A curated list of the frameworks, standards, regulations, and tools enterprises use to govern, secure, and assure the safety of AI systems.
AI governance guidance is scattered across standards bodies, regulators, security communities, and technology vendors. This list gathers the most operationally relevant frameworks, standards, regulatory instruments, and tools for enterprise AI governance, risk, security, and compliance, each linked to its primary source.
Every entry is also mapped onto a four-layer GRC operating model (Organization, Governance, Risk, Compliance) and made searchable by practitioner role in the interactive AI Governance, Security & Safety Framework Navigator, maintained by MindXO. See the selection criteria below for how entries are chosen.
- Governance & Management Systems
- Risk Management
- Security & Threat Intelligence
- Safety & Frontier Model Governance
- Ethics & Responsible AI
- Regulation & Compliance
- Evaluation, Measurement & Testing
- Selection Criteria
- Related Resources
Foundational frameworks that establish AI governance, management systems, and the operating model an enterprise runs AI within.
- NIST AI 100-1: AI Risk Management Framework - The foundational US framework, built on four functions: Govern, Map, Measure, and Manage.
- ISO/IEC 42001:2023: AI Management System - The first certifiable management-system standard for establishing AI governance, increasingly used as EU AI Act conformity evidence.
- ISO/IEC 5338:2023: AI System Lifecycle Processes - Defines processes for managing the AI lifecycle from conception through development, operation, and retirement.
- NIST AI RMF Playbook - Interactive companion to the AI RMF with suggested actions and references for each function and subcategory.
- NIST AI 100-5: A Plan for Global Engagement on AI Standards - US strategy for AI standardization and coordination across ISO, IEC, IEEE, and other bodies.
- ARMOR: AI Readiness Model for Operational Resilience - Vendor-agnostic readiness framework from WWT and NVIDIA spanning six domains, from GRC to model and infrastructure security.
Risk taxonomies, methodologies, and monitoring frameworks for identifying, measuring, and treating AI risk.
- SaferAI Frontier AI Risk Management Framework - Rigorous risk identification, analysis, evaluation, and treatment methodology built for frontier AI systems.
- ISO/IEC 23894:2023: AI Risk Management - Guidance on AI-specific risk management processes, aligned with the ISO 31000 standard.
- CRI Financial Services AI Risk Management Framework - Sector-specific framework from the Cyber Risk Institute with 230 control objectives, aligned to the NIST AI RMF.
- NIST AI 800-4: Challenges to the Monitoring of Deployed AI Systems - Six categories of monitoring challenges for AI systems in production, from functionality to societal effects.
- IBM AI Risk Atlas - Structured taxonomy of AI risks across input, inference, output, and non-technical categories.
- MAS Project MindForge: Generative AI Risk Framework - MAS-led consortium framework defining seven generative-AI risk dimensions for financial services.
Threat taxonomies, control frameworks, and secure-development guidance for protecting AI systems from adversarial attack and exploitation.
- MITRE ATLAS - ATT&CK-style knowledge base of real-world adversarial tactics, techniques, and case studies for AI systems.
- NIST AI 100-2: Adversarial Machine Learning Taxonomy and Terminology - The authoritative taxonomy of evasion, poisoning, privacy, and abuse attacks across predictive and generative AI.
- OWASP AI Exchange - Living, community-maintained catalog of AI security threats, vulnerabilities, and controls across ML, generative, and agentic systems.
- ENISA Threat Landscape 2025 - Annual EU threat analysis of 4,875 incidents, identifying AI as a defining element of the current landscape.
- ENISA Multilayer Framework for Good Cybersecurity Practices for AI - Three-layer model covering cybersecurity foundations, AI-specific security, and sector-specific practices.
- OWASP Top 10 for LLM Applications - The most-referenced list of critical LLM vulnerabilities, from prompt injection to excessive agency and model theft.
- Databricks AI Security Framework (DASF) v3.0 - 97 risks and 73 controls across 13 AI system components, mapped to MITRE ATLAS, OWASP, NIST, and ISO.
- Google Secure AI Framework (SAIF) - Six core elements for securing AI systems across the lifecycle, aligned with NIST AI RMF and MITRE ATLAS.
- Cisco Integrated AI Security & Safety Framework - Treats AI security and AI safety as complementary dimensions of one unified risk framework.
- OWASP Top 10 for Agentic Applications 2026 - The top security risks for autonomous and agentic AI, covering planning, tool use, and multi-agent communication.
- NVIDIA AI Safety Recipe - Enterprise recipe for building, deploying, and operating trustworthy agentic AI with policy enforcement and guardrails.
- AIUC-1: AI Agent Standard - The first certifiable AI agent standard, spanning data, security, safety, reliability, accountability, and transparency, with crosswalks to NIST, ISO, OWASP, and MITRE.
- Autonomous Action Runtime Management (AARM) - Cloud Security Alliance specification for securing autonomous agent actions at runtime, with eleven agentic threat classes.
- CSA AI Controls Matrix - Cloud Security Alliance control matrix (18 domains, 243 control objectives) for securing AI workloads, mapped to the Cloud Controls Matrix.
- CSA AI Security Maturity Model (AISMM) - Structured roadmap for building and measuring an enterprise AI security program, feeding the STAR for AI certification pathway.
- NIST IR 8596: Cybersecurity Framework Profile for AI - Maps the NIST CSF 2.0 onto AI systems with a Secure, Defend, and Thwart structure (initial public draft).
- NIST SP 800-53 Control Overlays for Securing AI Systems (COSAiS) - Ongoing project mapping the SP 800-53 control catalog to AI use cases with tailored control selections.
