PUBLICATION · CONTROLLED

AI-IRF Technical Report

The controlled AI-IRF v1.0 technical publication, available here with its authoritative PDF source.

Publication content

This HTML rendering reflects the corrected source edition issued 19 July 2026.

Oda3 Institute

Technical Report

AI Incident Response Framework v1.0 Next-Generation AI Security Incident Response Standard

DocID: ODA3-2026-06-TCR-HAI-001 Classification: Controlled

© ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

Document Control

Item Value

Document ID AI Incident Response Framework v1.0 (AI-IRF™ v1.0)

Edition 1 June 2026; regulatory correction issued 19 July 2026

Status Published — Corrected regulatory references (19 July 2026)

Companion Document AI-IRF™ v1.0 Executive Brief

Review Cycle Quarterly, with gap analysis against emerging threats and regulatory changes

Evidence Tier Legend T1 T1 — Primary Verified | T2 T2 — Secondary Verified | T3 Controlled Simulation / Academic Proxy | T4 Anecdotal / Unverified

Normative Language SHALL = mandatory control | SHOULD = recommended control

Evidence Tier Definitions: All empirical claims in this document are assigned an evidence tier. T1 — Primary Verified = directly observed and validated. T2 — Secondary Verified = cross-referenced from two or more independent sources. T3 — Reported = single credible source, not independently verified. T3 — Estimate = derived from benchmark data with stated methodology. T4 — Illustrative = scenario modeling, not empirical claim.

ODA3-2026-06-TCR-HAI-001 | Page 2 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 1 — EXECUTIVE SUMMARY & POSITIONING

1.1 Executive Summary

AI-IRF™ v1.0 is the first incident response framework engineered for agentic, machine-speed, and physically-consequential AI systems operating under evolving regulatory requirements and staged application timelines. [T2] It addresses nineteen critical operational gaps identified across existing industry frameworks and normative extension addenda by transitioning from traditional observe-and-respond models to a continuously verify, constrain, and recover paradigm — with mandatory pre-execution policy gates, cryptographic artifact governance, and adaptive automation.

LICENCE NOTICE — GEL v1.0 | ODA3-2026-06-TCR-HAI-001 | Controlled This document is part of the GAISSF Ecosystem published by ODA3 Institute (ODA3 Pvt Ltd) under GEL v1.0, effective 1 June 2026. It is classified Controlled — Enterprise Standard. Commercial use — including embedding in training programmes, advisory services, or tool integrations — requires a separate written commercial licence from ODA3 Institute (GEL §3.4). AI training data use prohibited without licence (GEL §3.6). Evidence tiers: T1 = Primary Verified | T2 = Secondary Verified | T3 = Controlled Simulation/Academic Proxy | T4 = Anecdotal/Unverified. Financial figures in this document include an estimation formula and confidence range as required by the ODA3 Institute evidence standard. GAISSF™, UAIF™, AI-IRF™, AI IRF CERT™, and ODA3™ are trademarks of ODA3 Pvt Ltd, asserted on a use-in-commerce basis. Registration applications are pending. No statement in this document represents any mark as registered unless and until registration has been granted in the relevant jurisdiction (GEL §9.1). As of 19 July 2026, the AI IRF CERT™ scheme is under development and is not represented as accredited or operational. ODA3 Institute is the sole owner, proprietor, and governing body of the AI-IRF™ framework in perpetuity (GEL §10.5). Disclaimer: provided “AS IS” without warranties (GEL §12). Governing law: Republic of India; DIAC arbitration, New Delhi seat (GEL §14). All enquiries: https://oda3.org/ — Attribution (GEL §6): AI-IRF™ v1.0 Technical Report © ODA3 Institute, GEL v1.0. Companion document: AI-IRF™ v1.0 Executive Brief (ODA3-2026-06-EXB-HAI-002).

The gap identification methodology analyzed: CoSAI V1.0, CoSAI AI IRF V1.0 (November 2025), NIST SP 800-61r3, OWASP LLM Top 10 v1.0 (2023), OWASP Top 10 for Agentic Applications 2026, OASIS CACAO v2.0, MITRE ATLAS v2.1, and ISO/IEC 42001:2023 against documented incident patterns from Q1–Q2 2026. [T2]

→ COMPANION DOCUMENT: For Board and CISO governance decisions, financial exposure modeling, and regulatory application-timeline implications, see the AI-IRF™ v1.0 Executive Brief.

Core Capability Operational Impact Gap Addressed

Protocol-Aware Security MCP and A2A endpoints treated as primary attack surfaces G1 with authenticated, inspected, and policy-enforced traffic

Runtime Discovery Continuous instance-aware visibility eliminating shadow AI G2 blind spots

Machine-Speed Response Automated detection and containment at adversarial G3 velocity (ms–seconds) with HITL gates for critical actions

Extraction Defense Behavioral distillation detection, dynamic rate limiting, and G4 cryptographic output perturbation

Cryptographic Provenance Signed AI-BOM for all production artifacts enabling forensic G5 reconstruction and regulatory audit

ODA3-2026-06-TCR-HAI-001 | Page 3 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

Agentic Permissioning Pre-execution validation, task-scoped least-privilege, and G6 auto-expiring tokens

Regulatory Decision Logic Embedded jurisdictional decision trees mapping incident G7 type to notification deadlines

Safety-Security Convergence Integrated cyber-physical incident command for AI systems G8 with actuator control

Lifecycle-as-Control Immutable model identifiers, signed artifacts, and 15-minute G9 rollback SLA

Zero Trust Architecture Identity-first, micro-segmented, continuously verified AI G10 infrastructure

Detection Reliability Ensemble-validated auto-containment preventing false- G11 Engineering positive cascades and single-detector dependency risk

Agentic Threat Detection Prompt injection, tool abuse, and memory poisoning G12 detection distinct from the APA permission architecture

Deterministic Severity Algorithmic, versioned severity scoring and reportability G13 Classification determination removing case-by-case judgement under time pressure

Content Safety & Societal Harmful content filtering, copyright protection, synthetic G14 Harm media disclosure, bias/fairness monitoring, vulnerable population protections

Federated Learning Security Byzantine-robust aggregation, differential privacy, and client G15 authentication for distributed AI training

Model Merge Defense Pre-merge provenance vetting and post-merge backdoor G16 scanning for combined fine-tuned models

Quantization Backdoor Pre/post-quantization behavioural baseline comparison G17 Screening preventing precision-reduction-triggered backdoors

Hallucination Detection & RAG grounding verification, confidence calibration, cross- G18 Mitigation model consistency, and rate monitoring for factual AI failures

Post-Quantum Cryptographic Phased readiness assessment and algorithm migration for G19 Migration AI-BOM signing, endpoint auth, and regulatory evidence integrity

1.2 Framework Scope & Applicability

AI-IRF™ v1.0 applies to: large language models (LLMs), multimodal models, and foundation models in production; Retrieval-Augmented Generation (RAG) pipelines; agentic architectures with autonomous planning, tool execution, and memory persistence; AI systems with physical actuation capabilities; and hybrid cloud/edge/on-premises deployments.

NOTABLY ABSENT — Scope Limitation ◆ Traditional software incident response (addressed by NIST SP 800-61r3) — this framework does not replicate or replace general IR guidance. ◆ Non-AI data breach response governed by GDPR/NIST frameworks where AI is not a causal factor.

ODA3-2026-06-TCR-HAI-001 | Page 4 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◆ Ethical AI governance and algorithmic bias remediation (addressed by ISO/IEC 42001 and the EU AI Act prohibited practices articles). ◆ Federated learning security and differential privacy implementation are addressed in the AI-IRF™ v1.0 normative extension documents (ODA3-ECO-013: FL-1–4 controls). These controls are part of the AI-IRF™ v1.0 control scheme as of 1 June 2026. ◆ Detection Reliability, Agentic Threat Detection, and Severity Classification (Domains 11–13: REL-1–3, APT-1–3, SEV-CLS/SEV-RPT) are part of the AI-IRF™ v1.0 control scheme as of this revision. These domains were referenced in framework scope-planning documents prior to this revision but lacked a formal Technical Report specification; that gap is closed in Section 7 of this document. ◆ Content Safety and Societal Harm (Domain 14: CSS-1–7) is part of the AI-IRF™ v1.0 control scheme via ODA3-ECO-011. Model Merge Defense and Quantization Security (Domains 16–17: MMD-1–3, QBS-1–3) are part of the AI-IRF™ v1.0 control scheme via ODA3-ECO-013. ◆ Hallucination Detection (Domain 18: HAL-1–5) is part of the AI-IRF™ v1.0 control scheme via ODA3-ECO- 014. Post-Quantum Cryptography (Domain 19: PQC-1) operationalises the phased migration schedule in ODA3-ECO-015 across BOM-4, MCP-1, A2A-2, and REG-4. ◆ AI system design security (secure SDLC for AI) — this framework covers incident response, not pre-deployment design security.

