You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A practitioner-led, vendor-agnostic control framework for securing enterprise AI. Each risk is mapped to a NIST AI 600-1 GenAI risk domain and to MITRE ATLAS where a technique applies, then answered with three tiers of control: define it, enforce it, validate it.
Version: 1.0 · Controls: 57 across 12 risk domains · License:CC BY 4.0
v1.0 is a released version of the framework. v1.1 is in progress — practitioner feedback is what shapes it, and disagreement is the point. See Giving feedback.
The three tiers
Tier
Name
What it means
1
Define & Constrain
Policy, boundaries, and standards. What is allowed, what is prohibited, who owns it.
2
Enforce & Monitor
Technical enforcement of tier 1. Detection, logging, blocking, escalation.
3
Validate & Adapt
Adversarial testing and continuous evidence that tiers 1 and 2 actually hold.
A tier is not a maturity badge you graduate from. Tier 3 without tier 1 is theatre; tier 1 without tier 2 is a PDF.
How to read a control
Every control is one file under controls/, named by its stable ID. Structured fields live in the YAML frontmatter (domain, severity, NIST AI RMF subcategories, MITRE ATLAS mapping, stakeholder, references); the prose body carries the risk, a real-world scenario, the three tiers, and the tooling landscape.
IDs are stable. Once assigned, a control ID is never reused or renumbered, even if the control is withdrawn.
Open a pull request — edit the control file directly. One control per PR keeps review tractable. See CONTRIBUTING.md.
Start a discussion — org discussions for anything broader than one control: tier boundaries, domain coverage, framework structure.
Join the Slack — aiseca.slack.com for working conversation with the board and other practitioners.
If you have implemented one of these controls in production and it did not work as written, that is the single most valuable contribution you can make.
On tooling references
Named tools are open source only — many corporate-originated, none proprietary. Commercial options appear as market categories (SCA, ASPM, AIDR), never as named products. Listing is descriptive, not an endorsement. See CONTRIBUTING.md for the bar.
Risk domains
Domains follow NIST AI 600-1 (Generative AI Profile).
Practitioner-led AI security control framework: 57 controls across 12 NIST AI 600-1 GenAI risk domains, mapped to MITRE ATLAS, in three tiers. Vendor-agnostic, CC BY 4.0.