ACTAM™

Obligation follows position.

An AI system's governance burden should be set by two things: how much autonomy it has been granted, and how much consequence it carries when it is wrong.

ACTAM places a system on those two axes and reads off what follows — the controls, the evidence, and the human who signs.

CONSEQUENCE
AUTONOMY

Four zones, two axes. A system moves between them when its autonomy or its consequence changes — not when the technology changes.

The problem it addresses

Autonomy is granted by technology teams. Consequence is owned by nobody.

The same model can carry opposite obligations. A recommendation engine suggesting a series on a streaming app and a model auto-declining a small-business loan may use near-identical techniques. Their consequence profiles are worlds apart, so their governance must be too — yet both are often approved through the same process, by the same people, against the same checklist.

Most AI governance failures are not security breaches. The system is used exactly as designed. What was missing was a limit tied to consequence, and a named person accountable for the outcome.

The two axes

What is measured

A

Autonomy

How far the system acts without human-paced intervention.

Speed
Machine pace against human pace.
Scale
One decision, or millions.
Depth
Recommends, decides, or acts.
C

Consequence

What is at stake when the system is wrong.

Severity
How bad one wrong output is.
Reversibility
Whether it can be undone, and how fast.
Breadth
One person, or a population.
Exposure
Sensitivity of the data it touches.

Each sub-dimension is rated 1 to 5 and the axis score is the average. Consequence is scored from the affected person's side as well as the organisation's, which is where most assessments quietly diverge from reality. Reversibility is the most under-used variable in AI risk work, and usually the most decisive.

Applying it

Five steps, in order

  1. Name the decision the system touchesFor whom, how often, and at what value. Not the model — the decision.
  2. Score autonomySpeed, scale, depth. Each score justified from an observable fact, not an impression.
  3. Score consequenceSeverity, reversibility, breadth, exposure — including from the affected person's side.
  4. Read the zone, and name one accountable humanOne role, not a committee, with the escalation path written down.
  5. Set the evidenceWhat proof, at what cadence, reviewed by whom, by what date.

The wider model

Six components

The matrix is the entry point. ACTAM is the assurance model that sits behind it: controls, evidence and decision rights scale with position, so proportionality is made explicit rather than asserted.

  • ACTAM‑1Digital trust equation — integrity, assurance and accountability set against exposure.
  • ACTAM‑2Trust stack — six layers, from digital identity to public legitimacy. Trust fails at the weakest layer, not on average.
  • ACTAM‑3Reference architecture for assurance.
  • ACTAM‑4Operating governance — who approves what, at which threshold.
  • ACTAM‑5Leading-indicator dashboard.
  • ACTAM‑6Trust command centre — continuous monitoring and independent assurance.

Where it sits

Against the instruments already in force

ACTAM is a management heuristic for deciding how much governance a system needs and who signs for it. It does not replace a standard or a law, and it is designed to be used alongside them.

InstrumentHow ACTAM is used with it
SDAIA — National AI Risk Management FrameworkThe two axes give a repeatable way to reach a tier and to evidence why that tier was chosen.
Saudi PDPLData sensitivity enters the consequence axis as exposure, so personal-data risk raises the governance burden directly.
NIST AI RMFSupports Map and Measure: position on the axes is the input to Manage.
ISO/IEC 42001Supplies the proportionality logic for an AI management system's controls and review cadence.
EU AI ActWhere a system is placed on the EU market, the Act's tier governs; the axes help establish readiness and evidence.
Where a law applies, the law governs. If a system falls under a binding instrument, that instrument sets the obligation. ACTAM organises the decision and the evidence around it.

In use

Taught to a business-school cohort

ACTAM was taught to final-year business students at Alfaisal University, College of Business, on 30 September 2026, delivered in person with a parallel room on Zoom. Comprehension was measured live through two anonymous checkpoints.

168responses at the first checkpoint, across both rooms
91.1%correctly identified the governance failure in a live scenario
98.3%rejected full autonomy for a high-consequence lending decision

Asked to justify the choice in their own words, students reached for the model rather than repeating it:

“It balances AI efficiency with human oversight, while testing for drift and fairness before scaling.”
“It limits risk, then expands based on evidence from monitoring.”

Teaching materials are available to universities on request: the assignment brief, a standard answer template, the marking rubric, and the wallet card that carries the matrix and the method.

Authorship

Who built it, and from what

ACTAM was developed by Ali Alasiri — Chairman of BlackBaz Holding and former Chief Executive of the Saudi e-Government Program (Yesser) — from failure modes observed on both sides of the table: building national digital platforms, and conducting commercial due diligence on AI companies.

That work includes the National Enterprise Architecture and the Digital Government Academy, the first AI crowd-management platform for Hajj and Umrah at the National Digitization Unit, and current delivery of ZATCA's Enterprise Architecture Office and the unified municipal platform for Riyadh.

The same pattern kept appearing: autonomy granted by the technology team, consequence owned by nobody. ACTAM is the instrument built to close that gap.

No AI system should gain autonomy faster than the institution gains accountability.

Working with ACTAM

The model is open to cite and to teach. For institutional adoption, curriculum use, briefings or assessment work, write to ali@alasiri.net.

Suggested citation: Alasiri, A. (2026). ACTAM: governing AI by autonomy and consequence. actam.org