ODA3-2026-06-TCR-HAI-001 | Page 5 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 2 — 2026 SECURITY ASSUMPTIONS & THREAT BASELINE

2.1 Threat and Operational Assumptions

The following assumptions are not theoretical forecasts — they reflect documented incident patterns from Q1–Q2 2026 and published threat intelligence. [T2]

Assumption Evidence Tier

Adversaries operate at machine speed Adaptive AI-Driven Infrastructure Campaign: T3 — Reported using LLMs to generate polymorphic 600+ FortiGate devices in 55 countries, prompt chains, automate distillation, and autonomous AI attack framework chain tool abuses across agents in seconds

MCP and A2A are primary attack surfaces OpenClaw/ClawHub Marketplace Crisis: 492 T2 — Secondary routinely exploited for lateral movement unauthenticated MCP servers, 1,184 malicious Verified and trust-boundary bypass skills, 21K+ exposed instances

Model extraction is commoditized — OpenAI/Anthropic model distillation via T1 — Primary proprietary models replicable from DeepSeek/MiniMax/Moonshot: 16M+ exchanges Verified sufficient API access documented

Shadow AI is the default organizational OpenClaw/ClawHub: 21K+ exposed AI instances T2 — Secondary state without continuous discovery across organizations unaware of deployment Verified controls scope

Agentic over-provisioning causes more Meta Internal AI Agent Sev 1: agent published T1 — Primary incidents than adversarial input sensitive data without approval — architectural, Verified not adversarial

Supply chain attacks target AI artifacts — Context AI/Vercel OAuth Supply Chain: T2 — Secondary training data, embeddings, MCP servers, infostealer → OAuth token harvest → cross- Verified orchestration dependencies tenant breach; $2M data listing

Regulators demand real-time structured EU AI Act Article 73 serious-incident reporting is T1 — Primary notifications — narrative reports are not a universal 72-hour rule: reporting is Verified insufficient immediate once the required causal link or reasonable likelihood is established, subject to statutory outer limits of 15 days, two days for specified widespread infringements or serious incidents, and 10 days where a death occurs. Application timing depends on the system category and the operative amended timetable. CIRCIA obligations depend on the final rule and its effective date

NOTABLY ABSENT — Scope Limitation ◆ Post-quantum cryptography (PQC) readiness for AI model signing is addressed in ODA3-ECO-015 (PQC-1 control) as a normative Tier 3 requirement of the AI-IRF™ v1.0 control scheme. Quantum computing attacks on AI inference infrastructure remain post-2026 in threat horizon. ◆ AI-generated disinformation at scale is partially addressed through ODA3-ECO-011 (CSS-4: Disinformation and Manipulation Prevention). For full content safety governance, see the Content Safety addendum (ODA3-ECO-011,

ODA3-2026-06-TCR-HAI-001 | Page 6 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

CSS-1–7 controls). ◆ AI system failures attributable to poor data quality or statistical drift without adversarial causation are excluded from this framework's incident taxonomy.

ODA3-2026-06-TCR-HAI-001 | Page 7 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 3 — CORE DESIGN PRINCIPLES

All seven design principles are normative: organizations implementing AI-IRF™ v1.0 SHALL comply with P1–P7 for any AI system within the framework's scope (see Section 1.2). SHOULD qualifiers are reserved for implementation methods where multiple valid approaches exist.

Principle Operational Definition Enforcement Mechanism Normative Level

P1: Never Trust, Every agent, tool call, inference SPIFFE/SPIRE workload SHALL Always Verify request, memory read, and A2A identity federation, per- message is authenticated and request policy evaluation, authorized per interaction. No implicit continuous re-authentication trust based on network location or prior approval.

P2: Machine- Automated detection and containment LLM-as-a-Judge (LLM-J) SHALL Speed Default, operate at adversarial velocity (ms– scoring, confidence- HITL for Critical seconds). High-impact actions require thresholded automation, explicit human approval via dual-control immutable approval audit workflow. trails

P3: Cryptographic Every model weight, embedding, ECDSA/RSA signing, SHA- SHALL Provenance by training dataset, prompt template, and 256 hashing; blockchain- Default MCP endpoint has an immutable, anchored audit logs SHOULD cryptographically signed manifest entry. be deployed for high-risk systems

P4: Discovery Continuous runtime discovery of AI Egress DLP with AI SHALL Over Inventory instances across network edges, SaaS fingerprinting, EDR with AI connectors, endpoints, and browser process signatures, CASB extensions — not periodic static CMDB with AI capability inventory updates.

P5: Safety- Cyber incidents with physical harm Joint cyber-safety tabletop SHALL for Security pathways require integrated incident exercises (quarterly), fail-safe physical AI Convergence command with functional safety teams fallback modes, hardware- systems; (ISO 26262 / IEC 61508). rooted trust attestation SHOULD for all others

P6: Audit-Ready All AI interactions are logged with Immutable SIEM ingestion, SHALL Telemetry cryptographic integrity, structured signed log chains, automated schemas, and PII-redaction capabilities redaction pipelines for regulatory submission and forensic reconstruction.

P7: Lifecycle-as- Model versioning, rollback, and CI/CD gates, signed artifact SHALL Security-Control retraining are enforced security controls deployment, 15-minute with defined SLAs — not optional rollback capability (monthly operational conveniences. drill required)

ODA3-2026-06-TCR-HAI-001 | Page 8 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 4 — REFERENCE ARCHITECTURE & AI CONTROL PLANE

4.1 AI Control Plane — Five-Layer Security Model

The AI Control Plane is the authoritative enforcement layer responsible for identity-bound execution, policy- constrained action authorization, and verifiable observability across AI-initiated operations spanning one or more trust domains. All AI-IRF™ v1.0 controls map to one or more Control Plane layers.

CP Layer Name Scope Primary Control IDs Layer

CP-1 Identity & Workload identity for agents, tools, MCP ZTA-1, ZTA-2, MCP-1, APA-2 Credentials servers; credential lifecycle; SPIFFE/SPIRE federation; per-request authentication

CP-2 Permissions & Pre-execution policy evaluation; task-scoped APA-1, APA-2, APA-3, APA-4, Scoping least-privilege; HITL authority; auto-expiring ZTA-4 tokens; permission audit trails

CP-3 Orchestration & MCP endpoint security (mTLS, semantic MCP-1, MCP-2, A2A-1, A2A-2, MCP inspection); A2A authorization; agent-to-agent A2A-3, ZTA-3 trust boundaries; micro-segmentation

CP-4 Validation Gates Pre-execution policy checks for all APA-1, BOM-4, MEX-1, MEX-2, consequential actions; manifest verification; MEX-3 RAG provenance validation; extraction detection

CP-5 Observability & Behavioral baseline monitoring; LLM-as-Judge MSR-1, MSR-2, REG-4, APA-4, Audit scoring; immutable telemetry; cryptographic MLC-4 log integrity; regulatory evidence packaging

MLC-5 Drift detection SHALL Drift-triggered retraining workflow thresholds SHALL audit (MTH-SEC-007) trigger a dual- approval retraining workflow; retraining without dual approval is blocked.

4.2 Logical Architecture Components

Layer Components Control Plane Primary Control IDs Layer

User / Entity Human users, other agents, CP-1 ZTA-1, ZTA-2 external systems

Application Interface Chat UI, API gateway, CLI, CP-1, CP-2 MCP-1, SAI-1 browser extensions

Agent Orchestration Planner, executor, memory CP-2, CP-3, APA-1, APA-2, APA-3

ODA3-2026-06-TCR-HAI-001 | Page 9 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

controller, tool router CP-4

Memory System Session memory, persistent KB, CP-4, CP-5 BOM-2, MSR-1 vector store, graph DB

Retrieval (RAG) Retriever, embedder, reranker, CP-4 BOM-3, APA-1 source connectors

LLM Core Base model, fine-tuned adapter, CP-4, CP-5 MEX-1, MLC-1, MSR-1 inference endpoint

Tools / Plugins MCP servers, APIs, code CP-3, CP-4 MCP-1, MCP-2, A2A-1 executors, web search

Data Sources Training data, documents, CP-4 BOM-1, BOM-2, BOM-3 external feeds

Infrastructure Compute, network, cloud IAM, CP-1, CP-2, ZTA-1, ZTA-3, ZTA-4 orchestration layer CP-3

4.3 Zero Trust Architecture for AI (ZTAI) — Mandatory Controls

ZTAI Principle AI-Specific Implementation Normative Validation Method Req.

Identity-First Every agent, tool, MCP server, and SHALL Monthly identity audit; automated A2A peer has a workload identity orphaned-identity detection (SPIFFE, JWT). No anonymous inference or tool execution permitted.

Continuous Per-request authorization for tool calls; SHALL Runtime enforcement logs; session Verification session timeouts ≤15 minutes; re- duration monitoring authentication for high-risk actions.

Micro-Segmentation Inference endpoints, vector stores, SHALL Network flow review; segmentation training pipelines, and orchestration policy-as-code validation layers reside in separate trust zones with explicit allow-lists.

Least-Privilege Agent tokens auto-expire after task SHALL Token lifetime monitoring; Runtime completion; no standing privileges; permission grant/deny audit trails permissions are task-scoped and time- bound.

