A practitioner-led alliance defining a practical, vendor-agnostic standard for securing enterprise AI.
Enterprises are deploying AI faster than security standards are evolving. AISECA closes that gap with a control framework built by the people who implement AI security, not only by those who advise on it.
57 controls across 12 GenAI risk domains, mapped to NIST AI 600-1 and to MITRE ATLAS techniques. Every risk is answered at three tiers:
| Tier | Name | What it means |
|---|---|---|
| 1 | Define & Constrain | Policy, boundaries, standards. What is allowed, what is prohibited, who owns it. |
| 2 | Enforce & Monitor | Technical enforcement of tier 1. Detection, logging, blocking, escalation. |
| 3 | Validate & Adapt | Adversarial testing and continuous evidence that tiers 1 and 2 actually hold. |
A tier is not a badge you graduate from. Tier 3 without tier 1 is theatre; tier 1 without tier 2 is a PDF.
Domains covered: Information Security · Data Privacy · Value Chain & Component Integration · Human-AI Configuration & Overreliance · Information Integrity · Harmful Bias & Homogenization · Intellectual Property · Confabulation · CBRN · Dangerous, Violent, or Hateful Content · Obscene, Degrading, or Abusive Content · Environmental Impacts
Each control is a single Markdown file carrying the risk, a real-world scenario, all three tiers, and open-source tooling references. Machine-readable copies live at dist/framework.json and dist/framework.csv for anyone building tooling on top of it.
| Repository | What it is |
|---|---|
| framework | The control framework. Start here. |
| charter | Board charter, governance model, membership guidelines |
| .github | Community health files and this profile |
The framework is published as a working draft specifically so practitioners can argue with it. If you have implemented one of these controls in production and it did not work as written, that is the most valuable contribution you can make.
- Challenge a control — it is wrong, unworkable, or mis-tiered
- Propose a control — a risk we do not cover
- Correct a mapping — a NIST, ATLAS, or citation error
- Open a pull request — edit the control text directly
Named tooling in the framework is open source only. Commercial options appear as market categories, never as named products. AISECA is vendor-neutral and inclusion is not for sale.
| Website | aiseca.org |
| Newsletter | aiseca.substack.com — framework updates and board notes |
| Slack | Join the workspace |
| AISECA group | |
| Events | aiseca.org/events |
| Maturity quiz | aiseca.org/quiz |
| Discussions | GitHub Discussions |
Board membership is by application — apply at aiseca.org.
The framework is released under CC BY 4.0. Share it, adapt it, build products on it — with attribution.
AISECA — AI Security Alliance · aiseca.org