REFERENCE · PUBLIC

AI-IRF Frequently Asked Questions

Practical, evidence-bounded answers about scope, adoption, incident operations, assessment status and licensing.

AI-IRF frequently asked questions

Searchable public guidance for adoption, architecture, incident operations, evidence, assessment status, claims, and licensing.

General

What is AI-IRF?

AI-IRF is the AI Incident Response Framework. It provides an operational structure for preparing for, identifying, classifying, containing, investigating, recovering from, communicating about, and learning from AI security incidents.

Why does AI-IRF exist?

Conventional incident-response practices do not always capture AI-specific failure modes, model and data dependencies, agentic actions, prompt and output evidence, or AI-specific recovery decisions. AI-IRF provides a common operational layer for those requirements.

Who should use AI-IRF?

Security operations teams, incident responders, AI engineering and MLOps teams, security architects, governance teams, legal and communications stakeholders, risk owners, and organizations that develop, deploy, procure, or operate AI systems.

Is AI-IRF a certification scheme?

No. AI-IRF v1.0 is a published incident-response framework. ODA3 Institute does not currently represent AI-IRF organizational certification, accredited certification-body operations, or practitioner credentialing as operational services.

Framework architecture

What does AI-IRF v1.0 contain?

The current public release contains 79 controls across 19 domains, supported by AIIS machine-readable schema and reference data. The structured control register is the authoritative source for the published control count.

How does AI-IRF relate to UAIF?

UAIF provides a common incident identity, classification, severity, impact, confidence, and evidence structure. AI-IRF consumes that classification context to guide coordinated response activities.

How does AI-IRF relate to GAISSF?

GAISSF provides the organizational governance and assurance layer. AI-IRF supports the response layer, while incident findings and remediation evidence can inform GAISSF control improvement when their use is authorized and governed.

What is AIIS?

AIIS is the machine-readable schema family associated with AI-IRF. It includes the core schema and supporting control, playbook, severity, and performance-profile data used for structured implementation and interoperability.

Can AI-IRF be used independently?

Yes. Organizations may use AI-IRF as an AI incident-response reference on its own. Using UAIF and GAISSF alongside it provides stronger classification consistency and organizational governance context.

Adoption and implementation

How should an organization start?

Define the AI-system and organizational scope, identify accountable response roles, map existing incident processes, adopt a common classification method, select applicable controls, and test the resulting response workflow through exercises.

Must all 79 controls be implemented?

Not automatically. Applicability depends on system scope, architecture, risk, operational context, and dependencies. Organizations should document inclusion, exclusion, tailoring, compensating measures, and the basis for each decision.

Can a small organization use AI-IRF?

Yes. A smaller organization can begin with a bounded AI service or high-priority use case, assign combined roles where independence is not required, and scale the response capability as its AI footprint grows.

How does AI-IRF integrate with SOC, SIEM, SOAR, MLOps, and GRC tools?

AI-IRF can inform event fields, triage logic, playbooks, evidence capture, escalation paths, remediation tracking, and governance reporting. Integration should preserve source attribution, access control, timestamps, and decision traceability.

Are sector resources available?

Public sector notes and implementation resources may be released as their publication gates close. Sector material supplements the core framework and does not establish regulatory approval or automatic compliance.

How should third-party AI services be handled?

Scope third-party models, APIs, agents, data providers, hosting services, and operational dependencies. Response plans should address contractual contacts, evidence access, containment options, shared responsibilities, notification paths, and service-exit constraints.

Incident operations and evidence

What counts as an AI security incident?

An event or condition affecting an AI system that may compromise confidentiality, integrity, availability, safety, intended behaviour, accountability, or governed operation, and that requires coordinated investigation or response.

Does AI-IRF replace an existing incident-response plan?

No. It extends existing cyber, privacy, resilience, safety, legal, and crisis-management processes with AI-specific roles, evidence, decision points, and response considerations.

What evidence should be preserved?

Evidence may include prompts, outputs, interaction logs, model and dataset identifiers, configurations, tool calls, access records, alerts, timelines, approvals, containment actions, communications, test results, and chain-of-custody information. Collection must remain lawful, proportionate, authorized, and privacy-aware.

Does AI-IRF prescribe regulatory notification deadlines?

No. Notification duties depend on jurisdiction, sector, facts, contractual duties, and legal analysis. AI-IRF can support fact collection and decision traceability but does not provide legal advice or determine whether notification is required.

How should organizations validate readiness?

Use tabletop exercises, technical simulations, evidence-retrieval tests, role walkthroughs, communication drills, recovery tests, and post-exercise remediation tracking. Record exercise scope, assumptions, limitations, findings, and closure evidence.

Assessment, claims, and licensing

Can organizations assess themselves against AI-IRF?

Yes. Internal reviews can compare implemented practices with applicable AI-IRF controls and document evidence, gaps, limitations, and remediation actions. An internal review is not ODA3 certification or endorsement.

Is independent assessment available today?

ODA3 Institute is developing assessment and assurance pathways. Any pilot, planned, or future capability must be identified by its actual operational status and documented scope.

Can an organization claim to be AI-IRF certified or compliant?

Not without an applicable, operational, and authorized ODA3 programme. Factual statements such as ‘uses AI-IRF as a response reference’ or ‘maps internal procedures to specified AI-IRF controls’ should be precise, supportable, and consistent with GEL v1.0.

Does using AI-IRF establish legal or regulatory compliance?

No. AI-IRF does not replace legal advice, regulatory interpretation, competent professional judgment, or obligations imposed by law, contract, regulators, or sector authorities.

How is AI-IRF licensed?

AI-IRF publications are governed by the GAISSF Ecosystem License (GEL) v1.0. Users should review the licence for permitted public use, attribution, trademark, commercial-use, redistribution, and integration conditions.

Can software vendors embed AI-IRF content?

Embedding, redistribution, automation, commercial delivery, or product integration may require permission or a commercial licence depending on the material and use. Contact ODA3 Institute before implementing a commercial integration.

How are changes and feedback handled?

Published changes should be recorded through version history and release notes. Feedback may be submitted to ODA3 Institute and is evaluated through the applicable editorial, technical, governance, and publication controls.

Downloadable edition