Secure AI Atlas mark Secure AI Atlas SECURITY & GOVERNANCE

Method

The ATLAS model

A capability becomes risk when it acquires authority it was not designed to hold. The model traces that transition and can be read in either direction.

01

AI Capability

What the system can do: language, reasoning, code, tool use, long-horizon autonomy.

02

Exposure Surface

What the capability can reach: data, identity, tools, permissions, decisions.

03

Control Layer

What constrains it: identity-bound authorization, validation, approval, logging, classification.

04

Governance Layer

Who owns it, who accepts residual risk, and with what evidence.

Editorial governance

Editorial status

Every object carries a status: draft, under review, verified, published, superseded or archived.

Source policy

Primary sources first. Facts, ATLAS analysis, hypotheses and external claims are distinguished and attributed.

Verification

Framework pages expose official version, publisher, current status and last verification date.

Voice

Headlines may carry personality. Technical body copy stays evidence-based.

Automated checks

The build validates parity, links, sources and framework metadata before publishing.

How ATLAS works

See how ATLAS operates, how its changes are reviewed, and where human authority remains mandatory.

Read the operating model