AGCP Conformance clarifies what has been assessed, listed, verified, and assurance-tested.
AGCP separates assessment status, registry status, conformance level, and capability coverage so buyers, founders, auditors, risk teams, and implementation partners can understand exactly what has been evaluated and what has not.
AGCP Assessment & Registry Assessment Levels
AGCP uses four public assessment levels to distinguish automated assessment, Registry admission, human verification, and assurance-oriented evaluation. These levels do not automatically imply complete AGCP capability coverage.
AGCP Registry Assessed
The implementation has completed the AGCP Registry Assessment process and a capability profile has been generated.
AGCP Registry Listed
The implementation has successfully completed Registry Assessment and has been admitted to the AGCP Registry.
AGCP Human Verified
The implementation’s Registry Assessment results, capability mappings, evidence, or implementation claims have been reviewed by a qualified human assessor.
AGCP Assurance Assessed
The implementation has undergone an assurance-oriented evaluation of demonstrated governance capabilities and supporting evidence.
Important Clarification
Assessment status is distinct from capability coverage.
An implementation may be AGCP Registry Assessed, AGCP Registry Listed, AGCP Human Verified, or AGCP Assurance Assessed while only demonstrating a subset of AGCP governance capabilities.
Governance capabilities are represented separately through the implementation’s Capability Profile.
Three concepts must remain separate
AGCP Registry records are designed to separate status, admission, and capability claims. This prevents buyers from assuming that a listed implementation supports every AGCP requirement or every runtime governance capability.
Assessment Status
Indicates what kind of AGCP assessment, verification, or assurance review has occurred.
Registry Status
Indicates whether the implementation has been admitted to the AGCP Registry or remains outside the Registry.
Capability Profile
Identifies which AGCP governance capabilities were demonstrated, mapped, reviewed, or validated within the assessment scope.
AGCP Registry Assessed is not the same as AGCP Registry Listed. Some assessed implementations may not be included in the Registry.
Assessment level definitions
Each level communicates a different assurance claim. Higher levels provide stronger review context, but still do not imply complete AGCP capability coverage unless the Capability Profile says so.
| Assessment Level | Meaning | Does imply | Does not imply |
|---|---|---|---|
| AGCP Registry Assessed | The implementation has completed the AGCP Registry Assessment process. | Assessment against the AGCP Registry methodology and generation of a capability profile. | Registry admission, human review, assurance validation, or full capability coverage. |
| AGCP Registry Listed | The implementation has successfully completed Registry Assessment and has been admitted to the AGCP Registry. | Registry admission and satisfaction of Registry admission criteria within the stated scope. | Human verification, assurance validation, or complete capability coverage. |
| AGCP Human Verified | The implementation’s assessment results, claims, mappings, evidence, or artifacts have been reviewed by a qualified human assessor. | Human review of the relevant Registry Assessment findings and supporting evidence within the stated scope. | Assurance validation, live runtime testing, or complete capability coverage unless separately stated. |
| AGCP Assurance Assessed | The implementation has undergone an assurance-oriented evaluation designed to assess demonstrated governance capabilities and supporting evidence. | Evidence-oriented assessment of demonstrated governance capabilities within the stated scope. | Universal coverage of all AGCP capabilities, legal compliance certification, cybersecurity certification, or model-quality certification. |
Capability Profile
The Capability Profile is the primary record of what the implementation actually demonstrated. It should be read together with the assessment status and registry status.
Capability coverage
Identifies which AGCP governance capabilities were represented, mapped, assessed, reviewed, or validated.
Evidence basis
Indicates whether the capability profile was based on automated assessment, documentation, implementation artifacts, source review, runtime evidence, or assurance testing.
Scope boundaries
Clarifies operational, technical, architectural, or evidentiary limitations of the assessment.
AGCP Conformance Levels
AGCP Conformance Levels describe runtime governance capability depth. They are separate from Assessment Levels.
Schema & Envelope Validation
Governance message structure, metadata handling, envelope integrity, and structured rejection semantics.
Ordered Governance Mediation
Evaluation ordering, policy sequencing, constraint evaluation, governance decision recording, and rejection behavior.
Deterministic Governance
Replayable governance behavior, deterministic decision consistency, invariant preservation, and reproducible outcomes.
Execution Authorization Control
Human-in-the-loop enforcement, quorum and cosign controls, execution gating, and commit-bound authorization.
Multitenant Governance Isolation
Tenant isolation, namespace isolation, cross-tenant protection, and tenant-scoped execution mediation.
What AGCP evaluates
AGCP focuses on runtime governance behavior and evidence. Assessment depth depends on the assessment level, scope, and available evidence.
