Skip to content
@aiseca

AI Security Alliance

Practitioner-led advisory board defining the gold standard for securing enterprise AI tooling.

AISECA — AI Security Alliance

A practitioner-led alliance defining a practical, vendor-agnostic standard for securing enterprise AI.

Enterprises are deploying AI faster than security standards are evolving. AISECA closes that gap with a control framework built by the people who implement AI security, not only by those who advise on it.


The Tiered Control Framework

57 controls across 12 GenAI risk domains, mapped to NIST AI 600-1 and to MITRE ATLAS techniques. Every risk is answered at three tiers:

Tier Name What it means
1 Define & Constrain Policy, boundaries, standards. What is allowed, what is prohibited, who owns it.
2 Enforce & Monitor Technical enforcement of tier 1. Detection, logging, blocking, escalation.
3 Validate & Adapt Adversarial testing and continuous evidence that tiers 1 and 2 actually hold.

A tier is not a badge you graduate from. Tier 3 without tier 1 is theatre; tier 1 without tier 2 is a PDF.

Domains covered: Information Security · Data Privacy · Value Chain & Component Integration · Human-AI Configuration & Overreliance · Information Integrity · Harmful Bias & Homogenization · Intellectual Property · Confabulation · CBRN · Dangerous, Violent, or Hateful Content · Obscene, Degrading, or Abusive Content · Environmental Impacts

Read the framework →

Each control is a single Markdown file carrying the risk, a real-world scenario, all three tiers, and open-source tooling references. Machine-readable copies live at dist/framework.json and dist/framework.csv for anyone building tooling on top of it.

Repositories

Repository What it is
framework The control framework. Start here.
charter Board charter, governance model, membership guidelines
.github Community health files and this profile

Contributing

The framework is published as a working draft specifically so practitioners can argue with it. If you have implemented one of these controls in production and it did not work as written, that is the most valuable contribution you can make.

Named tooling in the framework is open source only. Commercial options appear as market categories, never as named products. AISECA is vendor-neutral and inclusion is not for sale.

Community

Website aiseca.org
Newsletter aiseca.substack.com — framework updates and board notes
Slack Join the workspace
LinkedIn AISECA group
Events aiseca.org/events
Maturity quiz aiseca.org/quiz
Discussions GitHub Discussions

Board membership is by application — apply at aiseca.org.

License

The framework is released under CC BY 4.0. Share it, adapt it, build products on it — with attribution.


AISECA — AI Security Alliance · aiseca.org

Pinned Loading

  1. charter charter Public

    AISECA Board Charter, Governance Model, and Membership Guidelines

    2

  2. framework framework Public

    Practitioner-led AI security control framework: 57 controls across 12 NIST AI 600-1 GenAI risk domains, mapped to MITRE ATLAS, in three tiers. Vendor-agnostic, CC BY 4.0.

    Python 2 1

  3. controls-catalog controls-catalog Public archive

    Catalogue of AI security controls across all three AISECA maturity tiers

    2

Repositories

Showing 4 of 4 repositories

Top languages

Loading…

Most used topics

Loading…