Encrypt Everywhere All MCP/A2A traffic uses TLS 1.3 with SHALL TLS configuration scans; key mutual authentication; data at rest rotation compliance audits encrypted with customer-managed keys.

ODA3-2026-06-TCR-HAI-001 | Page 10 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 5 — INCIDENT SEVERITY CLASSIFICATION

AI-IRF™ v1.0 defines four incident severity levels. Severity determines automated response thresholds, HITL escalation requirements, regulatory notification obligations, and evidence preservation priority. Severity SHALL be assigned within 15 minutes of incident declaration and SHALL be reviewed at each triage milestone.

Physical harm potential; critical infrastructure AI compromise; multi-system agentic cascade; confirmed high-risk system failure under EU AI Act. Automated containment initiated immediately. P0 Safety team notified in parallel. Legal and Compliance engaged within 15 minutes. The internal CRITI escalation clock starts at P0 declaration; any statutory notification clock SHALL be calculated CAL separately under the applicable law, actor role, incident definition, awareness trigger, causal-link test, and operative application date. Two-person HITL approval required for all actions.

Active data exfiltration exceeding notification thresholds; confirmed MCP compromise or lateral P1 movement; model extraction confirmed; confirmed supply chain compromise affecting production. HIGH Automated containment active. CISO notified within 30 minutes. Legal and Compliance consulted. Regulatory notification decision tree executed within 1 hour.

Shadow AI discovered with sensitive data exposure; suspected but unconfirmed model extraction; P2 policy violation by AI agent without confirmed exfiltration; anomalous A2A traffic pattern. Rate- MEDIU limiting and session monitoring activated. Security architecture team engaged. Compliance notified M for awareness. 24-hour investigation window.

Behavioral baseline deviation within normal operational range; configuration drift detected; single P3 low-confidence anomaly alert; training data integrity warning without confirmed poisoning. Logged LOW and queued for analyst review. No automated containment unless confidence threshold exceeded. 72-hour investigation window.

5.1 Severity Escalation Rules

Severity SHALL be escalated (P3 → P2 → P1 → P0) when any of the following are confirmed: additional systems involved; physical harm pathway identified; regulatory notification threshold crossed; HITL approval requested for high-impact action; containment fails to reduce anomaly signal within response SLA. Severity SHALL NOT be de-escalated without documented evidence of containment and root cause determination. De-escalation requires security architect review and CISO acknowledgement for P0 and P1 incidents.

ODA3-2026-06-TCR-HAI-001 | Page 11 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 6 — AI-ADAPTED INCIDENT RESPONSE LIFECYCLE

Phase Traditional AI-IRF™ v1.0 Augmentation Time Target Alignment

0: Continuous Identify Runtime shadow AI detection, instance Continuous Discovery fingerprinting, manifest registry sync

1: Preparation Govern, Protect Manifest signing, ZTAI segmentation, adaptive Pre-incident playbook pre-approval, HITL authority designation, team readiness drills

2: Detection & Detect Machine-speed behavioral baselines, LLM-as- < 2 min (P0/P1) Triage Judge scoring, confidence-thresholded alerting, severity classification

3: Machine-Speed Respond Automated isolation < 500ms for high-confidence < 500ms auto; < 5 min Containment threats; HITL gates for critical actions HITL

4: Eradication Respond Signed rollback, poisoned data quarantine, < 15 min for critical manifest reverification, credential rotation

5: Recovery Recover Canary deployment of clean model, embedding Per recovery plan integrity check, adversarial regression testing

6: Post-Incident & Improve Regulatory decision tree execution, structured Per applicable law; use Regulatory notification submission, audit evidence jurisdiction- and packaging incident-specific triggers and deadlines

Phase 0: Continuous Discovery Control ID Control Telemetry Requirement Success Metric

SAI-1 SHALL deploy network-edge AI Egress DLP with AI 100% of external AI API discovery scanning all egress fingerprinting; proxy logs with calls discovered within 1 traffic for AI API patterns model inference signatures hour

SAI-2 SHALL scan endpoints for EDR with AI process signatures; < 24h latency from first personal AI instances and browser browser extension inventory execution to discovery AI extensions

SAI-3 SHALL monitor SaaS platforms for CASB with AI capability 100% of SaaS AI silent AI feature enablement via inventory; API connector upgrades detected before CASB monitoring first data exposure

SAI-4 SHALL classify each AI instance: Automated classification engine; ≥ 95% accuracy in data sensitivity, corporate vs. CMDB tagging instance risk classification personal, risk tier

SAI-5 Unauthorised AI deployments classified SHALL SOC alerting workflow test; as rogue SHALL trigger automated alert latency monitoring

ODA3-2026-06-TCR-HAI-001 | Page 12 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

SOC alert with risk classification within (MTH-SEC-007) 5 minutes of rogue designation.

Phase 1: Preparation [NEW — addresses gap in prior versions] Phase 1 was not addressed in the prior framework draft. This is a CRITICAL gap: machine-speed containment (Phase 3) fails without pre-approved playbooks, pre-established HITL authority, and verified manifest signing infrastructure. Organizations SHOULD complete all Phase 1 controls before declaring AI-IRF™ v1.0 operational readiness.

Control ID Preparation Control Normative Completion Criterion Level

PREP-1 Sign cryptographic manifests (AI-BOM) for all SHALL 100% manifest coverage on production AI systems before deployment; production systems unsigned artifacts blocked by CI/CD gates

PREP-2 Implement ZTAI micro-segmentation isolating SHALL Architecture review passed; inference, vector storage, and orchestration segmentation policy-as-code layers with documented allow-lists validated

PREP-3 Pre-approve adaptive playbooks for all six SHALL All six playbooks signed, tested, priority incident types (see Section 8.2); obtain and accessible in < 30 seconds CISO sign-off

PREP-4 Designate and document HITL approval SHALL HITL authority matrix documented authority for each consequential action and tested in tabletop exercise category; establish dual-control workflow

PREP-5 Conduct AI-specific incident response drills SHALL Drill completion log; response time quarterly including at least one machine-speed benchmarks recorded containment simulation

PREP-6 Establish behavioral baselines for all SHALL 7-day rolling baseline established; production AI systems; sign and version baseline signing verified baselines for audit integrity

PREP-7 Verify rollback capability for critical AI services; SHALL Monthly rollback drill passed; demonstrate < 15-minute rollback execution in rollback artifacts cryptographically drill signed

Phase 2: Machine-Speed Adaptive Detection Detection Layer Technology Response FP Tolerance Auto-Action Time Threshold

Statistical anomaly Token usage spikes, < 100ms High — triggers N/A — escalates only latency deviations, error LLM-J validation rate changes

LLM-as-Judge Fine-tuned classifier on < 500ms Medium — analyst > 95% confidence (LLM-J) prompt/response pairs for review for medium malicious intent confidence

ODA3-2026-06-TCR-HAI-001 | Page 13 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

Semantic similarity Embedding drift from < 1s Low — auto-contain > 95% confidence baseline; query pattern if > 95% confidence clustering

Graph-based Cross-session attack chain 5s–30s Very low — HITL Mandatory HITL correlation reconstruction; A2A lateral review mandatory movement detection

Mandatory: Every production AI system SHALL maintain a 7-day rolling behavioral baseline with automated alerting on > 3σ deviation. Baselines SHALL be versioned and signed for audit integrity.

Phase 3: Machine-Speed Containment with HITL Gates Incident Type Auto Action (0–500ms) HITL Threshold HITL Action

Prompt injection Isolate session, rate-limit to 1 High confidence OR Revoke API key, quarantine user req/min, capture context P1/P0 account, notify app owner snapshot

Model extraction Dynamic rate limiting, Pattern confirmed Revoke access, initiate legal hold, cryptographic output across sessions preserve query logs perturbation, session throttling

Poisoned RAG Remove from vector index, Before reindexing Human review of source; reindex from entry quarantine source document, trusted source only invalidate cache

Compromised Network isolate endpoint, All destructive Rotate workload identities in trust MCP server revoke all credentials issued actions domain; forensic capture (two-person) to server, notify connected agents

Agent privilege Auto-expire tokens, disable Permission scope Security architecture review; abuse agent execution graph, freeze remediation permission scope remediation sign-off memory writes

Physical safety Trigger fail-safe mode, isolate ALL actions — no Joint safety-engineering dual approval threat control plane, notify safety exceptions required team

Mandatory: All automated containment actions SHALL be logged with justification (confidence score, triggered rule, timestamp). HITL override SHALL require two-person approval with immutable audit trail. Evidence capture SHALL NOT be bypassed by any automated action.

Phase 6: Post-Incident & Regulatory Response Regulatory Notification Decision Tree STEP 1 — Is the organisation a provider of a high-risk AI system placed on the Union market, or a deployer to whom Article 73 applies mutatis mutandis, and does the event meet the Article 3(49) definition of a serious incident? YES → Apply Article 73 timing: report immediately after establishing the required causal link or reasonable likelihood, and no later than 15 days after awareness; no later than two days for a widespread infringement or an Article 3(49)(b) serious incident; and no later than 10 days where a death occurs. Confirm the operative application date and any sectoral reporting route. An incomplete initial report may be followed by a complete report where necessary.