- NIST SP 800-218A: SSDF Community Profile for AI Model Development - Applies the Secure Software Development Framework to generative-AI model development and supply-chain integrity.
Frontier-lab self-governance, misuse prevention, and safety guidance for powerful general-purpose and agentic AI.
- Anthropic Responsible Scaling Policy - Defines AI Safety Levels (ASL-1 to ASL-4) with escalating safeguards as frontier model capabilities increase.
- OpenAI Preparedness Framework - Evaluates frontier model risk across cybersecurity, CBRN, persuasion, and model autonomy, with deployment thresholds.
- Singapore Model AI Governance Framework for Agentic AI - The first government-issued governance framework built specifically for agentic AI, from Singapore's IMDA.
- NIST AI 600-1: Generative AI Profile - Companion to the AI RMF identifying 13 generative-AI risks with over 400 suggested actions.
- NIST AI 800-1: Managing Misuse Risk for Dual-Use Foundation Models - Draft framework for addressing CBRN, cyber, and disinformation misuse risks of powerful foundation models.
- NIST AI 100-4: Reducing Risks Posed by Synthetic Content - Watermarking, authentication, and provenance techniques for deepfakes and other synthetic media.
Principles, normative instruments, and enterprise responsible-AI frameworks that set the values AI governance operationalizes.
- OECD AI Principles - Five foundational principles adopted by 46+ countries and embedded in the EU AI Act and national strategies.
- UNESCO Recommendation on the Ethics of AI - The broadest international AI ethics instrument, adopted by all 193 UNESCO member states.
- IEEE 7000: Model Process for Addressing Ethical Concerns During System Design - Standards process for embedding ethical value considerations into system design from concept onward.
- ISO/IEC TR 24368:2022: Overview of Ethical and Societal Concerns - Technical report surveying AI bias, transparency, accountability, and human-oversight concerns.
- Cisco Responsible AI Framework - Enterprise responsible-AI framework built on six principles, operationalized through committee oversight and impact assessments.
- Microsoft Responsible AI Standard v2 - The internal governance standard Microsoft applies to its own AI products, published as an enterprise reference.
Binding laws, regulatory codes, and certifiable compliance instruments that produce audit-ready evidence.
- EU AI Act - The world's first comprehensive, legally binding AI law, using a risk-based classification with phased enforcement through 2026.
- GPAI Code of Practice - European Commission code letting general-purpose AI model providers demonstrate EU AI Act compliance.
- ALTAI: Assessment List for Trustworthy AI - European Commission self-assessment checklist covering the seven requirements for trustworthy AI.
- ISO/IEC 27001:2022: Information Security Management - The certifiable ISMS standard that provides the baseline security controls AI-specific frameworks build upon.
- Software Bill of Materials for AI: Minimum Elements - CISA and G7 joint guidance defining what an AI-specific SBOM must contain for supply-chain transparency.
Benchmarks, evaluation methodologies, and test platforms that turn risk and safety claims into measurable evidence.
- NIST Dioptra - Open-source platform for testing AI system resilience to adversarial attacks.
- OWASP AI Testing Guide - First open standard for trustworthiness testing across application, model, infrastructure, and data layers.
- OWASP AI Vulnerability Scoring System (AIVSS) - Quantifiable scoring methodology for AI vulnerabilities, extending CVSS with an agentic-AI risk score (in development).
- MLCommons AILuminate v1.0 Safety Benchmark - Grades general-purpose chat AI across twelve hazard categories using 24,000+ test prompts per language.
- NIST AI 700-1: GenAI Pilot Study on Text-to-Text Evaluation - Pilot methodology for systematically evaluating text-to-text generative AI outputs.
- NIST AI 800-2: Practices for Automated Benchmark Evaluations of Language Models - Draft best practices for evaluating LLMs and AI agents through automated benchmarks.
- ISO/IEC TR 24029-1:2021: Assessment of the Robustness of Neural Networks - Methods for assessing neural-network robustness against adversarial inputs and distributional shift.
The list is deliberate, not exhaustive. Every candidate is tested against five filters:
- Operational relevance. Every entry offers guidance, controls, requirements, or risk taxonomies an enterprise governance, risk, security, or compliance team can act on. Pure research is excluded unless it has reached practitioner-reference status.
- Authority or adoption. Every entry comes from a standards body, a government or regulator, an established security or risk community, or a technology vendor whose framework has cross-industry reference status.
- Functional coverage. Entries are chosen so that every layer of the GRC operating model, and every cross-cutting domain, is represented.
- Geographic relevance. Global-first, with strong US, EU, GCC, Singapore, and Korea coverage. Region-specific overlays are added case by case.
- Currency. Every entry is currently published, in active draft, or under active revision. Superseded versions and abandoned projects are dropped.
Deliberately excluded: general-purpose cybersecurity frameworks not adapted for AI, vendor product documentation, academic preprints without practitioner adoption, national AI strategies and vision documents, and most tooling (measurement platforms such as NIST Dioptra and OWASP AIVSS are the exception).
- AI Safety Organizations Atlas - Companion map of the institutions, labs, and bodies shaping AI safety and governance, from the same team.
- MindXO Research - Applied research on AI governance, risk taxonomies, and system reliability that informs this list.
Contributions are welcome. Read the contribution guidelines first, then open a pull request. In short: one entry per line, linked to its primary source, with a concise one-sentence description, placed in the domain section it best fits.
To the extent possible under law, MindXO has waived all copyright and related or neighboring rights to this work under CC0 1.0.