PUBLICATION · PUBLIC

AI-IRF Executive Brief

Decision-level introduction to the AI Incident Response Framework.

Publication content

This HTML rendering reflects the corrected source edition issued 19 July 2026.

Oda3 Institute

Executive Brief

AI-IRF™ v1.0 Executive Brief — Board & CISO Summary

DocID: ODA3-2026-06-EXB-HAI-002 Classification: Public — Published under GAISSF Ecosystem Licence (GEL v1.0)

© ODA3 Pvt Ltd ODA3 Institute | Executive Brief | AI-IRF™ v1.0 — Board & CISO Summary

Document Information

Document ID ODA3-2026-06-EXB-HAI-002

Document Type Executive Brief (EXB)

Framework AI-IRF™ v1.0 (part of the GAISSF Ecosystem: GAISSF™ | UAIF™ | AI-

Irf™)

Version 1.0 — Regulatory and capability-status correction issued 19 July 2026

Effective Date 1 June 2026

Classification Public — Published under GAISSF Ecosystem Licence (GEL v1.0)

Paired TCR ODA3-2026-06-TCR-HAI-001

Cert Scheme AI IRF CERT™ — planned scheme; not operational or accredited as of 19 July 2026

Regulatory Crosswalk EU AI Act, GDPR, NIST AI RMF, ISO/IEC 42001, NIS2, CIRCIA

Evidence Tier Not applicable — Executive Briefs carry zero inline evidence-tier tags by design; full tiered evidence (T1–T4) is documented in the paired TCR

Audience Board & CISO

Publish Date / Review 1 June 2026; correction issued 19 July 2026 / Annual or upon material Cycle regulatory change

Maintainer ODA3 Institute (ODA3 Pvt Ltd)

LICENCE NOTICE — GEL v1.0 SOURCE-AVAILABLE | NON-COMMERCIAL BY DEFAULT | COMMERCIAL-USE RESTRICTED

This document is part of the GAISSF Ecosystem published by ODA3 Institute (ODA3 Pvt Ltd) under the GAISSF Ecosystem Licence (GEL v1.0), effective 1 June 2026. It is source-available, non- commercial by default, and commercial-use restricted. No rights are granted except as explicitly stated in GEL v1.0. This document is NOT open-source and is NOT compatible with OSI-approved licences. Commercial Use (GEL §3.4, §5.3): Use of this document as the basis for consulting, advisory, audit, assessment, certification, compliance, SaaS, training, or managed services — regardless of whether a fee is charged specifically for access — constitutes Commercial Use and requires a separate written commercial licence from ODA3 Institute. Contractor & AI Training Data Restrictions (GEL §3.2, §3.6): External consultants and third-party firms using this document to deliver services to any external client require a separate commercial licence. Use of this document as AI training, fine-tuning, or evaluation data for any commercially deployed model requires a separate written commercial licence from ODA3 Institute. Trademarks (GEL §9.1, §9.2, §9.3): GAISSF™, UAIF™, AI-IRF™, AI IRF CERT™, and ODA3™ are trademarks of ODA3 Pvt Ltd, asserted on a use-in-commerce basis. Registration applications are pending. No statement in this

ODA3-2026-06-EXB-HAI-002 | Page 2 | ODA3 Pvt Ltd ODA3 Institute | Executive Brief | AI-IRF™ v1.0 — Board & CISO Summary

document represents any mark as registered unless and until registration has been granted in the relevant jurisdiction. The ODA3 Institute logo, brand colour palette, and visual identity elements are proprietary design assets of ODA3 Pvt Ltd. No licence to use any of these marks or assets is granted under GEL v1.0 except for factual attribution per GEL §6. Certification Authority (GEL §10.5): ODA3 Institute states that it owns and governs the AI-IRF™ framework and reserves the AI IRF CERT™ marks and scheme authority under GEL v1.0. As of 19 July 2026, the certification scheme is under development: ODA3 Institute has not represented it as accredited or operational, has not authorised a certification body to issue AI IRF CERT™ certificates, and does not maintain an operational certification registry. No third party may represent itself as authorised to provide AI IRF CERT™ services without a separate written agreement. Redistribution (GEL §5.2): Modified versions of this document may only be redistributed under GEL §5.2 conditions and must carry the mandatory disclaimer: “IMPORTANT: This is an unofficial modification of the GAISSF Ecosystem. It has not been reviewed, endorsed, or certified by ODA3 Institute. For the official GAISSF Ecosystem, visit https://oda3.org/” Disclaimer (GEL §12): This document is provided “AS IS” without warranties of any kind. All enquiries: https://oda3.org/ — Attribution (GEL §6): GAISSF™, UAIF™, and AI-IRF™ are frameworks of ODA3 Institute, referenced under the GAISSF Ecosystem Licence (GEL) v1.0.