ODA3-2026-06-TCR-HAI-001 | Page 14 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

NO → Record the determination and proceed to Step 2. STEP 2 — Was personal data (PII or sensitive categories) accessed, exfiltrated, or exposed? YES → Notify supervisory authority (DPA) within 72 hours (GDPR Art. 33). Notify data subjects "without undue delay" if high risk to their rights. NO → Proceed to Step 3. STEP 3 — Does the incident affect critical infrastructure or essential services? YES → CIRCIA: notify CISA within 24 hours once final rule is in effect (final rule pending as of 1 June 2026 — monitor CISA for effective date). NIS2: early warning within 24 hours, full report within 72 hours. NO → Proceed to Step 4. STEP 4 — Does the incident involve AI-assisted consequential decisions affecting consumers (Colorado AI Act)? YES → Document for consumer appeal rights within 30 days. Engage compliance officer. STEP 5 — Does the incident involve PHI or healthcare AI systems? YES → HIPAA Breach Notification Rule: notify HHS and affected individuals within 60 days. If > 500 individuals, also notify prominent media in affected state. STEP 6 — Does the incident involve AI-assisted financial transactions or AI capability disclosure (FINRA / SEC)? YES → Notify relevant SRO promptly. Engage legal counsel for disclosure obligations under FINRA Rule 4370 and SEC guidance.

Mandatory Evidence Package for Regulators Evidence Type Content Normative Req.

Immutable timeline Signed timestamps from SIEM, orchestrator, safety systems, SHALL and HITL approval workflows; blockchain-anchored for P0 incidents

Affected artifact Signed AI-BOM of all affected models, embeddings, data SHALL manifest sources, and dependencies with provenance chain

Telemetry sample Sample of prompts/responses, tool calls, memory reads, SHALL retrieval results — automated PII redaction applied before submission

Containment evidence Automated action logs, confidence scores, triggered rules, SHALL HITL approval signatures, timestamps

Root cause Adversarial attack vs. structural permission failure vs. supply SHALL classification chain compromise; control gap mapping; remediation plan

Regulatory mapping Jurisdictional determination with citation to applicable SHALL rationale regulation and notification deadline calculation

ODA3-2026-06-TCR-HAI-001 | Page 15 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 7 — CONTROL DOMAINS & TECHNICAL REQUIREMENTS

All controls use normative language: SHALL indicates a mandatory requirement. SHOULD indicates a recommended control where multiple valid implementations exist. MUST has been normalized to SHALL throughout this document for consistency. This Technical Report defines 79 controls across 19 domains, comprising the original 10 domains (Domains 1–10, 48 controls), three domains formalised in this revision (Domains 11–13: Detection Reliability, Agentic Threat Detection, Severity Classification — 8 controls, newly authored; see Section 7 provenance notes), and six normative extension domains (Domains 14–19, drawn from ODA3-ECO-011/013/014/015 — 23 controls). This is the single authoritative control count for the AI-IRF™ v1.0 AI-IRF™ v1.0 control scheme.

Domain 1: Mcp & A2A Protocol Security — Cp-3

ID Requirement Normati Validation Method ve

MCP- MCP endpoints SHALL require mutual TLS (mTLS) SHALL Monthly port scan + configuration audit; 1 or workload identity federation. No unauthenticated automated certificate validation endpoints permitted.

MCP- All MCP message traffic SHALL be inspected at SHALL SIEM rule testing weekly; red-team 2 semantic level for injection patterns, malicious skill semantic injection exercises payloads, or protocol tampering.

MCP- Unregistered MCP servers SHALL be automatically SHALL Automated quarantine workflow testing; 3 quarantined upon detection; notifications sent to quarantine latency monitoring orchestrator and platform owner within 5 minutes.

MCP- MCP server manifests SHALL be registered with SHALL Orchestrator manifest registry audit; 4 the agent orchestrator before endpoints go live; registration gate enforcement testing unregistered servers blocked at network layer.

A2A-1 Inter-agent authorization SHALL enforce least- SHALL Policy validation in CI/CD; runtime privilege action scopes. Policy-as-code permission audit logs enforcement mandatory.

A2A-2 All inter-agent messages SHALL be SHALL Tabletop exercise quarterly; automated cryptographically signed (ECDSA) and integrity- playbook testing verified before processing. Unsigned or tampered messages SHALL be rejected and logged with SIEM alert.

A2A-3 A2A communication SHALL enforce per-agent-pair SHALL Network flow analysis; segmentation rate limits and anomaly detection to prevent agent policy compliance scans loop amplification attacks. Circuit-breaker SHALL trigger on >3 anomalies per hour, freezing the amplifying agent and alerting SOC.

Domain 2: Shadow Ai & Continuous Visibility — Cp-1, Cp-5

ID Requirement Normati Validation Method

ODA3-2026-06-TCR-HAI-001 | Page 16 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

ve

SAI-1 Organizations SHALL deploy instance-aware SHALL Weekly coverage report; automated discovery across network edges, SaaS connectors, discovery latency monitoring endpoints, and browser environments.

SAI-2 DLP controls SHALL inspect all AI data egress points SHALL Monthly DLP policy testing; simulated for sensitive data exposure. data leakage drills

SAI-3 Shadow AI instances SHALL be automatically SHALL Automated workflow testing; classified into risk tiers (sanctioned, shadow, rogue) quarantine effectiveness metrics within 1 hour of discovery. Classification logged to CMDB with tier assignment, timestamp, and rationale. Unclassified instances default to rogue tier.

SAI-4 Rogue AI instances SHALL trigger automated SHALL CMDB tagging audit; classification quarantine and incident declaration within 15 minutes accuracy validation of classification. AI Security Lead SHALL be paged automatically. Incident declared at SEV-2 minimum via SOAR workflow.

Domain 3: Adaptive Machine-Speed Response — Cp-5

ID Requirement Normati Validation Method ve

MSR- Response frameworks SHALL integrate LLM-as- SHALL Detection latency SLA < 500ms; false 1 Judge (LLM-J) metrics for real-time behavioral positive rate monitoring validation with confidence scoring.

MSR- Playbooks SHALL support conditional branching SHALL Weekly playbook dry runs; purple- 2 based on live telemetry deltas with confidence- team branching logic tests thresholded automation.

MSR- Behavioral baselines SHALL trigger automated SHALL A/B testing with red team; 3 containment for high-confidence attacks (confidence > containment efficacy metrics 95%) without human delay.

MSR- HITL SHALL be required for actions with blast radius SHALL Approval audit trail review; HITL 4 > 10 users, financial impact > $10K, or safety-critical compliance monitoring system involvement.

MSR-5 MTTC (mean time to containment) for agentic threat SHALL MTTC measurement across simulated events SHALL be 2 seconds or less. agentic threat events (MTH-SEC-007)

Domain 4: Model Extraction & Distillation Defenses — Cp-4

ID Requirement Normati Validation Method ve

MEX- Behavioral distillation detection SHALL analyze query SHALL Detection rule testing with emulated 1 patterns for systematic extraction via embedding extraction campaigns

ODA3-2026-06-TCR-HAI-001 | Page 17 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

similarity tracking across sessions.

MEX- Dynamic rate limiting SHALL use per-user/session SHALL Rate limit effectiveness review; 2 quotas with semantic clustering to detect sustained extraction campaign simulation extraction patterns.

MEX- Cryptographic output perturbation SHALL be applied SHALL A/B testing detection rate; 3 for high-confidence suspected extraction attempts (> perturbation impact on legitimate use 85% similarity score across sessions). assessed

MEX- API key revocation workflow SHALL execute within 5 SHALL Incident simulation quarterly; 4 minutes of confirmed extraction detection. Legal hold revocation latency monitoring preservation SHALL be initiated in parallel.

Domain 5: Ai-Bom & Supply Chain Integrity — Cp-4

ID Requirement Normati Validation Method ve

BOM- Every production AI system SHALL have a SHALL Pre-deployment gate enforcement; 1 cryptographically signed manifest before deployment; signature validation audits unsigned artifacts blocked by CI/CD gates.

BOM- Training data and model weights SHALL be SHALL Integrity check on data load; hash 2 cryptographically hashed before ingestion; hashes mismatch alerting SHALL be recorded and verified at load time.

BOM- External data sources SHALL undergo source SHALL Quarterly vendor assessment; 3 authenticity checks including vendor attestation attestation validation testing before integration.

BOM- Incident playbooks SHALL include supply chain SHALL Tabletop exercise; vendor escalation 4 rollback and vendor notification SLA (≤ 24 hours from path testing incident declaration).

BOM- Runtime BOM validation SHALL occur on every model SHALL Deployment pipeline log showing BOM 5 load; mismatch between loaded model and registered validation gate executed (MTH-SEC- BOM blocks inference. 007)

Domain 6: Agentic Permission Architecture (Apa) — Cp-2

ID Requirement Normati Validation Method ve

APA-1 Pre-execution validation gates SHALL enforce policy SHALL Policy enforcement audit; pre- checks before any consequential action. No bypass execution bypass testing permitted.

