AARM Spec for AI Agent Audit Trails Released: 9 Properties to Fight Memory Poisoning
Funky_Chicken_22 · reddit · 2026-08-05
The Cloud Security Alliance (CSA) recently released AARM, a conformance model for auditing autonomous AI agents, aiming to solve the lack of unified standards in Agent auditing.
AARM Core Content:
- 9 Audit Properties: Includes tamper-evident receipts, cryptographic identity binding, external anchors, third-party offline verification, cross-agent handoff, retrospective governance revision, runtime authorization, least-privilege posture, and session-scoped disclosure.
- 10 Defended Threats: Covers memory poisoning, goal hijacking, intent drift, confused deputy, data exfiltration, and malicious tool outputs, etc.
The author developed an MCP-based signing tool, Etch, and mapped it against AARM publicly. The tool explicitly fails 2 properties (runtime authorization and least-privilege). The author explains this is a deliberate choice to keep the tool purely as an "evidence layer" rather than an "enforcement layer," ensuring the objective independence of the audit records.
More from coding & agent
- Lost Your Phone? Ask Claude to Build a Bluetooth Tracker in 60 Seconds — tristanbob · 2026-08-05
- Poolside Desktop Assistant 1.4 Adds First-Class Subagents and Plan Mode — Scobleizer · 2026-08-05
- Developer Waited 6 Months for Claude, Built Entire App in One Day — airkatakana · 2026-08-05
- Claude Autonomously Builds Browser Extension in 15 Mins, Rivaling 50 Junior Devs — trashydesigner · 2026-08-05
- Proposed cmux Multi-Column Sidebar: Machines, Workspaces, and Agents — philipvollet · 2026-08-05
- Chinese Models Dominate Forecasting Leaderboard with Advanced AI Agents — teortaxesTex · 2026-08-05