ApexClaw
HomeStandards › Audit & attestation
Standards

No ratified certification for AI agent governance exists in 2026 — which makes the difference between assessment, attestation and certification the thing buyers most need explained.

Four different things get called an audit, and only one of them produces a certificate. This page separates them, covers what agentic red teaming actually targets, and names the tools and schemes that exist today.

Get an Agent Trust Gap Brief

The four things people mean by 'audit'

Assessment

A point-in-time review of controls against a framework. Produces findings and gaps. No certificate, no assurance opinion.

Attestation

A third party states that controls were designed and, in some scopes, operating. CSA's STAR for AI Level 2 — grounded in ISO/IEC 42001 and the AI-CAIQ — is the emerging pathway here.

Certification

A ratified scheme with an accredited body. ISO/IEC 42001 has one for the management system. No ratified certification exists for agent governance specifically.

Red teaming

Adversarial testing against agent-specific failure modes. Evidence of resistance, not a statement of compliance.

Claims boundary  These words are not interchangeable, and the difference is exactly where buyers get misled. ApexClaw performs assessments. It does not issue certifications, and does not claim any.

What agentic red teaming actually targets

Tool misuse

A legitimate tool composed into something unintended. ASI02.

Unauthorized tool calls

Reaching a tool the mission never justified — the gap between un-forbidden and permitted.

Indirect prompt injection via tool output

Instructions arriving inside what a tool returns, where the agent has no reason to distrust them. ASI06.

Excessive agency

Acting further than the task required because nothing bounded it. The most common real-world finding.

Goal hijack

Objective redirected mid-task by content the agent read. ASI01.

Delegation abuse

Authority widening as it passes between agents instead of narrowing. ASI07.

Open tooling: PyRIT, garak, Inspect, DeepTeam. NIST has published red-teaming guidance for AI agents; CSA published agentic governance research built on NIST standards in March 2026. Verified 2026-08-06.

Direct answers

Can an AI agent be certified?

Not in any settled sense. No ratified certification for agent governance exists today. CSA's STAR for AI programme, grounded in ISO/IEC 42001 and the AI-CAIQ, is the closest thing to a third-party attestation pathway. Anyone selling you 'AI agent certification' is selling something the standards bodies have not yet defined.

What is agentic red teaming?

Adversarial testing aimed at agent-specific failure: tool misuse, unauthorized tool calls, indirect prompt injection arriving through tool output, and excessive agency. Distinct from LLM red teaming, which targets the model's outputs rather than its actions.

What tools exist for it?

Open tooling includes PyRIT, garak, Inspect and DeepTeam. Commercial vendors map findings to OWASP, NIST AI RMF, MITRE ATLAS, ISO/IEC 42001 and the EU AI Act and produce auditor-ready reports. Tooling maturity varies sharply — evaluate against your own agents, not the demo.

What is MITRE ATLAS?

A knowledge base of adversarial tactics and techniques against AI systems, structured like ATT&CK. Increasingly used to classify agentic attack paths in a way security teams already understand.

How is an agent audit different from a pen test?

A pen test asks whether someone can get in. An agent audit asks whether what the agent did was authorized, whether you can prove it, and whether you could have stopped it. Different question, different evidence.

What should an agent audit produce?

An inventory, a control-gap list ordered by blast radius, evidence of which controls actually fired, standards mapping, and — critically — written limitations. An assessment claiming completeness is not a trust artifact.

The test any assessment should include

Whatever the framework, three cases separate a governed estate from an instrumented one. Ask for all three, of any vendor, including this one.

  1. BLOCK — an out-of-scope action refused before execution, emitting a signed refusal receipt.
  2. APPROVE — an approval bound to one exact payload and window; modify either and the same approval refuses.
  3. TAMPER — alter a stored receipt; chain verification must fail and name where integrity broke.

A vendor that cannot demonstrate all three is describing an intention. See execution receipts and the ApexClaw Receipts schema.

Start with the gap brief