战略定位
ACF 对比 AI Act / ISO 42001 / NIST AI RMF / GDPR

ACF 并不取代现有的 AI 标准。

它将这些标准落地为可执行的运营。

每一个主流参考框架都在监管 AI。ACF® 工作于更底层一层:agentic 决策本身。本页展示 17 张 ACF® 卡牌如何与欧盟 AI Act、ISO/IEC 42001、NIST AI RMF、GDPR 与 COBIT 一一对应——任何合规团队都能在几分钟内把 ACF 接入现有的审计追溯链路。

高管视角

一段话看懂 ACF 的定位差异。

各治理领域的主流标准回答了既有问题。ACF 回答的是下一个问题——在决策层面,究竟该如何落地处置。

需求现行主导答案ACF 的补位价值
AI complianceEU AI ActAI Act + operationalisation at the decision layer
AI managementISO/IEC 42001ISO 42001 + agentic decision control
AI risk managementNIST AI RMFRisk + agentic autonomy & criticality
Data protectionGDPRGDPR + signed automated arbitrations
详细对应矩阵

每一张 ACF 卡牌都对应到 AI Act、ISO 42001、NIST AI RMF、GDPR 与 COBIT。

对应关系采用保守口径:当一张卡牌涉及多条条款时,我们仅引用最主要的一条。完整对应(含次级引用)收录于 ACF® 工具包手册之中。

ACF 卡牌欧盟 AI ActISO/IEC 42001NIST AI RMFGDPRCOBIT 2019
ACF-00
Sovereignty Score
Measures the decisional sovereignty retained when deploying autonomous systems.
Art. 9Risk management systemClause 6.1.2AI risk assessmentMAP-3AI risks and benefitsArt. 35DPIAEDM-01Governance framework
ACF-01
Decision Map
Maps the agent's decisions and the human approval chain that governs them.
Art. 14Human oversightClause 8.4 / A.6AI system operationGOVERN-1.1Defined rolesArt. 22Automated decision-makingEDM-03Risk optimisation
ACF-02
Criticality Matrix
Classifies each agent by criticality, impact and irreversibility.
Art. 6 + Annex IIIHigh-risk classificationClause 6.1.2Risk categorisationMAP-2CategorisationArt. 35DPIA thresholdAPO-12Managed risk
ACF-03
Agentic Constitution
Internal charter defining who decides what, how and within which limits.
Art. 5 + Art. 26Prohibited practices + deployer dutiesClause 5.2AI policyGOVERN-2Cultivate cultureArt. 25Privacy by designEDM-01Governance setting
ACF-04
Agent Card
Operational identity of each agent: scope, data, tools, autonomy level.
Art. 11 + Art. 26(6)Technical documentation + logs retentionClause 7.5 + 8.1Documented information / operational planningMAP-1System contextArt. 30Records of processingBAI-09Managed assets
ACF-05
Supervision & Governance
Continuous supervision mechanisms with the DDAO role as the human pivot.
Art. 14 + Art. 26(5)Human oversight + deployer monitoringClause 5.3 + 9.1Roles + monitoringGOVERN-3 / MANAGE-2.3Workforce / ongoing monitoringArt. 22 + Art. 37-39Automated decisions + DPOMEA-02Internal control
ACF-06
Kill Switch
Emergency stop procedure for a drifting agent.
Art. 14(4) + Art. 26(5)Stop button + suspend obligationClause 8.3Operational controlsMANAGE-4DecommissioningArt. 22(3)Right to contest / withdrawDSS-02Service requests & incidents
ACF-07
First Agent Briefing
Qualification dossier before the first production deployment.
Art. 11–13 + Art. 17Documentation + QMSClause 8.1 + 6.2Operational planning + objectivesMAP-2 + GOVERN-4Categorisation + pre-deploy testingArt. 30 + Art. 35Records + DPIABAI-01Managed programmes
ACF-08
Agentic Decision Register
Cryptographic ledger of every decision the agent has taken.
Art. 12 + 19 + 26(6)Logging + retention (6 months min.)Clause 9.1 + 7.5.3Monitoring + control of recordsMEASURE-2Performance & trustworthinessArt. 30Records of processingMEA-01Performance monitoring
ACF-09
Action & Improvement Plan
Post-deployment continual improvement plan, driven by the DDAO.
Art. 9(4) + Art. 17Continuous risk mgmt + QMSClause 10.1 + 10.2Nonconformity + continual improvementMANAGE-2Risk treatmentArt. 24 + Art. 32Responsibility + securityBAI-08Managed knowledge
ACF-10
30-day Governance Audit
Periodic internal audit demonstrating operational mastery.
Art. 17 + Art. 71QMS audit + post-market monitoringClause 9.2 + 9.3Internal audit + management reviewGOVERN-5 + MANAGE-3.1Engagement + risk treatment reviewArt. 32Security auditMEA-02 + MEA-03Internal control + compliance
ACF-11
Agentic Risk Assessment
Risk analysis specific to agents: drift, hallucination, escalation.
Art. 9Risk management systemClause 6.1.2AI-specific risksMAP-3 + MAP-4Risks & benefits + trustworthinessArt. 35DPIAAPO-12Managed risk
ACF-12
Agent Mandate
Formal, enforceable delegation of decision-making power granted to the agent.
Art. 16 + 17 + 26Provider & deployer dutiesClause 5.3Roles & authoritiesGOVERN-3 + GOVERN-6Workforce + external communicationsArt. 28 + 24Processor + controller responsibilityAPO-05Managed portfolio
ACF-13
Guided Case Study
Worked case study, step by step, for training and mock audits.
Art. 6 + 13 + Annex IIISector examples + transparencyClause 7.2 + 7.3Competence + awarenessMAP-2CategorisationArt. 22Worked profiling examplesBAI-05Organisational change
ACF-14
Teacher Guide
For instructors: lesson plans, answer keys, sample exams.
Art. 4AI literacyClause 7.2 + 7.3Competence + awarenessGOVERN-1.6 + GOVERN-6Workforce literacyArt. 39DPO training dutyAPO-07Managed human resources
ACF-15
Governance Simulation
Sandbox exercise: replay a crisis to measure governance resilience.
Art. 9 + Art. 57-63Risk mgmt + regulatory sandboxesClause 9.1 + 6.2Monitoring + planned objectivesMANAGE-3 + MEASURE-3Risk treatment evaluationArt. 32Security testingBAI-06Managed IT changes
ACF-16
Responsibility by Design
Cross-cutting principle: accountability is wired in from design onwards.
Art. 5 + 13 + 16(b)Accountability + transparencyClause 5.2AI policy & accountabilityGOVERN-1 + MANAGE-1Accountability + risk managementArt. 5(2) + 24 + 25Accountability + by designEDM-01Governance setting

