The problem it addresses
Autonomy is granted by technology teams. Consequence is owned by nobody.
The same model can carry opposite obligations. A recommendation engine suggesting a series on a streaming app and a model auto-declining a small-business loan may use near-identical techniques. Their consequence profiles are worlds apart, so their governance must be too — yet both are often approved through the same process, by the same people, against the same checklist.
Most AI governance failures are not security breaches. The system is used exactly as designed. What was missing was a limit tied to consequence, and a named person accountable for the outcome.
The two axes
What is measured
Autonomy
How far the system acts without human-paced intervention.
- Speed
- Machine pace against human pace.
- Scale
- One decision, or millions.
- Depth
- Recommends, decides, or acts.
Consequence
What is at stake when the system is wrong.
- Severity
- How bad one wrong output is.
- Reversibility
- Whether it can be undone, and how fast.
- Breadth
- One person, or a population.
- Exposure
- Sensitivity of the data it touches.
Each sub-dimension is rated 1 to 5 and the axis score is the average. Consequence is scored from the affected person's side as well as the organisation's, which is where most assessments quietly diverge from reality. Reversibility is the most under-used variable in AI risk work, and usually the most decisive.
Applying it
Five steps, in order
- Name the decision the system touchesFor whom, how often, and at what value. Not the model — the decision.
- Score autonomySpeed, scale, depth. Each score justified from an observable fact, not an impression.
- Score consequenceSeverity, reversibility, breadth, exposure — including from the affected person's side.
- Read the zone, and name one accountable humanOne role, not a committee, with the escalation path written down.
- Set the evidenceWhat proof, at what cadence, reviewed by whom, by what date.
The wider model
Six components
The matrix is the entry point. ACTAM is the assurance model that sits behind it: controls, evidence and decision rights scale with position, so proportionality is made explicit rather than asserted.
- ACTAM‑1Digital trust equation — integrity, assurance and accountability set against exposure.
- ACTAM‑2Trust stack — six layers, from digital identity to public legitimacy. Trust fails at the weakest layer, not on average.
- ACTAM‑3Reference architecture for assurance.
- ACTAM‑4Operating governance — who approves what, at which threshold.
- ACTAM‑5Leading-indicator dashboard.
- ACTAM‑6Trust command centre — continuous monitoring and independent assurance.
Where it sits
Against the instruments already in force
ACTAM is a management heuristic for deciding how much governance a system needs and who signs for it. It does not replace a standard or a law, and it is designed to be used alongside them.
| Instrument | How ACTAM is used with it |
|---|---|
| SDAIA — National AI Risk Management Framework | The two axes give a repeatable way to reach a tier and to evidence why that tier was chosen. |
| Saudi PDPL | Data sensitivity enters the consequence axis as exposure, so personal-data risk raises the governance burden directly. |
| NIST AI RMF | Supports Map and Measure: position on the axes is the input to Manage. |
| ISO/IEC 42001 | Supplies the proportionality logic for an AI management system's controls and review cadence. |
| EU AI Act | Where a system is placed on the EU market, the Act's tier governs; the axes help establish readiness and evidence. |
In use
Taught to a business-school cohort
ACTAM was taught to final-year business students at Alfaisal University, College of Business, on 30 September 2026, delivered in person with a parallel room on Zoom. Comprehension was measured live through two anonymous checkpoints.
Asked to justify the choice in their own words, students reached for the model rather than repeating it:
“It balances AI efficiency with human oversight, while testing for drift and fairness before scaling.”
“It limits risk, then expands based on evidence from monitoring.”
Teaching materials are available to universities on request: the assignment brief, a standard answer template, the marking rubric, and the wallet card that carries the matrix and the method.