Methodology Note This Executive Brief summarises governance, commercial, and regulatory implications for Boards, CISOs, and Legal/Compliance leadership. It carries no inline evidence-tier tags. Full tiered evidence (T1–T4), control-by-control mapping, and testing methodology are documented in the paired Technical + Compliance Report, ODA3-2026-06-TCR-HAI-001.

ODA3-2026-06-EXB-HAI-002 | Page 3 | ODA3 Pvt Ltd ODA3 Institute | Executive Brief | AI-IRF™ v1.0 — Board & CISO Summary

Commercial Value Proposition For CISOs

  • Structure evidence of AI incident-response capability for internal assurance, procurement, insurer,

and regulatory-readiness discussions; independent verification is not implied

  • Structured roadmap from current state to Tier 3 autonomous security capability
  • Evidence reuse potential: selected AI-IRF™ artifacts may support scoped ISO/IEC 27001, SOC 2,

FedRAMP, or HITRUST audit activities where the relevant assessor accepts them; no equivalence or cross-certification is claimed For Boards and CFOs

  • Reduce AI-related systemic risk with quantified, tier-based control assurance
  • Cyber insurance positioning: demonstrable AI security posture reduces exposure
  • Regulatory-readiness support: structured evidence that may inform analysis under the EU AI Act,

GDPR, and NIS2; applicability and compliance require separate legal determination For Legal and Compliance

  • Structured regulatory routing: decision-support logic for GDPR, the EU AI Act, CIRCIA, NIS2, and

the Colorado AI Act, subject to jurisdiction, actor role, incident definition, operative dates, and legal review

  • Cryptographic evidence chain: immutable audit logs, ECDSA-signed (Elliptic Curve Digital Signature

Algorithm) AI-BOM (AI Bill of Materials), WORM (Write Once Read Many) storage

  • Post-incident regulatory package: pre-structured STIX 2.1 (Structured Threat Information

Expression) export and CTI (Cyber Threat Intelligence) sharing workflow

ODA3-2026-06-EXB-HAI-002 | Page 4 | ODA3 Pvt Ltd ODA3 Institute | Executive Brief | AI-IRF™ v1.0 — Board & CISO Summary

The AI Security Gap — Why AI-IRF™ v1.0 Exists AI systems are now embedded in critical business operations — financial decisioning, healthcare diagnostics, customer service, and physical infrastructure. Existing security certifications were not designed for them.

Existing Standard The Gap

ISO/IEC 27001 Not AI-specific. No controls for agentic systems, LLM threats, or machine-speed response.

ISO/IEC 42001 AI management-system standard with broader governance scope; it does not provide the AI-incident-response control depth targeted by AI-IRF™.

NIST AI RMF Voluntary risk-management framework with a broader risk scope; AI-IRF™ adds prescriptive incident-response controls and evidence expectations.

SOC 2 Not AI-native. Does not address prompt injection, model extraction, or AI supply chain integrity.

AI-IRF™ v1.0 addresses this operational gap through 79 testable incident-response controls, CACAO- aligned playbook structures, and three proposed assurance tiers. The framework is published; the associated certification scheme and delivery network are still under development.

ODA3-2026-06-EXB-HAI-002 | Page 5 | ODA3 Pvt Ltd ODA3 Institute | Executive Brief | AI-IRF™ v1.0 — Board & CISO Summary

What AI-IRF™ v1.0 Provides

Three Proposed Assurance Tiers

Tier Name Target Organisation Key Capability

Tier 1 Regulatory SMEs, early adopters, Continuous AI discovery, pre- Baseline compliance-driven execution gates, regulatory decision trees, signed AI-BOM, deterministic severity scoring

Tier 2 Advanced Regulated industries, AI- Full MCP (Model Context Protocol) / Operational native enterprises A2A (Agent-to-Agent) semantic inspection, LLM-as-a-Judge ensemble, behavioural distillation detection, Zero Trust AI architecture

Tier 3 Autonomous Critical infrastructure, Machine-speed containment <500ms, Security high-risk AI operators integrated cyber-safety command, 15-minute automated rollback, autonomous HITL (Human-in-the- Loop) exception handling

What a Future Assessment Could Demonstrate

  • AI incident-response capability evaluated against a documented scope and evidence set, once an

authorised and appropriately qualified assessment mechanism becomes operational

  • Operationally enforceable controls — not policy statements — with testable evidence artifacts
  • Regulatory-readiness evidence: routing and mapping support for GDPR, the EU AI Act, CIRCIA, and