资料来源:欧盟 AI Act(法规 2024/1689)· ISO/IEC 42001:2023 · NIST AI RMF 1.0(2023)· GDPR(法规 2016/679)· COBIT 2019。

差异化主张

现有框架治理 AI 本身。ACF 治理的是自主系统所做出的决策。

欧盟 AI Act 告诉你这套 AI 系统受监管。ISO/IEC 42001 告诉你如何管理 AI 资产组合。NIST AI RMF 告诉你需要识别哪些风险。GDPR 告诉你必须获取谁的同意。

可一旦 agent 真正行动起来——定一个价格、批一笔授信、订一张机票、调一个 API——以上框架没有一个能告诉你:这条具体决策由谁签署、依据哪一部章程、配备何种 kill switch、由谁审计、留存多久。

ACF 形式化的正是这一层。17 张卡牌,就是它的运营语汇。

品类定位

为什么 agentic 治理理应拥有自己的框架。

每一个相邻领域都已有其主导框架。自主 agent 的崛起开辟出一个全新领域——而 ACF 正是它的参考框架。

领域主导参考框架
CybersecurityISO/IEC 27001
PrivacyGDPR
Artificial IntelligenceISO/IEC 42001
Regulated AIEU AI Act
Agentic governanceACF®

想从战略定位走向运营落地?

ACF Compliance——配套的 SaaS 产品——将上述每一项对应关系实现为租户隔离的密码学注册中心。自评估免费开放。

打开 ACF Compliance试用免费诊断