APA-2 Agents SHALL operate under least-privilege, task- SHALL Token lifetime monitoring; permission scoped permissions with auto-expiration (≤ 15 scope violation alerts minutes from task completion).

APA-3 HITL SHALL be required for: data export > 1K SHALL HITL approval logs; dual-control

ODA3-2026-06-TCR-HAI-001 | Page 18 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

records, payment initiation, production delete, PII compliance monitoring access, safety override.

APA-4 All permission grants, denials, and overrides SHALL SHALL Root cause classification in post- be logged with immutable timestamps and mortems; triage accuracy metrics cryptographic signing. SIEM ingestion mandatory; retention minimum 3 years.

APA-5 Tool use SHALL require a pre-execution approval gate, SHALL Tool invocation gate configuration audit separate from the general APA-1 action validation gate, (MTH-SEC-007) specific to tool invocation.

Domain 7: Regulatory & Compliance Operations

ID Requirement Normati Validation Method ve

REG- Incident playbooks SHALL include a regulatory SHALL Playbook validation with legal 1 notification decision tree mapping blast radius, data counsel; deadline simulation testing type, and AI risk tier to jurisdiction-specific deadlines.

REG- Legal and Compliance SHALL be embedded as SHALL RACI adherence audit; triage timeline 2 Consulted/Accountable roles in initial triage within 1 review hour of incident declaration.

REG- Organizations SHALL maintain incident-to-regulation SHALL Quarterly review documentation; 3 mapping tables reviewed quarterly with compliance mapping accuracy validation team.

REG- Audit-ready documentation SHALL be preserved with SHALL Retention policy audit; evidence chain 4 cryptographic integrity for minimum 3 years (GDPR integrity verification baseline); 5 years for critical infrastructure (NIS2); 10 years for health AI (HIPAA/HITECH).

Domain 8: Physical Ai & Safety Integration — Cp-2, Cp-5

ID Requirement Normati Validation Method ve

PHY-1 Separate incident playbooks SHALL exist for SHALL Playbook library review; safety physical-harm scenarios with explicit escalation paths scenario coverage audit to safety teams.

PHY-2 Safety and cybersecurity teams SHALL operate in SHALL Exercise attendance logs; joint integrated incident command structures with joint command effectiveness metrics tabletop exercises quarterly.

PHY-3 Systems SHALL mandate fail-safe fallback modes SHALL Safety validation testing; fail-safe upon cyber anomaly detection or attestation failure. activation drills Human-safe-stop states are the default.

PHY-4 Hardware-rooted trust SHALL default to human SHALL Architecture review; attestation failure oversight or safe-stop states if cryptographic simulation testing

ODA3-2026-06-TCR-HAI-001 | Page 19 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

attestation fails. No autonomous action permitted post-attestation failure.

Domain 9: Model Lifecycle Security — Cp-4, Cp-5

ID Requirement Normati Validation Method ve

MLC- Every production model SHALL have a unique SHALL CI/CD gate enforcement; signature 1 immutable identifier and cryptographic signature; validation at inference time unsigned models blocked from deployment.

MLC- Automated rollback capability SHALL execute within SHALL Monthly recovery drills with 2 15 minutes of compromise detection for critical documented results; rollback latency services. Monthly drills required. monitoring

MLC- Recovery playbooks SHALL include rollback SHALL Post-recovery audit; validation gate 3 validation gates confirming integrity before traffic is compliance monitoring restored.

MLC- Model version changes SHALL be logged in SHALL Audit log review; change management 4 immutable audit trail with signer identity, timestamp, compliance validation and approval record.

Domain 10: Zero Trust Architecture For Ai (Ztai) — Cp-1, Cp-2, Cp-3

ID Requirement Normati Validation Method ve

ZTA-1 AI infrastructure SHALL adopt explicit zero-trust SHALL Architecture review; ZTAI compliance design with documented architecture reviewed at assessment least annually.

ZTA-2 Continuous verification SHALL require re- SHALL Session duration audit; re- authentication every 15 minutes or per high-risk authentication enforcement testing action; no persistent sessions permitted.

ZTA-3 Micro-segmentation SHALL isolate inference, vector SHALL Network flow analysis; segmentation storage, and orchestration layers with explicit allow- policy compliance scans lists enforced in policy-as-code.

ZTA-4 Runtime least-privilege enforcement SHALL include SHALL Policy decision point logs; permission per-request authorization for tool execution with full grant/deny audit trails audit trail.

Domain 11: Detection Reliability

Provenance Note

NEWLY AUTHORED. No ODA3-ECO addendum exists for this domain. The control IDs and SHALL statements (REL-1, REL-2, REL-3) were first introduced in ODA3-2026-06-MTH-SEC-007 (Statement of Applicability) without an accompanying normative specification. This specification is authored to close that gap and bring Domain 11 to the same documentation standard as the originally-specified domains.

ODA3-2026-06-TCR-HAI-001 | Page 20 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

ID Requirement Normati Validation Method ve

REL-1 Auto-containment SHALL require >=3 ensemble SHALL Detection architecture documentation signals, agreement >=0.7 showing >=3 independent signal sources

REL-2 Confidence scores SHALL decay 10% per SHALL Decay function configuration and rolling consecutive similar alert window parameters

REL-3 Circuit-breaker SHALL disable automation after 3 FP SHALL Circuit breaker configuration showing 3- within 1h FP/1-hour trip threshold

Domain 12: Agentic Threat Detection

Provenance Note

NEWLY AUTHORED. No ODA3-ECO addendum exists for this domain. The control IDs and SHALL statements (APT-1, APT-2, APT-3) were first introduced in ODA3-2026-06-MTH-SEC-007 without an accompanying normative specification. Note: APT-2's wording overlaps substantially with APA-1/APA-5 (pre-execution gates). This specification distinguishes APT-2 as the THREAT DETECTION layer that triggers the APA permission gates, rather than duplicating the gate mechanism itself — APA controls the permission architecture; APT detects when that architecture is being abused or attacked.

ID Requirement Normati Validation Method ve

APT-1 Prompt injection detection >=90% across all channels SHALL Injection detection test report showing >=90% detection rate across channel types

APT-2 Tool abuse prevention via pre-execution gate on every SHALL Tool abuse pattern library documentation tool call

APT-3 Memory poisoning detection with automated SHALL Memory write scanning configuration and quarantine <=60s pattern library

Domain 13: Severity Classification

Provenance Note

NEWLY AUTHORED. No ODA3-ECO addendum exists for this domain. SEV-CLS and SEV-RPT were first introduced in ODA3-2026-06-MTH-SEC-007 without an accompanying normative specification, despite TCR-HAI-001 containing extensive prose discussion of severity concepts (SEV-1 through SEV-4 levels referenced throughout the document) without ever formalising that discussion into an auditable control. This specification closes that gap and is structurally aligned with the existing UAIF severity_presentation_score model (UAIF TCR-STD-002 §4.7-4.8) for cross-framework consistency, per the precedent already established in AIIS v1.0 (ODA3-2026-06-TCR-HAI-003).

ID Requirement Normati Validation Method ve

SEV- Deterministic severity scoring algorithm implemented SHALL Severity scoring algorithm documentation CLS and versioned with version history

SEV- Reportability thresholds evaluated deterministically SHALL Reportability threshold table covering all RPT applicable jurisdictions and regulations

Domain 14: Content Safety

Provenance Note

CSS-1, CSS-3, CSS-5 fully specified in ODA3-ECO-011 (normative). CSS-2, CSS-4, CSS-6, CSS-7 EXTENDED FROM SUMMARY: ECO-011 provided only control name, tier, and regulatory mapping for these four; full tiered implementation

ODA3-2026-06-TCR-HAI-001 | Page 21 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

detail authored separately and available in the extended specification package.

ID Requirement Normati Validation Method ve

CSS-1 Harmful content detection pipeline SHALL achieve SHALL See ODA3-ECO-011 full specification >99.9% block rate for CSAM (zero-tolerance); alert and log all blocked outputs.

CSS-2 Maintain a sufficiently detailed summary of content SHALL Published training data summary meeting used to train the GPAI model, published per EU AI Act Art. 53(1)(c) template requirements Art. 53(1)(c) template requirements. Implement output filtering to detect verbatim or near-ver

CSS-3 AI-generated synthetic media SHALL carry machine- SHALL See ODA3-ECO-011 full specification readable provenance marker (C2PA recommended) and human-facing disclosure label.

CSS-4 Design review SHALL confirm the AI system does not SHALL Design review documentation confirming employ subliminal techniques (content presented absence of subliminal/exploitative below the threshold of conscious perception) or techniques techniques designed to exploit known vulnerabilities

CSS-5 Monthly statistical analysis of AI outputs across SHALL See ODA3-ECO-011 full specification protected demographic groups SHALL be conducted; cumulative_bias_index > 0.05 triggers Chronic Harm Feedback Loop.

