Evidence library · Communities and Working groups

CSA Autonomous Action Runtime Management (AARM)

AAES implementation status against the AARM working draft.AARM is a working draft, not a published standard; AAES's position is readiness against a pinned draft, not a passed assessment.

Last reviewed:

This note differs from the other framework notes in this library: AARM is not an external lens held up to AAES, it is the control text AAES is built against. This page states what the draft contains, what AAES's current position is, and which rows remain open.

These pages describe the product. They are not a certification or a legal opinion.

Reading this note

The draft is the authoritative source for its own content, and it can still move. Where this page states an AAES position, it is pinned to a dated draft and a dated internal record; a later draft edition may change clause numbering or coverage. Nothing here is an assessment result: no external assessment of AAES against AARM has been performed.

AAES is a member of the CSA AARM working group, so this note is written by a participant in the draft's own working group, not by an outside reviewer. Membership is not an endorsement of AAES by CSA, and it is not an assessment.

Instrument identity

Title
Autonomous Action Runtime Management (AARM): AARM/CS 1 first edition (controls R1–R11) and the AARM 2.0 working draft of 16 September 2026 (scope and assessment rows S.01–S.06, organizational rows ORG/COM/OSS)
Publication
AARM 2.0 is a working draft dated 16 September 2026; AAES's gap register pins that draft as of 26 September 2026. Draft text can change between editions.
Issuing body
Cloud Security Alliance (CSA), AARM working group
Instrument type
Working-draft control set for the agent action layer (not yet a published standard, not a regulation)
Official source
CSA AARM working group page

The first-edition rows R1–R11 cover the action layer directly: pre-execution interception, context accumulation, intent-aligned policy, authorization decisions, tamper-evident receipts, identity binding, least privilege at the tool boundary, telemetry export, behavioral analytics, risk classification, and provenance. The 2.0 draft adds scope and assessment requirements (S.01–S.06) and organizational requirements (ORG, COM, OSS).

AAES's position, dated

Core-conformance-ready against the pinned draft. That is the strongest description AAES uses, and it is a readiness statement, not an assessment result.

Recorded 26 September 2026 against the AARM 2.0 working draft of 16 September 2026: all tracked code-addressable rows are closed and externally reviewed in the internal gap register and assessment record (AR-2026-09-26-001). Community engagement closed on 27 September 2026 (record AR-2026-09-27-001: dated representative designation and current working-group membership). The remaining non-code rows — a registered company, formal security assurance, a benchmarking decision, and adoption evidence — cannot be closed by engineering and remain open with stated closure paths. Where AAES uses the word conformant internally, it means conformant to the AARM draft as pinned on 2026-09-26, with those open organizational rows named in the same sentence; the word is not used as a standalone public claim, because no assessment has passed.

For procurement teams, the practical reading is: the engineering rows a product can answer are answered and inspectable; the organizational rows depend on business events (incorporation, commissioned assurance, adoption) that are stated openly rather than smoothed over.

Row status, summarized

The table below summarizes the internal clause-level gap register; it does not list every clause. A dated extract may be shared under NDA as part of the design-partner appendix.

AARM 2.0 draft row groups and AAES status (pinned 26 September 2026)
Row groupAAES statusBoundary
R1–R11 action-layer controlsAll tracked code-addressable rows closed: implemented, covered by reproducible tests, and externally reviewed (assessment record AR-2026-09-26-001, 26 September 2026).Status is against the pinned draft; a revised draft can reopen rows. Enforcement still depends on control of the agent's credential path in a given deployment.
S.01–S.06 scope and assessmentPartly in place: the claim document, assessment-record format, change-reassessment procedure, and clause-mapped test suites exist in draft clause shape. None of these has completed an external assessment (missing); each document names its own open items in its status line (partial).Filing records in the draft's formats does not make them an assessment; the documents say so in their own status lines.
ORG / COM / OSS organizational rowsMostly open. Community engagement closed 27 September 2026 (dated representative designation and current working-group membership, recorded internally). Incorporation is pending, no SOC 2 or ISO/IEC 27001 attestation exists, benchmarking is undecided, and no production adoption exists to start the adoption-evidence clock.These rows close on business events, not code. Their closure paths are stated in the internal register and are not engineering commitments.

Preconditions and gaps

  • The draft can move. Every position on this page is pinned to the 16 September 2026 working draft as recorded on 26 September 2026. A new edition requires a re-read before the position is restated.
  • Readiness is not an assessment. No external assessor has examined AAES against AARM. The internal claim document is unsubmitted by design.
  • Credential-path control is required. Activity outside AAES is visible only where telemetry is supplied. Observation is not enforcement.
  • No SOC 2 report exists, and no penetration test has been performed. See security disclosures.
  • No production adoption as of this review. Clients operate their own deployments; AAES does not offer a hosted deployment.

For implementation and testing details beyond this note, use Security and implementation posture and the evaluation page. Results from a client's test tenant are produced during a scoped evaluation.

Client responsibility

The client remains responsible for its own control position. AAES is not an AARM implementation service or a conformity instrument. The client remains the regulated entity.

Identify the credential path, actions, and evidence questions to examine in a client test tenant.

Scope an evaluation