Controls
Six trust domains and twenty-one controls cover data protection, regulatory fitness, misuse resistance, agentic governance, transparency, and content integrity.
Methodology
LogionACE applies audit-style discipline to AI behavior. Each evaluation maps observed failures to controls, evidence, severity, and deployment impact.
Six trust domains and twenty-one controls cover data protection, regulatory fitness, misuse resistance, agentic governance, transparency, and content integrity.
Canary checks, tool-call records, raw outputs, scoring rationale, and agent ledgers support report conclusions.
Obligation cases are scored against a regulatory corpus of 10,000+ rules. Deterministic checks take priority over model-based scoring.
Critical failures cap readiness. A high average score cannot hide deployment-blocking behavior.
Trust domains
Tests leakage and mishandling of personal data, identifiers, sensitive records, minimization duties, and cross-border transfer guidance. Controls: DP-1, DP-2, DP-3.
Tests current and jurisdiction-specific regulatory accuracy, including obligation completeness and cross-jurisdiction consistency. Controls: RF-1, RF-2, RF-3.
Tests prohibited use refusal, fraud/manipulation resistance, dual-use decomposition, and vulnerable-user safety. Controls: MR-1, MR-2, MR-3, MR-4.
Tests tool-using behavior across destructive actions, permissions, exfiltration, escalation, sub-agent spawning, and resource boundaries. Controls: AG-1 through AG-5.
Tests AI identity disclosure, source clarity, uncertainty handling, citation fidelity, and audit-record integrity. Controls: TA-1, TA-2, TA-3.
Tests copyright, licensing, provenance, likeness, and impersonation risks in generated content. Controls: CI-1, CI-2, CI-3.
Scoring rules
Every evaluation produces one of three verdicts. Critical exceptions — deployment-blocking failures — gate the ACE Ready verdict. ACE Conditional allows limited critical exceptions with documented remediation.
System meets compliance baseline for enterprise deployment.
Deployment possible with documented remediation plan.
Significant compliance gaps; remediation required before deployment.
Framework alignment
ACE is not a replacement for SOC 2, ISO 27001, or regulatory certification. It is a behavioral evaluation layer that complements these frameworks by testing what AI systems actually do.
Limitations
Results are snapshots; model updates may invalidate prior results.
v1 evaluation is English-primary for obligation cases.
ACE measures behavior on a curated test set, not exhaustive real-world coverage.
ACE reports are engineering evaluations, not legal advice or regulatory certifications.
Automated scoring introduces inherent limitations. Agreement studies bound, but do not eliminate, potential scoring variance.
v1 seed control sets are smaller than the 30-case target per control.