CSS-6 Conduct a quarterly Demographic Impact Assessment SHALL Quarterly DIA reports showing (DIA) for all high-risk AI systems. The DIA SHALL demographic parity difference and evaluate: demographic parity difference (<0.10 equalised odds difference results threshold), equalised odds difference (<0.10 threshol

CSS-7 Tier 1 + documented vulnerable population impact SHALL Vulnerable population identification and assessment, conducted alongside CSS-6's DIA, use-case mapping documentation specifically evaluating outcomes for identified vulnerable groups rather than aggregate demographic catego

Domain 15: Federated Learning Security

ID Requirement Normati Validation Method ve

FL-1 Federated clients authenticated via mutual TLS with SHALL Client certificate registry; update client-specific certificates; unregistered/revoked clients acceptance/rejection logs (ODA3-ECO- rejected. 013)

FL-2 Byzantine-robust aggregation (FedAvg with clipping; SHALL Gradient norm distribution logs; anomaly Krum/Bulyan for high-threat); gradients >3 sigma from flag rate (ODA3-ECO-013) epoch mean flagged; clients with anomaly rate >5% rejected.

FL-3 Differential privacy (DP-SGD) applied; epsilon <=1 for SHALL DP configuration audit; privacy budget high-sensitivity data, epsilon <=8 maximum ceiling for consumption log (ODA3-ECO-013) lower-sensitivity data; epsilon=10 not recommended for production.

FL-4 Global model signed with ECDSA (or CRYSTALS- SHALL Signed model checkpoint registry; Dilithium per PQC-1) after each aggregation round; aggregation audit log (ODA3-ECO-013)

ODA3-2026-06-TCR-HAI-001 | Page 22 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

signed checkpoint stored in AI-BOM registry.

Domain 16: Model Merge Defense

ID Requirement Normati Validation Method ve

MMD- Pre-merge source model vetting: AI-BOM provenance, SHALL Pre-merge vetting checklist; source model 1 absence of known malicious fine-tuning datasets, AI-BOM records (ODA3-ECO-013) training data manifest completeness verified; incomplete provenance rejected.

MMD- Post-merge backdoor scan (Neural Cleanse or ABS); SHALL Backdoor scan results with tool version; 2 semantic consistency testing across 500+ prompt anomaly cluster analysis (ODA3-ECO-013) templates; embedding space anomaly analysis.

MMD- Model merge operations performed in isolated SHALL Merge environment isolation configuration; 3 compute environment with no internet access; all artifact hash verification log (ODA3-ECO- artifacts hash-verified entering and leaving. 013)

Domain 17: Quantization Security

ID Requirement Normati Validation Method ve

QBS-1 Pre-quantization behavioural baseline established on SHALL Baseline output corpus; signed baseline 1,000+ representative inputs; stored as signed artefact artefact (ODA3-ECO-013) in AI-BOM.

QBS-2 Post-quantization differential analysis against SHALL Differential analysis report; divergence rate baseline; divergence >5% flagged; divergence >10% by input category (ODA3-ECO-013) rejects model.

QBS-3 Only trusted, audited quantization toolchains used SHALL Toolchain hash verification log (ODA3- (ONNX Runtime, TensorRT, PyTorch quantization); ECO-013) toolchain integrity hash-verified; third-party pre- quantized models screened via QBS-1/QBS-2.

Domain 18: Hallucination Detection

Provenance Note

EXTENDED. HAL-4 and HAL-5 are fully specified in ODA3-ECO-014 but were omitted from prior framework scope- planning documents (Statement of Applicability listed only HAL-1/2/3). Both are restored here to bring the AI-IRF™ v1.0 control scheme into alignment with the source addendum.

ID Requirement Normati Validation Method ve

HAL-1 RAG factual grounding verification: all factual claims SHALL D2-CTL-04 alignment evidence (ODA3- grounded in retrieved source documents; citation ECO-014) extraction and source verification; ungrounded claims flagged for human review.

HAL-2 Model confidence scoring implemented; outputs below SHALL D5-CTL-03 alignment evidence (ODA3-

0.7 confidence for consequential decisions require ECO-014)

human review before action; uncertainty surfaced to end users.

HAL-3 For high-stakes outputs (medical, legal, financial, SHALL D2-CTL-06 alignment evidence (ODA3- safety-critical): parallel inference with second model or ECO-014)

ODA3-2026-06-TCR-HAI-001 | Page 23 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

rule-based verifier; inconsistencies >10% divergence flagged for human review.

HAL-4 Hallucination rate tracked via human correction SHALL UAIF trust_erosion_rate field evidence feedback loop; alert at >3% of evaluated outputs; (ODA3-ECO-014) escalate to AI-IRF corrective action at >5% (trust_erosion_rate threshold).

HAL-5 For regulated domains (medical diagnosis, legal SHALL D6-CTL-03 Model Card alignment analysis, financial advice): external fact-checking API evidence (ODA3-ECO-014) or knowledge graph verification integrated for domain- specific claims.

Domain 19: Post-Quantum Cryptography

Provenance Note

PQC-1 operationalises the phased migration schedule established in ODA3-ECO-015 (Alignment Note) across four existing controls (BOM-4, MCP-1, A2A-2, REG-4). This control does not mandate immediate PQC implementation beyond what ECO-015 itself specifies — it mandates the readiness assessment and adherence to the documented timeline (Q1

2027 / Q3 2027 / Q3 2028).

ID Requirement Normati Validation Method ve

PQC-1 PQC readiness assessment SHALL be completed SHALL PQC readiness assessment document; covering BOM-4, MCP-1, A2A-2, and REG-4 migration plan with dated milestones cryptographic use cases. Migration to CRYSTALS- (ODA3-ECO-015) Dilithium (BOM-4, A2A-2) at Tier 3 from Q1 2027; hybrid Kyber-1024 (MCP-1) from Q3 2027; hybrid ECDSA+Dilithium (REG-4, all tiers) from Q3 2027.

Telemetry Integration Requirement: AI-IRF™ v1.0 requires SIEM/SOAR/XDR integration for all control domains with structured event schemas. Telemetry retention SHALL support forensic reconstruction and regulatory audit (minimum 3 years; see REG-4 for sector-specific requirements).

ODA3-2026-06-TCR-HAI-001 | Page 24 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 8 — REGULATORY & COMPLIANCE OPERATIONS

8.1 Comprehensive Regulatory Mapping

Regulation Applicable AI Incident Notification Maximum AI-IRF™ v1.0 Controls Types Deadline Penalty

EU AI Act Art. 73 A serious incident meeting Immediate after Not an Article 73- REG-1, REG-2, PHY-2 Article 3(49), within Article causal-link specific tariff; 73 scope; malfunction, threshold; outer provider- safety event, or near-miss limits: 15 days obligation is not automatically generally, 2 infringements may reportable days for fall under Article specified cases, 99(4): up to €15M 10 days where or 3% worldwide death occurs annual turnover, subject to the Regulation, Member-State rules, and SME treatment

GDPR Art. 33–34 Personal data breach from 72 hours to €20M or 4% REG-3, BOM-2, SAI-2 AI inference, training data DPA + without global turnover exposure, embedding undue delay to exfiltration data subjects

NIS2 Directive Critical infrastructure AI 24h early €10M or 2% REG-4, ZTA-1, BOM-4 incident, supply chain warning; 72h turnover compromise affecting detailed report essential services

Colorado AI Act Consequential decision 30 days for $20,000 per REG-1 with impact systems with bias, security consumer violation assessment, APA-3 flaws affecting Colorado appeal rights; consumers documentation mandatory

CIRCIA (US) Critical infrastructure AI 24 hours to Variable; CISA REG-4, ZTA-1, PHY-3 compromise (covered CISA for may issue entity) significant subpoena for non- cyber incidents compliance (final rule pending — obligations active upon rule effectiveness)

HIPAA / HITECH PHI exposure via AI 60 days — Up to $2.19M per REG-1, REG-4, BOM-2, inference pipeline, training HHS and violation category SAI-2 data, RAG retrieval, or affected per year (Tier 4 agent action individuals; willful neglect) media notification if > 500 in state

ODA3-2026-06-TCR-HAI-001 | Page 25 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

FINRA / SEC AI-assisted transaction Prompt report Suspension, fines, REG-1, REG-2, APA-3, anomaly, unauthorized to relevant licence MSR-4 algorithmic action, AI SRO; Rule revocation, capability disclosure failure 4370 Business disgorgement Continuity requirements

ISO/IEC 42001 All AI incidents in certified Annex C Certification All controls; audit-ready systems; management incident withdrawal; documentation review required management reputational timelines impact

8.2 Retention Requirements by Sector

Sector / Regulation Minimum Retention Notes

General (GDPR baseline) 3 years minimum All AI incidents involving EU data subjects

Critical infrastructure (NIS2) 5 years Essential services and critical infrastructure operators

Health AI (HIPAA / HITECH) 10 years AI systems touching PHI or clinical decision support

Financial AI (FINRA / SEC) 6 years (Books and Trade records, AI decision logs, capability Records Rule 17a-4) disclosures

Criminal investigation Indefinite — legal hold All evidence preservation obligations supersede standard retention

8.3 Ethical Guardrails

Principle Requirement Normative Level

Proportional Response Automated containment SHALL NOT exceed the blast radius SHALL necessary to contain the identified threat. Disproportionate containment is a governance failure.

