Skip to content
@aiseca

AI Security Alliance

Practitioner-led advisory board defining the gold standard for securing enterprise AI tooling.

AISECA — AI Security Alliance

A practitioner-led alliance defining a practical, vendor-agnostic standard for securing enterprise AI.

Enterprises are deploying AI faster than security standards are evolving. AISECA closes that gap with a control framework built by the people who implement AI security, not only by those who advise on it.


The Tiered Control Framework

57 controls across 12 GenAI risk domains, mapped to NIST AI 600-1 and to MITRE ATLAS techniques. Every risk is answered at three tiers:

TierNameWhat it means
1Define & ConstrainPolicy, boundaries, standards. What is allowed, what is prohibited, who owns it.
2Enforce & MonitorTechnical enforcement of tier 1. Detection, logging, blocking, escalation.
3Validate & AdaptAdversarial testing and continuous evidence that tiers 1 and 2 actually hold.

A tier is not a badge you graduate from. Tier 3 without tier 1 is theatre; tier 1 without tier 2 is a PDF.

Domains covered: Information Security · Data Privacy · Value Chain & Component Integration · Human-AI Configuration & Overreliance · Information Integrity · Harmful Bias & Homogenization · Intellectual Property · Confabulation · CBRN · Dangerous, Violent, or Hateful Content · Obscene, Degrading, or Abusive Content · Environmental Impacts

Read the framework →

Each control is a single Markdown file carrying the risk, a real-world scenario, all three tiers, and open-source tooling references. Machine-readable copies live at dist/framework.json and dist/framework.csv for anyone building tooling on top of it.

Repositories

RepositoryWhat it is
frameworkThe control framework. Start here.
charterBoard charter, governance model, membership guidelines
.githubCommunity health files and this profile

Contributing

The framework is published as a working draft specifically so practitioners can argue with it. If you have implemented one of these controls in production and it did not work as written, that is the most valuable contribution you can make.

Named tooling in the framework is open source only. Commercial options appear as market categories, never as named products. AISECA is vendor-neutral and inclusion is not for sale.

Community

Websiteaiseca.org
Newsletteraiseca.substack.com — framework updates and board notes
SlackJoin the workspace
LinkedInAISECA group
Eventsaiseca.org/events
Maturity quizaiseca.org/quiz
DiscussionsGitHub Discussions

Board membership is by application — apply at aiseca.org.

License

The framework is released under CC BY 4.0. Share it, adapt it, build products on it — with attribution.


AISECA — AI Security Alliance · aiseca.org

Pinned Loading

  1. chartercharterPublic

    AISECA Board Charter, Governance Model, and Membership Guidelines

    2

  2. frameworkframeworkPublic

    Practitioner-led AI security control framework: 57 controls across 12 NIST AI 600-1 GenAI risk domains, mapped to MITRE ATLAS, in three tiers. Vendor-agnostic, CC BY 4.0.

    Python 3

  3. controls-catalogcontrols-catalogPublic archive

    Catalogue of AI security controls across all three AISECA maturity tiers

    2

Repositories

Showing 4 of 4 repositories

Top languages

Loading…

Most used topics

Loading…