Admissibility
Whether proposed actions are evaluated against applicable policies, constraints, evidence, and current governance conditions.
Execution authorization
Whether consequential execution remains bound to valid governance authorization at the point of execution or commit.
Lifecycle integrity
Whether governance objects move through valid lifecycle states and preserve escalation, refusal, authorization, and terminal-state semantics.
Evidence continuity
Whether governance decisions, approvals, refusals, traces, and execution outcomes remain linked to defensible evidence.
Deterministic behavior
Whether equivalent governance conditions produce reproducible, attributable, and explainable governance outcomes.
Runtime assurance
Whether governance capabilities can be supported through artifacts, traces, runtime evidence, replay, or observed behavior.
How to read an AGCP Registry entry
A Registry entry should not be read as a blanket claim that the implementation supports everything in AGCP.
| Registry Field | What it answers | Example |
|---|---|---|
| Assessment Designation | What type of assessment, review, or assurance evaluation has occurred? | AGCP Human Verified |
| Registry Status | Has the implementation been admitted to the AGCP Registry? | AGCP Registry Listed |
| Capability Profile | Which governance capabilities were demonstrated, assessed, or validated? | Execution Authorization, Evidence Continuity, Lifecycle Integrity |
| Conformance Level | What AGCP conformance depth was demonstrated within the assessed scope? | Level 3 — Deterministic Governance |
Example Registry Entry
| Field | Value |
|---|---|
| Organization | ExampleAI |
| System | ExampleAI Agent Platform |
| Assessment Designation | AGCP Human Verified |
| Registry Status | AGCP Registry Listed |
| Capability Profile | Execution Authorization, Evidence Continuity, Lifecycle Integrity |
| Conformance Level | Level 3 — Deterministic Governance |
| Assessment Date | June 2026 |
| Scope | Agent Execution Governance |
Interpretation
- The implementation completed Registry Assessment.
- The implementation was admitted to the AGCP Registry.
- A qualified human assessor reviewed the assessment results.
- The implementation demonstrated selected AGCP governance capabilities.
- The implementation demonstrated Level 3 governance capability within the assessed scope.
This does not mean
- The implementation supports every AGCP capability.
- The implementation has completed Assurance Assessment.
- The implementation has achieved Level 4 or Level 5 conformance.
- The implementation is certified for regulatory compliance.
- The implementation has been evaluated outside the stated assessment scope.
What AGCP Conformance does not mean
AGCP designations are intended to be precise, defensible, and non-overstated.
Not a model-quality score
AGCP does not certify model performance, training quality, benchmark results, or prediction accuracy.
Not a legal compliance certification
AGCP assessment does not certify compliance with any particular law, regulation, procurement rule, or contractual obligation.
Not a cybersecurity maturity certification
AGCP evaluates runtime governance and execution-control behavior, not generalized enterprise cybersecurity maturity.
Not universal capability coverage
Registry listing, human verification, or assurance assessment does not imply that every AGCP capability is present.
Not source-code ownership
AGCP assessment does not require AGCP-developed software, AGCP-owned infrastructure, or proprietary AGCP runtime components.
Not unrestricted public disclosure
Proprietary implementation details, source code, confidential traces, and sensitive artifacts are not publicly disclosed unless expressly authorized.
Frequently Asked Questions
Is AGCP Registry Assessed the same as AGCP Registry Listed?
No. AGCP Registry Assessed means the implementation completed the AGCP Registry Assessment process and a capability profile was generated. AGCP Registry Listed means the implementation was admitted to the AGCP Registry.
Can an implementation be assessed but not listed?
Yes. Some assessed implementations may not be included in the Registry. Assessment and Registry admission are separate concepts.
Does AGCP Registry Listed mean the implementation supports all AGCP capabilities?
No. Registry Listing does not imply complete capability coverage. Capability coverage is represented separately through the implementation’s Capability Profile.
What does AGCP Human Verified mean?
AGCP Human Verified means that a qualified human assessor reviewed the implementation’s Registry Assessment results, capability mappings, implementation claims, source code, artifacts, or other supporting evidence within the stated scope.
What does AGCP Assurance Assessed mean?
AGCP Assurance Assessed means the implementation underwent an assurance-oriented evaluation of demonstrated governance capabilities and supporting evidence. This may include runtime governance evaluation, evidence review, behavioral verification, and assurance profile generation.
Does AGCP require proprietary software?
No. AGCP is implementation-agnostic and does not require AGCP-managed infrastructure, proprietary runtime middleware, AGCP SDKs, or AGCP-developed execution components.
Move from governance claims to defensible governance capability.
AGCP helps organizations distinguish assessment, listing, verification, assurance review, and capability coverage so runtime governance claims can be evaluated with greater precision.
