent Conformance & Trust (F-ACT) specification, version 1.0 and any subsequent version published under this pledge. The pledge covers any use of the core claims — including, but not limited to, conformance. It is irrevocable, royalty-free, and worldwide, and it binds every successor and assign, including the Society OS Foundation to which the core claims are being transferred (see “Who holds the core claims”).
What is covered
The pledge covers any use of the core claims of F-ACT — the observable, checkable outcomes published in the specification: the five governance clauses (Authority, Scope, Data, Audit, Revocation) and the requirement that every agent answer them; the four conformance tiers (L0 Unattested, L1 Declared, L2 Enforced, L3 Provable) and the criteria that define each tier; and the defining principle that policy must be enforced before execution, not observed after it. Conformance is one covered use among many — you do not need to conform to benefit from this pledge.
What is not covered
This pledge does not extend to specific implementations, architectures, or mechanisms that are not required by the F-ACT specification. Society OS holds separate intellectual property — including trade secrets, know-how, and a pending patent application (AU provisional 2026900773, filed 2 Feb 2026, unexamined) — covering particular methods of achieving conformance; that IP is not transferred to the Foundation. The distinction is simple: the standard says what must be true; the operational IP protects how Society OS does it. You are free to meet the standard by any method.
Who holds the core claims
The core claims are being placed with the Society OS Foundation — a neutral Swiss steward being established for this purpose — so that no single company can ever hold a veto over the standard. Until that transfer completes, Society OS Pty Ltd makes this pledge as the current owner and it binds every successor and assign, so the guarantee holds continuously across the transfer. The Foundation licenses the core claims back to Society OS Pty Ltd on a non-exclusive basis — the identical terms available to anyone else. There is no exclusive lock and no special deal: the company competes on the merit of its products and its operational IP, never on a structural chokehold over the rules.
Version 1.0 · Effective upon publication
F-ACT is forming a multi-stakeholder consortium — modelled on W3C, IETF, and the Linux Foundation — so the standard that governs autonomous agents is itself governed by humanity, not by any single company.
Phase 1: Formation
NowPhase 2: Shared Governance
HandoverFive constituency seats
“The standard that governs how autonomous agents act on behalf of humanity should itself be governed by humanity.”
F-ACT is open. You do not need our permission to use it — you need only require it.
Adopt the five questions
Make Authority, Scope, Data, Audit and Revocation the required answer set for every agent you deploy or accept from a vendor. This is the vocabulary of the standard.
Set your conformance floor
Decide the minimum tier you will accept. Declared (L1) is a starting line; Enforced (L2) is where governance becomes real; Provable (L3) is what survives an audit or a court.
Require it of your supply chain
Ask every agent vendor which F-ACT tier they meet and how they prove it. The standard is open — cite it in policy, in procurement, and in your own attestations.
Ready to declare conformance?
Self-attest L1 and appear on the public F-ACT registry. No fee. No contract.
The five questions map cleanly onto the EU AI Act, ISO/IEC 42001 and the NIST AI RMF. Cite F-ACT in your policy, prove your tier with the live engines, and see how one control set answers three frameworks at once.