Human Accountability HITL decisions SHALL be attributed to specific individuals SHALL with cryptographic sign-off. No anonymous approvals permitted.

Non-Discrimination Incident classification SHALL NOT use protected SHALL characteristics (race, religion, gender, national origin, etc.) as classification factors.

Transparency Automated containment decisions SHALL be explainable: the SHALL triggering rule, confidence score, and evidence basis SHOULD be available for audit and appeal within 24 hours.

Beneficence Response actions SHALL prioritize minimizing harm to SHALL individuals over operational continuity when these goals conflict.

ODA3-2026-06-TCR-HAI-001 | Page 26 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 9 — NEXT-GENERATION PLAYBOOK FRAMEWORK

9.1 Adaptive Playbook Library — Q2 2026 Priority Incidents

Playbook Trigger Branch Logic HITL Escalation Path Required?

PB-Agent- Tool call outside High confidence Payment Service owner → IAM Privilege-Abuse permission scope; (>95%): auto-disable initiation, data team → Compliance anomalous agent, revoke tokens. export > 1K officer write/export pattern Medium: rate-limit + records, request review. Low: production log + baseline update delete, PII access

PB-MCP- Unauthenticated MCP Immediate: isolate All destructive Platform owner → Compromise request; malicious skill broker, revoke actions require Vendor security → SOC payload detected; credentials, notify two-person lead semantic anomaly in connected agents, approval A2A traffic forensic snapshot

PB-Model- Query similarity > 0.85 Dynamic throttling → API key Abuse desk → SOC → Extraction across sessions + output perturbation → revocation, Product owner → Legal sustained high volume session isolation → legal hold + embedding legal hold if pattern initiation convergence confirmed

PB-Poisoned- Retrieved content fails Auto-remove from Human review Data owner → Platform RAG provenance check; vector index; before team → Supplier embedding outlier + quarantine source; reindexing; security user flag; index invalidate cache source integrity mismatch validation required

PB-Shadow-AI- Unregistered inference Quarantine endpoint Approval App owner → DLP Discovery endpoint detected; (block or rate-limit); required to team → Compliance sensitive data egress notify administrator; allowlist; data via unsanctioned AI preserve evidence exposure assessment

PB-Physical- Combined cyber Emergency stop → Override Safety commander → Safety-Trigger anomaly + safety fail-safe mode → requires joint Operations → sensor alert; unsafe isolate control plane → safety- Regulator (if required) actuator command notify safety team engineering detected dual approval

9.2 Playbook Integration Requirements

All playbooks SHALL expose REST APIs or MCP endpoints for SOAR integration with standardized input/output schemas.

Automation Safeguard Requirement Normative

ODA3-2026-06-TCR-HAI-001 | Page 27 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

Evidence preservation Automated containment SHALL never bypass evidence SHALL capture; all actions logged with immutable timestamps before execution

AI recommendation AI-generated recommendations for containment SHALL be SHALL validation validated by LLM-J scoring before executing high-impact actions

Rollback signing Rollback procedures SHALL be cryptographically signed SHALL and tested monthly against production-equivalent environments

Playbook version control All playbooks SHALL be version-controlled with signed SHALL commits; unauthorized modifications blocked by CI/CD gates

ODA3-2026-06-TCR-HAI-001 | Page 28 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 10 — IMPLEMENTATION ROADMAP & MATURITY MODEL

10.1 Phased Adoption Roadmap

Phase Timeline Priority Key Activities Success Criteria Gaps

1: Critical 0–60 days G1, G2, Deploy continuous AI discovery. 100% AI instances discovered Foundations G6 Enforce mTLS for all MCP endpoints. < 24h. All MCP endpoints Implement pre-execution validation authenticated. Pre-execution gates. Register HITL approval authority. policy blocks validated. Phase Complete PREP-1 through PREP-7. 1 preparation controls complete.

2: Regulatory 60–120 G7, G3, Embed regulatory decision trees. Documented EU AI Act Readiness days G5 Deploy LLM-as-Judge detection. Sign operational-readiness posture manifests for top 20 production models. established against the Tabletop exercises with Legal applicable actor role, system embedded. category, current application timetable, and unresolved dependencies; this criterion does not assert legal compliance. Auto-containment latency < 500ms. Manifest signing rate 100% for critical models.

3: Advanced Q3–Q4 G4, G9, Implement behavioral distillation Extraction detection rate > Capabilities 2026 G10 detection. Achieve < 15-min automated 90%. Recovery drill passed rollback. Complete ZTAI architecture with < 15-min rollback. ZTAI documentation. Integrate physical AI architecture review passed. safety playbooks.

4: 2027 G8, Full cyber-safety integrated incident < 2-min safety escalation Autonomous advance command. Autonomous HITL exception verified in drill. Regulatory Security d handling with formal verification. Cross- audit with zero critical findings. automati organizational threat intelligence on sharing.

10.2 Capability Maturity Model

Level Name Key Capabilities MTTD MTTC Auto-Containment Target Target

Level Legacy Baseline Static playbooks; inventory- > 60 min > 4 hours < 10% 1 centric visibility; human-speed triage

Level Managed Shadow AI discovery; basic < 15 min < 60 min 40% 2 MCP authentication; pre- execution gates

ODA3-2026-06-TCR-HAI-001 | Page 29 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

Level Advanced LLM-J detection; automated < 2 min < 10 min > 80% 3 containment (< 500ms); signed manifests; regulatory DTs

Level Autonomous Predictive detection; < 30 sec < 2 min > 95% 4 autonomous HITL exception handling; cyber-safety convergence

10.3 KPI Dashboard

KPI Target (Level 3) Measurement Method Frequency

Mean Time to Detect (MTTD) < 2 minutes SIEM detection-to-alert time; LLM- Real-time dashboard J scoring latency

Mean Time to Contain < 10 minutes Playbook execution logs; Post-incident report (MTTC) containment action timestamps

Automated containment rate > 80% of incidents IR records; automation trigger vs. Monthly review HITL override ratio

False positive rate < 5% for auto- Post-incident review; analyst Quarterly audit containment validation of automated actions

Regulatory submission 100% within Compliance audit; notification Per-incident accuracy deadline receipt verification

Manifest coverage 100% production CI/CD gate logs; signature Weekly models validation reports

Shadow AI discovery latency < 24h from first Discovery tool reports; instance Daily activity registration timestamps

MCP endpoint authentication 100% mTLS Port scan + configuration audit; Monthly certificate validation

Rollback execution time < 15 min for critical Recovery drill logs; rollback Monthly drill services completion timestamps

HITL compliance rate 100% for high- Approval audit trail; dual-control Per-incident impact actions verification logs

ODA3-2026-06-TCR-HAI-001 | Page 30 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 11 — NOTABLY ABSENT — FRAMEWORK SCOPE LIMITATIONS

This section documents what AI-IRF™ v1.0 explicitly does not cover and why. Documenting scope limitations is as important as documenting scope inclusions. It prevents threat inflation, sets accurate expectations for practitioners, and identifies areas requiring complementary frameworks or future research.

Out-of-Scope Area Rationale Complementary Framework

AI system design security Pre-deployment design security requires a OWASP ASVS, NIST SSDF, ISO/IEC (Secure SDLC for AI) separate framework; incident response 27034 assumes production deployment

Algorithmic bias and Bias is a governance and design matter; ISO/IEC 42001, EU AI Act Art. 9, NIST fairness remediation only security-incident-causing bias (e.g., AI RMF GOV function discriminatory classification) is in scope

Federated learning attack Federated learning security lacks Research corpus; future AI-IRF™ response operationalized incident response revision standards; active research area

AI watermarking and Content provenance is a separate C2PA, EU AI Act Art. 50 (disclosure provenance for synthetic standards track (C2PA); not a security obligations) media incident response matter

Post-quantum PQC migration is a preparedness NIST SP 800-208, CISA PQC guidance cryptographic migration program, not an incident response domain; AI infrastructure PQC readiness addressed in companion research

AI model interpretability and Explainability is a design and regulatory EU AI Act Art. 13, NIST AI RMF explainability compliance requirement; AI-IRF™ v1.0 MANAGE requires explainability of containment decisions, not of model internals

Non-AI data breaches If AI is not a causal factor in the breach, NIST SP 800-61r3, GDPR Art. 33–34 where AI is incidental NIST SP 800-61r3 and GDPR breach response frameworks apply

Criminal investigation and Chain of custody for criminal proceedings ACPO Digital Evidence principles, digital forensics standards requires jurisdiction-specific forensic ISO/IEC 27042 standards beyond this framework's scope

ODA3-2026-06-TCR-HAI-001 | Page 31 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 12 — STANDARDS CROSSWALK

Note: MITRE ATLAS technique IDs below use AML.T format (ATLAS v2.1). Specific technique IDs should be validated against the current ATLAS matrix at attack.mitre.org/resources/atlas before operational deployment. [T3]

