Conformance

Independent Runtime Governance Assessment

AGCP Conformance clarifies what has been assessed, listed, verified, and assurance-tested.

AGCP separates assessment status, registry status, conformance level, and capability coverage so buyers, founders, auditors, risk teams, and implementation partners can understand exactly what has been evaluated and what has not.

AGCP Assessment & Registry Assessment Levels

AGCP uses four public assessment levels to distinguish automated assessment, Registry admission, human verification, and assurance-oriented evaluation. These levels do not automatically imply complete AGCP capability coverage.

1

AGCP Registry Assessed

The implementation has completed the AGCP Registry Assessment process and a capability profile has been generated.

2

AGCP Registry Listed

The implementation has successfully completed Registry Assessment and has been admitted to the AGCP Registry.

3

AGCP Human Verified

The implementation’s Registry Assessment results, capability mappings, evidence, or implementation claims have been reviewed by a qualified human assessor.

4

AGCP Assurance Assessed

The implementation has undergone an assurance-oriented evaluation of demonstrated governance capabilities and supporting evidence.

Important Clarification

Assessment status is distinct from capability coverage.

An implementation may be AGCP Registry Assessed, AGCP Registry Listed, AGCP Human Verified, or AGCP Assurance Assessed while only demonstrating a subset of AGCP governance capabilities.

Governance capabilities are represented separately through the implementation’s Capability Profile.

Three concepts must remain separate

AGCP Registry records are designed to separate status, admission, and capability claims. This prevents buyers from assuming that a listed implementation supports every AGCP requirement or every runtime governance capability.

Assessment Status

Indicates what kind of AGCP assessment, verification, or assurance review has occurred.

Registry Status

Indicates whether the implementation has been admitted to the AGCP Registry or remains outside the Registry.

Capability Profile

Identifies which AGCP governance capabilities were demonstrated, mapped, reviewed, or validated within the assessment scope.

AGCP Registry Assessed is not the same as AGCP Registry Listed. Some assessed implementations may not be included in the Registry.

Assessment level definitions

Each level communicates a different assurance claim. Higher levels provide stronger review context, but still do not imply complete AGCP capability coverage unless the Capability Profile says so.

Assessment Level Meaning Does imply Does not imply
AGCP Registry Assessed The implementation has completed the AGCP Registry Assessment process. Assessment against the AGCP Registry methodology and generation of a capability profile. Registry admission, human review, assurance validation, or full capability coverage.
AGCP Registry Listed The implementation has successfully completed Registry Assessment and has been admitted to the AGCP Registry. Registry admission and satisfaction of Registry admission criteria within the stated scope. Human verification, assurance validation, or complete capability coverage.
AGCP Human Verified The implementation’s assessment results, claims, mappings, evidence, or artifacts have been reviewed by a qualified human assessor. Human review of the relevant Registry Assessment findings and supporting evidence within the stated scope. Assurance validation, live runtime testing, or complete capability coverage unless separately stated.
AGCP Assurance Assessed The implementation has undergone an assurance-oriented evaluation designed to assess demonstrated governance capabilities and supporting evidence. Evidence-oriented assessment of demonstrated governance capabilities within the stated scope. Universal coverage of all AGCP capabilities, legal compliance certification, cybersecurity certification, or model-quality certification.

Capability Profile

The Capability Profile is the primary record of what the implementation actually demonstrated. It should be read together with the assessment status and registry status.

Capability coverage

Identifies which AGCP governance capabilities were represented, mapped, assessed, reviewed, or validated.

Evidence basis

Indicates whether the capability profile was based on automated assessment, documentation, implementation artifacts, source review, runtime evidence, or assurance testing.

Scope boundaries

Clarifies operational, technical, architectural, or evidentiary limitations of the assessment.

AGCP Conformance Levels

AGCP Conformance Levels describe runtime governance capability depth. They are separate from Assessment Levels.

Conformance Level 1

Schema & Envelope Validation

Governance message structure, metadata handling, envelope integrity, and structured rejection semantics.

Conformance Level 2

Ordered Governance Mediation

Evaluation ordering, policy sequencing, constraint evaluation, governance decision recording, and rejection behavior.

Conformance Level 3

Deterministic Governance

Replayable governance behavior, deterministic decision consistency, invariant preservation, and reproducible outcomes.

Conformance Level 4

Execution Authorization Control

Human-in-the-loop enforcement, quorum and cosign controls, execution gating, and commit-bound authorization.

Conformance Level 5

Multitenant Governance Isolation

Tenant isolation, namespace isolation, cross-tenant protection, and tenant-scoped execution mediation.

What AGCP evaluates

AGCP focuses on runtime governance behavior and evidence. Assessment depth depends on the assessment level, scope, and available evidence.