NIS2, without asserting legal compliance or regulatory approval

  • Supply chain integrity: cryptographically signed AI-BOM for all production models
  • Agentic system security: pre-execution permission gates, HITL controls, A2A trust enforcement

Current Status and Boundaries As of 19 July 2026, AI IRF CERT™ is a planned scheme and is not represented as operational or accredited. No AI IRF CERT™ certificate, accredited certification body, authorised audit network, or public certification registry is represented as currently available. Future assessment would not certify individual model safety, guarantee freedom from incidents, establish legal compliance, or constitute regulatory approval. Organisations remain responsible for their security posture and applicable legal obligations.

ODA3-2026-06-EXB-HAI-002 | Page 6 | ODA3 Pvt Ltd ODA3 Institute | Executive Brief | AI-IRF™ v1.0 — Board & CISO Summary

Illustrative Future Assessment Process — Not Yet Operational

Phase Duration What Happens

Self-Assessment 2–4 weeks Proposed internal gap analysis using an AI-IRF™ assessment workbook under development. Intended to identify control gaps and estimate remediation effort against a selected assurance tier.

Preparation 60–180 Implement controls, establish evidence collection processes days per Annex A specifications, conduct internal audit against the checklist pass/fail criteria.

Stage 1 — 2–4 weeks Future authorised assessor reviews policies, governance, Documentation and control-design documentation against the applicable AI- Review IRF™ requirements. Accreditation and authorisation arrangements have not yet been established.

Stage 2 — 2–6 weeks Proposed live testing of controls, evidence examination, Technical personnel interviews, and simulation exercises, including all Validation applicable SHALL requirements for the selected tier.

Certification 1–2 weeks Planned future decision step. Certificate issuance, registry Decision listing, verification endpoints, decision rules, and nonconformity thresholds remain subject to approved scheme documentation and operational launch.

Surveillance Annual / Proposed surveillance model: annual for Tiers 1 and 2 and Semi- semi-annual for Tier 3, with possible triggered reviews. Final annual intervals remain subject to approved scheme rules.

AI-IRF™ Assessment Workbook — Planned Controlled Tool An AI-IRF™ assessment workbook is under development as a planned controlled implementation resource. This brief does not represent the workbook as currently available for licensing or operational assessment. Availability, licence terms, validation status, and authorised uses will be published separately when approved.

ODA3-2026-06-EXB-HAI-002 | Page 7 | ODA3 Pvt Ltd ODA3 Institute | Executive Brief | AI-IRF™ v1.0 — Board & CISO Summary

Next Steps Current implementation and engagement steps:

Ste Action Contact p

1 Review the published AI-IRF™ framework and define the AI https://oda3.org/ systems, business services, jurisdictions, and incident-response scope to be assessed.

2 Document current controls and evidence against the selected https://oda3.org/ proposed assurance tier; record gaps and unresolved dependencies.

3 Contact ODA3 Institute regarding framework implementation, https://oda3.org/ research collaboration, or future scheme-participation updates. This is not an application for certification.

Framework Documents — GEL v1.0 Terms Apply AI-IRF™ v1.0 framework documents are available to the public under the GAISSF Ecosystem Licence (GEL v1.0) — source-available, non-commercial by default. They are not unconditionally public. Access, redistribution, and use are governed by GEL v1.0. Commercial use of any framework document requires a separate written commercial licence from ODA3 Institute. All documents, licensing terms, and the CB directory are accessible at https://oda3.org/

For framework implementation, research collaboration, or future assessment-scheme updates, contact ODA3 Institute at https://oda3.org/. ODA3 Institute does not provide legal advice or guarantee regulatory compliance.

ODA3-2026-06-EXB-HAI-002 | Page 8 | ODA3 Pvt Ltd ODA3 Institute | Executive Brief | AI-IRF™ v1.0 — Board & CISO Summary

GAISSF™ | UAIF™ | AI-IRF™ | ODA3™ Trademarks of ODA3 Pvt Ltd (registration applications pending). Published under GEL v1.0. ODA3 Institute is the sole owner, proprietor, and governing body of the AI-IRF™ framework and AI IRF CERT™ certification scheme in perpetuity. © 2026 ODA3 Pvt Ltd. All Rights Reserved. | https://oda3.org/

ODA3-2026-06-EXB-HAI-002 | Page 9 | ODA3 Pvt Ltd

Authoritative source

Download the approved PDF — corrected 19 July 2026 →

This accessible HTML rendering is rebuilt from the current authoritative PDF. Where presentation differs, the PDF governs.