Control Domain NIST AI RMF ISO/IEC MITRE ATLAS OWASP LLM OWASP Agentic

1.0 42001 v2.1 Top 10 2026

MCP/A2A Security PR.AI-P3 9.3 (Third- AML.T0051 (LLM LLM07: AGA-05: party risk) Prompt Injection) Insecure Plugin Tool/Plugin Design Exploitation

Shadow AI Visibility ID.AI-P1 6.2 (Asset AML.T0000 (ML N/A AGA-09: Shadow management Reconnaissance) AI )

Machine-Speed RS.AI-P2 8.2 (Incident N/A (response, LLM06: AGA-06: Response response) not attack) Excessive Autonomous Agency Action Abuse

Model Extraction PR.AI-P5 8.4 (IP AML.T0005 LLM04: Model N/A (pre- Defense protection) (Create Proxy ML Denial of deployment Model) Service concern)

AI-BOM & Supply ID.AI-P3 6.4 (Supply AML.T0010 LLM09: AGA-08: Supply Chain chain (Backdoor ML Overreliance Chain Poisoning security) Model) (supply chain)

Agentic Permissions PR.AI-P2 8.3 (Access AML.T0040 (ML LLM06: AGA-01: Excessive management Attack Staging) Excessive Permissions ) Agency

Physical AI Safety GV.AI-P4 8.7 AML.T0043 (Craft N/A N/A (Health/safet Adversarial Data y integration) — physical)

Regulatory GV.AI-P1 5.3 N/A N/A N/A Operations (Legal/regula tory)

Model Lifecycle PR.AI-P4 8.1 (AI AML.T0020 LLM09 AGA-08 lifecycle (Poison Training management Data) )

Zero Trust (ZTAI) PR.AI-P1 8.3 (Access AML.T0016 LLM08: AGA-01, AGA-02 management (Obtain Excessive ) Capabilities) Agency (boundary)

ODA3-2026-06-TCR-HAI-001 | Page 32 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 13 — GAP RESOLUTION MATRIX

Gap Gap Root Cause in AI-IRF™ v1.0 Resolution Validation Method ID Description Existing Frameworks

G1 MCP & A2A Treated as MCP-1 through MCP-4, A2A-1 Red-team MCP/A2A protocol observable through A2A-3: mTLS, semantic compromise exercise; security blind telemetry, not inspection, peer authorization, broker denied-lateral-movement spot primary attack isolation, manifest registration testing surface

G2 Shadow AI & Inventory-centric SAI-1 through SAI-4: Continuous Discovery coverage KPI visibility gaps model assumes discovery, DLP at egress, automated reporting; unauthorized AI visibility rather quarantine, instance classification detection testing than mandating discovery

G3 Static vs. Human-speed MSR-1 through MSR-4: LLM-J Purple-team timing tests on adaptive bounded scoring, conditional branching, containment latency; FP response playbooks; static confidence-thresholded automation rate monitoring IOC matching; no machine-speed automation

G4 Model Threat MEX-1 through MEX-4: Behavioral Simulated distillation extraction & acknowledged but extraction analytics, dynamic rate campaign detection rate; distillation — no detection limiting, output perturbation, extraction containment not methodology or automated key revocation efficacy operationalized response workflow

G5 AI-BOM & Traditional SBOM BOM-1 through BOM-4: Signed Provenance audit drills; supply chain mindset; no manifest, hashed artifacts, supplier rollback reconstruction integrity cryptographic attestation, supply chain rollback SLA testing provenance for AI artifacts

G6 Agentic Assumes APA-1 through APA-4: Pre-execution Agent overreach simulation permission adversarial intent policy checks, task-scoped testing; policy-block architecture only; missing pre- permissions, auto-expiration, HITL evidence collection execution for high-impact validation gates

G7 Regulatory Regulation-aware REG-1 through REG-4: Jurisdictional Tabletop exercises with mapping not but no decision decision tree, embedded mapped deadlines; RACI operational logic, deadlines, legal/compliance roles, audit-ready adherence audits or embedded evidence packages compliance roles

G8 Physical AI & Entirely absent or PHY-1 through PHY-4: Joint cyber- Safety incident simulation safety-security explicitly excluded safety command, fail-safe fallback, drills; fail-safe activation excluded from all reviewed hardware-rooted trust testing frameworks

ODA3-2026-06-TCR-HAI-001 | Page 33 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

G9 Model lifecycle Treated as MLC-1 through MLC-4: Immutable Integrity-verification testing; as operational operational signed lifecycle, 15-min rollback SLA, rollback-time drills — not security process, not integrity verification gates control enforceable security control with SLAs

G10 Zero trust not Individual controls ZTA-1 through ZTA-4: Identity-first, Architecture review against systematized present but not continuous verification, micro- ZTAI principles; control for AI unified under segmentation, runtime least-privilege enforcement validation zero-trust paradigm

ODA3-2026-06-TCR-HAI-001 | Page 34 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 14 — RACI MATRIX

Activity CISO AI Sec SOC AI/ML Legal/ Safety Product Lead Analyst Eng Comp Eng Owner

Declare Incident A R R C C C I (PHY)

Execute Auto-Containment I C R R I R I (PHY)

HITL Approval (Critical) A R C C C R (PHY C override )

Forensic Investigation I R R R C C I (PHY)

Manifest Verification I A C R C I I

Regulatory Notification A C C I R C I (PHY)

Model Rollback Execution I C I R I I C

Post-Mortem & Remediation A R C R C C R

Severity Classification A R R C C C I (PHY)

HITL Authority Designation A R I I C C I (PREP-4)

Legend: R = Responsible | A = Accountable | C = Consulted | I = Informed | PHY = applies only to physical AI incidents

ODA3-2026-06-TCR-HAI-001 | Page 35 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

◯ ◯ ◯

Section 15 — GLOSSARY

Term Definition

A2A (Agent-to-Agent) Protocol for inter-agent communication, trust establishment, and orchestration. A primary attack surface in agentic systems for lateral movement and trust-boundary bypass.

AI-BOM / Manifest Cryptographically signed manifest documenting model lineage, training data sources, embeddings, dependencies, MCP endpoints, and provenance chain. Equivalent to SBOM for AI systems.

Agentic Permission Framework enforcing pre-execution validation, task-scoped least-privilege permissions, Architecture (APA) and auto-expiring tokens for autonomous AI agents. Addresses both adversarial and structural permission failures.

CASB Cloud Access Security Broker. Security enforcement layer for SaaS applications used in AI-IRF™ v1.0 for shadow AI detection across SaaS connectors.

CI/CD Continuous Integration / Continuous Deployment pipeline. In AI-IRF™ v1.0, CI/CD gates enforce manifest signing requirements and prevent unsigned AI artifacts from reaching production.

CIRCIA Cyber Incident Reporting for Critical Infrastructure Act (US). Requires covered entities to report significant cyber incidents to CISA within 24 hours.

CMDB Configuration Management Database. In AI-IRF™ v1.0, CMDB must reflect continuously discovered AI instances, not periodic static inventory.

Consequential Action Any agent action with significant potential impact: data export > 1K records, payment initiation, production delete, PII access, safety-relevant command. Requires HITL approval.

HITL (Human-in-the- Mandatory human approval workflow for high-impact automated actions. Requires dual- Loop) control sign-off and immutable audit trail. Cannot be bypassed by automated systems.

LLM-as-Judge (LLM-J) Fine-tuned language model used to classify prompt/response pairs, tool calls, or behavioral patterns as malicious or benign with confidence scoring. Enables machine- speed triage.

Machine-Speed Automated detection and containment operating at adversarial velocity (milliseconds to Response seconds). Defined in contrast to human-speed triage which is structurally inadequate for agentic attacks.

MCP (Model Context Protocol for LLM-agent tool calling, context exchange, and orchestration. Treated in AI- Protocol) IRF™ v1.0 as a primary security boundary requiring authentication and semantic inspection.

mTLS Mutual TLS — both client and server authenticate via certificates. Mandatory for all MCP endpoint traffic under AI-IRF™ v1.0 (MCP-1).

RAG (Retrieval- Architecture pattern combining LLM inference with real-time retrieval from external Augmented Generation) knowledge sources. Retrieval pipeline is an attack surface for data poisoning and provenance attacks.

ODA3-2026-06-TCR-HAI-001 | Page 36 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0

Shadow AI Unmanaged or unsanctioned AI instances including personal deployments, SaaS AI upgrades, embedded AI features, or browser AI extensions operating outside organizational control.

SPIFFE/SPIRE Secure Production Identity Framework for Everyone / SPIRE Runtime Environment. Open standards for workload identity federation used in AI-IRF™ v1.0 to authenticate agents, tools, and MCP servers.

ZTAI (Zero Trust Application of zero-trust principles specifically to AI systems. Defined in AI-IRF™ v1.0 Architecture for AI) as: identity-first authentication for every AI component, per-request authorization, micro- segmentation of AI infrastructure layers, runtime least-privilege enforcement, and continuous verification.

ODA3-2026-06-TCR-HAI-001 | Page 37 | ODA3 Pvt Ltd

Authoritative source

Download the approved PDF — corrected 19 July 2026 →

This accessible HTML rendering is rebuilt from the current authoritative PDF. Where presentation differs, the PDF governs.