Admissibility

Whether proposed actions are evaluated against applicable policies, constraints, evidence, and current governance conditions.

Execution authorization

Whether consequential execution remains bound to valid governance authorization at the point of execution or commit.

Lifecycle integrity

Whether governance objects move through valid lifecycle states and preserve escalation, refusal, authorization, and terminal-state semantics.

Evidence continuity

Whether governance decisions, approvals, refusals, traces, and execution outcomes remain linked to defensible evidence.

Deterministic behavior

Whether equivalent governance conditions produce reproducible, attributable, and explainable governance outcomes.

Runtime assurance

Whether governance capabilities can be supported through artifacts, traces, runtime evidence, replay, or observed behavior.

How to read an AGCP Registry entry

A Registry entry should not be read as a blanket claim that the implementation supports everything in AGCP.

Registry Field What it answers Example
Assessment Designation What type of assessment, review, or assurance evaluation has occurred? AGCP Human Verified
Registry Status Has the implementation been admitted to the AGCP Registry? AGCP Registry Listed
Capability Profile Which governance capabilities were demonstrated, assessed, or validated? Execution Authorization, Evidence Continuity, Lifecycle Integrity
Conformance Level What AGCP conformance depth was demonstrated within the assessed scope? Level 3 — Deterministic Governance

Example Registry Entry

Field Value
Organization ExampleAI
System ExampleAI Agent Platform
Assessment Designation AGCP Human Verified
Registry Status AGCP Registry Listed
Capability Profile Execution Authorization, Evidence Continuity, Lifecycle Integrity
Conformance Level Level 3 — Deterministic Governance
Assessment Date June 2026
Scope Agent Execution Governance

Interpretation

  • The implementation completed Registry Assessment.
  • The implementation was admitted to the AGCP Registry.
  • A qualified human assessor reviewed the assessment results.
  • The implementation demonstrated selected AGCP governance capabilities.
  • The implementation demonstrated Level 3 governance capability within the assessed scope.

This does not mean

  • The implementation supports every AGCP capability.
  • The implementation has completed Assurance Assessment.
  • The implementation has achieved Level 4 or Level 5 conformance.
  • The implementation is certified for regulatory compliance.
  • The implementation has been evaluated outside the stated assessment scope.

What AGCP Conformance does not mean

AGCP designations are intended to be precise, defensible, and non-overstated.

Not a model-quality score

AGCP does not certify model performance, training quality, benchmark results, or prediction accuracy.

Not a legal compliance certification

AGCP assessment does not certify compliance with any particular law, regulation, procurement rule, or contractual obligation.

Not a cybersecurity maturity certification

AGCP evaluates runtime governance and execution-control behavior, not generalized enterprise cybersecurity maturity.

Not universal capability coverage

Registry listing, human verification, or assurance assessment does not imply that every AGCP capability is present.

Not source-code ownership

AGCP assessment does not require AGCP-developed software, AGCP-owned infrastructure, or proprietary AGCP runtime components.

Not unrestricted public disclosure

Proprietary implementation details, source code, confidential traces, and sensitive artifacts are not publicly disclosed unless expressly authorized.

Frequently Asked Questions

Is AGCP Registry Assessed the same as AGCP Registry Listed?

No. AGCP Registry Assessed means the implementation completed the AGCP Registry Assessment process and a capability profile was generated. AGCP Registry Listed means the implementation was admitted to the AGCP Registry.

Can an implementation be assessed but not listed?

Yes. Some assessed implementations may not be included in the Registry. Assessment and Registry admission are separate concepts.

Does AGCP Registry Listed mean the implementation supports all AGCP capabilities?

No. Registry Listing does not imply complete capability coverage. Capability coverage is represented separately through the implementation’s Capability Profile.

What does AGCP Human Verified mean?

AGCP Human Verified means that a qualified human assessor reviewed the implementation’s Registry Assessment results, capability mappings, implementation claims, source code, artifacts, or other supporting evidence within the stated scope.

What does AGCP Assurance Assessed mean?

AGCP Assurance Assessed means the implementation underwent an assurance-oriented evaluation of demonstrated governance capabilities and supporting evidence. This may include runtime governance evaluation, evidence review, behavioral verification, and assurance profile generation.

Does AGCP require proprietary software?

No. AGCP is implementation-agnostic and does not require AGCP-managed infrastructure, proprietary runtime middleware, AGCP SDKs, or AGCP-developed execution components.

Move from governance claims to defensible governance capability.

AGCP helps organizations distinguish assessment, listing, verification, assurance review, and capability coverage so runtime governance claims can be evaluated with greater precision.