Everything you need to know about the Agentic Commerce Framework®, AI governance, the EU AI Act, and our tools.
ACF® is the European Decision Trust Infrastructure for agentic decision-making. The standard organizations adhere to so that decisions made by their AI agents remain verifiable and defensible years later — before a regulator, an auditor, a court, or an insurer. The triplet Govern. Measure. Prove. structures this infrastructure: the doctrine governs, ACF Sovereignty Score™ measures, ACF Compliance proves. ACF® is built on 4 founding principles, 4 layers, implementation modules, and a reference set of 17 methodological cards.
ACF® was created by Vincent DORANGE, an AI governance expert. The Decision Trust Infrastructure ACF® is the result of several years of research on autonomous system governance in commercial environments. Agentic Commerce Framework®, ACF® and ACF Sovereignty Score™ are trademarks registered with INPI (French Industrial Property Office).
First, the separation of decision and execution, the sovereignty principle: an agent may execute, but it never sets its own objectives, so an unacceptable agent decision is a governance problem, not an artificial-intelligence problem. Second, non-delegable zones, the protection principle: decisions that engage reputation, legal liability or economic survival stay in human hands, which requires an explicit map of what may be optimised freely, what may be delegated under constraint, and what may never be handed over. Third, traceability and interruptibility, the control principle: an agent must be explainable and it must be stoppable, at a level proportionate to the situation. Fourth, living governance, the continuity principle: rules are revised, responsibilities are held by named people, and reviews are regular, because a framework that does not live quickly becomes a framework that lies. That fourth principle is carried by a named role, the DDAO.
The four layers define the governance architecture, and the order matters as much as the content: you never start with the agent, you always start with the decision. Layer 1 — Governance and Sovereignty: who really decides and on whose authority, the non-negotiable principles, the accountabilities and the forbidden zones. Layer 2 — Decision Policy: those principles translated into operable rules, thresholds, priorities, escalation conditions and financial limits. Layer 3 — Agent System: every agent holds a precise mandate, a defined perimeter, explicit constraints and an identified human owner. Layer 4 — Execution and Supervision: decision logs, dashboards, alerts, drift detection and emergency stop. Without the first, the organization drifts for lack of direction; without the second, its decisions become incoherent; without the third, agents act in a disorder nobody controls; without the fourth, the organization goes blind to its own automation.
The modules cover: M01 Agent Mapping, M02 Risk Classification, M03 Mandate Definition, M04 Gating Protocols, M05 Monitoring Architecture, M06 Emergency Stop Protocol, M07 Audit & Compliance Framework, M08 Training & Simulation. Progressive deployment over 6–18 months.
The KPIs measure decisional sovereignty across 6 governance axes (multiple KPIs per axis): decisional autonomy, algorithmic transparency, operational resilience, regulatory compliance, ethics, and performance. Each KPI has defined thresholds triggering automatic alerts and escalations.
The DDAO — Delegated Decision Agent Officer — is the governance role defined by ACF® that brings GDPR and the EU AI Act together in the organization. Operationally accountable for automated decisions under GDPR Article 22, and lead of agentic governance under ACF®: mandate definition, threshold monitoring, Sovereignty Score™ tracking, kill switch triggering. The DDAO is the named person a regulator or client will turn to with the question "who decides when the agent decides?".
ACF® is a proprietary Decision Trust Infrastructure created and maintained by Vincent DORANGE. The doctrine, tools and trademarks are registered with INPI. The whitepaper and teaching toolkit are freely accessible to encourage adoption, but certified implementation requires the official ACF® tools and processes.
A Decision Trust Infrastructure (DTI) is a shared trust layer organizations adhere to — like TLS for web encryption or SWIFT for interbank transfers. ACF® is not "one more governance framework to deploy": it is the European trust infrastructure organizations adhere to so that decisions made by their AI agents become independently verifiable and defensible against third parties. The difference is structural: a framework describes internal good practice; a DTI produces cryptographic proof independently verifiable by a regulator, an auditor, a court, or an insurer.
Govern. Measure. Prove. is the triplet that structures the ACF® Decision Trust Infrastructure. Govern: the ACF® doctrine (4 principles, 17 methodological cards, DDAO role, non-delegable zones) governs agentic decisions. Measure: ACF Sovereignty Score™ measures the organization's effective decisional sovereignty on a 0-100 scale. Prove: ACF Compliance produces the independently verifiable Ed25519 cryptographic proof of each decision. The three pillars are inseparable.
ACF Sovereignty Score™ is the 0-100 metric that measures an organization's effective decisional sovereignty over its AI agents. Six weighted dimensions: agent identifiability, human override capacity, decision traceability, threshold control, operational kill switch, and drift visibility. The score is Ed25519-signed for integrity, and mapped onto EU AI Act, ISO/IEC 42001, NIST AI RMF, GDPR and COBIT for direct compliance transposition. This is the "Measure" of the Govern. Measure. Prove. triplet.
ACF Compliance is the SaaS module that produces the independently verifiable cryptographic trace of every agentic decision. Technical mechanism: SHA-256 hash chain linking decisions tamper-evidently + Ed25519 signature on each decision + Ed25519-signed timestamping. This is the "Prove" of the Govern. Measure. Prove. triplet — the layer that turns an internal good practice into legal evidence admissible as written evidence (art. 1362 and 1366 of the French Civil Code), ultimate enforceability remaining subject to the court's appreciation.
acf-mcp is the official Model Context Protocol server for ACF®, distributed on npm (acf-mcp@1.1.0). It serves the Ed25519-signed ACF® doctrine and exposes 12 tools (7 REASON for governance reasoning, 5 READ for doctrine consultation) directly callable from Claude Desktop, Cursor, Windsurf, Continue and any MCP-compatible client. Documentation and integration guides: acfstandard.io. Goal: let AI agents operate within the doctrine without re-bootstrapping context on every session.
The V2.1 whitepaper is the June 2026 edition of the ACF® reference document. It formalises the Decision Trust Infrastructure positioning, the Govern. Measure. Prove. triplet, the 17×5 mapping matrix (methodological cards × reference frameworks: EU AI Act, GDPR, DORA, NIS2, ISO 42001) and the four-manifestation ecosystem (doctrine, score, compliance, MCP). Full reading on acfstandard.com/whitepaper.
ISO/IEC 42001 and NIST AI RMF say what to do (objectives, controls, risks to cover). ACF® says how to operate (doctrine + DDAO + 17 cards), how to measure effective decisional sovereignty (ACF Sovereignty Score™), and how to prove every decision (ACF Compliance with independently verifiable cryptographic proof). ACF® is an operational layer above reference-framework compliance, not a competing reference framework. The 17×5 mapping in the V2.1 whitepaper shows direct transposition to ISO 42001, NIST AI RMF, EU AI Act, GDPR and DORA.
Five steps: (1) Read the V2.1 whitepaper on acfstandard.com/whitepaper to understand the Decision Trust Infrastructure and the Govern. Measure. Prove. triplet. (2) Compute your ACF Sovereignty Score™ on acf-score.com (free, 15 minutes) to measure your current decisional sovereignty. (3) Install acf-mcp to expose the signed doctrine to your AI agents. (4) Appoint a DDAO (Delegated Decision Agent Officer) internally. (5) Engage the ACF Compliance module for the independently verifiable proof layer.