Secure AI Atlas mark Secure AI Atlas SECURITY & GOVERNANCE

Industry standards and frameworks

AI Security & Governance Frameworks

The standards that shape how organisations govern AI, manage risk, and prove their controls work. Each entry maps the framework's own language back to the ATLAS risk and control model.

Catalogue

Seven frameworks covering vulnerability standards, threat intelligence, risk management, regulation, and industry practice. Select by category or compare across domains.

Vulnerability standard

OWASP Top 10 for LLM Applications 2026

The definitive industry standard identifying the ten most critical security risks for applications powered by large language models, updated for 2026 with refined rankings, new threat categories, and mappings to MITRE ATLAS, CWE, and NIST AI RMF.

Vulnerability ManagementLLM SecurityApplication SecurityStandard

Vulnerability standard

OWASP Top 10 for Agentic AI Applications 2025

A dedicated top-10 list addressing the unique security challenges of agentic AI systems — where LLMs plan, execute multi-step tasks, invoke tools, and operate with delegated authority over enterprise systems.

Agentic AIVulnerability ManagementApplication SecurityStandard

Regulation

EU AI Act — Regulation (EU) 2024/1689

The European Union's comprehensive regulatory framework for artificial intelligence, establishing a risk-based classification system with escalating obligations for providers and deployers of AI systems.

RegulationGovernanceComplianceStandard

Industry framework

Google Secure AI Framework (SAIF)

A conceptual framework from Google for securing AI systems across their lifecycle, built on six core elements that extend familiar security principles into the AI domain.

Security ArchitectureIndustry FrameworkControls

Risk management

NIST AI Risk Management Framework 1.0

The U.S. National Institute of Standards and Technology framework for managing risks in the design, development, use, and evaluation of AI products and services.

Risk ManagementGovernanceRegulationStandard

How to use the frameworks

Start with the risk you care about in the Risk Catalogue, find the control that mitigates it in the Controls Catalogue, then return here to see which framework demands evidence for that control.

Risk → Control → Framework → Evidence. That is the operational reading ATLAS was built for.