AI Governance, frameworks and standards

Summary:

Understand the complex world of AI Governance Frameworks and standards

Agentic AI Threats & Mitigations (T01–T17)

The OWASP Agentic Security Initiative's foundational, broad threat-modelling taxonomy (17 entries, currently v1.1), mapping the full agentic attack surface. The narrower ASI Top 10 is derived from and synchronised with it.

AI TRiSM (Trust, Risk and Security Management)

An umbrella discipline (popularised by Gartner) covering governance, trustworthiness, fairness, robustness, and security across the AI lifecycle.

EU AI Act

The European Union's risk-based AI regulation, classifying systems into unacceptable, high, limited, and minimal-risk tiers with corresponding obligations. Entered into force August 2024, applying in stages through 2026–2027, with separate obligations for general-purpose AI models.

ISO/IEC 23894

International guidance on AI-specific risk management, complementing the generic ISO 31000 risk standard.

ISO/IEC 42001

The international management-system standard for AI (an "AI MS"), specifying requirements for establishing, operating, and continually improving responsible AI governance within an organisation. The AI analogue of ISO 27001.

MAESTRO

A layered threat-modelling framework from the OWASP Agentic Security Initiative, designed specifically for the agentic stack (reasoning, tools, memory, orchestration, multi-agent interaction) where traditional single-inference threat models fall short.

MITRE ATLAS

A knowledge base of adversarial tactics and techniques against machine-learning systems, modelled on the MITRE ATT&CK framework and backed by real-world case studies.

NIST AI 600-1 (Generative AI Profile)

A companion profile to the NIST AI RMF addressing risks specific to generative AI, with suggested actions.

NIST AI RMF (AI Risk Management Framework)

The US NIST voluntary framework organising AI risk management around four functions — Govern, Map, Measure, Manage — with an accompanying Playbook.

OWASP Agentic Security Initiative (ASI)

The OWASP GenAI Security Project's body of work on autonomous-agent security: the threat taxonomy, the MAESTRO threat-modelling framework, secure-development and operator controls, the ASI Top 10, and governance mappings.

OWASP Top 10 for Agentic Applications (ASI01–ASI10)

The December 2025 ("2026") ranked list of the most critical risks specific to autonomous AI agents: ASI01 Agent Goal Hijack, ASI02 Tool Misuse & Exploitation, ASI03 Identity & Privilege Abuse, ASI04 Agentic Supply Chain Vulnerabilities, ASI05 Unexpected Code Execution, ASI06 Memory & Context Poisoning, ASI07 Insecure Inter-Agent Communication, ASI08 Cascading Failures, ASI09 Human-Agent Trust Exploitation, ASI10 Rogue Agents.

OWASP Top 10 for LLM Applications (LLM01–LLM10)

The ranked list (2025 edition) of the most critical risks in LLM-based applications at the model layer: LLM01 Prompt Injection, LLM02 Sensitive Information Disclosure, LLM03 Supply Chain, LLM04 Data & Model Poisoning, LLM05 Improper Output Handling, LLM06 Excessive Agency, LLM07 System Prompt Leakage, LLM08 Vector & Embedding Weaknesses, LLM09 Misinformation, LLM10 Unbounded Consumption.

Shadow AI

Unsanctioned use of AI tools, agents, or services within an organisation outside IT and security oversight — the AI-era counterpart to shadow IT, and a common source of data-governance and compliance exposure.

Author
Neil Larkins
COO
·
Outerlimit