Oda3 Institute
Technical Report
AI Incident Response Framework v1.0 Next-Generation AI Security Incident Response Standard
DocID: ODA3-2026-06-TCR-HAI-001 Classification: Controlled
© ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
Document Control
Item Value
Document ID AI Incident Response Framework v1.0 (AI-IRF™ v1.0)
Edition 1 June 2026; regulatory correction issued 19 July 2026
Status Published — Corrected regulatory references (19 July 2026)
Companion Document AI-IRF™ v1.0 Executive Brief
Review Cycle Quarterly, with gap analysis against emerging threats and regulatory changes
Evidence Tier Legend T1 T1 — Primary Verified | T2 T2 — Secondary Verified | T3 Controlled Simulation / Academic Proxy | T4 Anecdotal / Unverified
Normative Language SHALL = mandatory control | SHOULD = recommended control
Evidence Tier Definitions: All empirical claims in this document are assigned an evidence tier. T1 — Primary Verified = directly observed and validated. T2 — Secondary Verified = cross-referenced from two or more independent sources. T3 — Reported = single credible source, not independently verified. T3 — Estimate = derived from benchmark data with stated methodology. T4 — Illustrative = scenario modeling, not empirical claim.
ODA3-2026-06-TCR-HAI-001 | Page 2 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 1 — EXECUTIVE SUMMARY & POSITIONING
1.1 Executive Summary
AI-IRF™ v1.0 is the first incident response framework engineered for agentic, machine-speed, and physically-consequential AI systems operating under evolving regulatory requirements and staged application timelines. [T2] It addresses nineteen critical operational gaps identified across existing industry frameworks and normative extension addenda by transitioning from traditional observe-and-respond models to a continuously verify, constrain, and recover paradigm — with mandatory pre-execution policy gates, cryptographic artifact governance, and adaptive automation.
LICENCE NOTICE — GEL v1.0 | ODA3-2026-06-TCR-HAI-001 | Controlled This document is part of the GAISSF Ecosystem published by ODA3 Institute (ODA3 Pvt Ltd) under GEL v1.0, effective 1 June 2026. It is classified Controlled — Enterprise Standard. Commercial use — including embedding in training programmes, advisory services, or tool integrations — requires a separate written commercial licence from ODA3 Institute (GEL §3.4). AI training data use prohibited without licence (GEL §3.6). Evidence tiers: T1 = Primary Verified | T2 = Secondary Verified | T3 = Controlled Simulation/Academic Proxy | T4 = Anecdotal/Unverified. Financial figures in this document include an estimation formula and confidence range as required by the ODA3 Institute evidence standard. GAISSF™, UAIF™, AI-IRF™, AI IRF CERT™, and ODA3™ are trademarks of ODA3 Pvt Ltd, asserted on a use-in-commerce basis. Registration applications are pending. No statement in this document represents any mark as registered unless and until registration has been granted in the relevant jurisdiction (GEL §9.1). As of 19 July 2026, the AI IRF CERT™ scheme is under development and is not represented as accredited or operational. ODA3 Institute is the sole owner, proprietor, and governing body of the AI-IRF™ framework in perpetuity (GEL §10.5). Disclaimer: provided “AS IS” without warranties (GEL §12). Governing law: Republic of India; DIAC arbitration, New Delhi seat (GEL §14). All enquiries: https://oda3.org/ — Attribution (GEL §6): AI-IRF™ v1.0 Technical Report © ODA3 Institute, GEL v1.0. Companion document: AI-IRF™ v1.0 Executive Brief (ODA3-2026-06-EXB-HAI-002).
The gap identification methodology analyzed: CoSAI V1.0, CoSAI AI IRF V1.0 (November 2025), NIST SP 800-61r3, OWASP LLM Top 10 v1.0 (2023), OWASP Top 10 for Agentic Applications 2026, OASIS CACAO v2.0, MITRE ATLAS v2.1, and ISO/IEC 42001:2023 against documented incident patterns from Q1–Q2 2026. [T2]
→ COMPANION DOCUMENT: For Board and CISO governance decisions, financial exposure modeling, and regulatory application-timeline implications, see the AI-IRF™ v1.0 Executive Brief.
Core Capability Operational Impact Gap Addressed
Protocol-Aware Security MCP and A2A endpoints treated as primary attack surfaces G1 with authenticated, inspected, and policy-enforced traffic
Runtime Discovery Continuous instance-aware visibility eliminating shadow AI G2 blind spots
Machine-Speed Response Automated detection and containment at adversarial G3 velocity (ms–seconds) with HITL gates for critical actions
Extraction Defense Behavioral distillation detection, dynamic rate limiting, and G4 cryptographic output perturbation
Cryptographic Provenance Signed AI-BOM for all production artifacts enabling forensic G5 reconstruction and regulatory audit
ODA3-2026-06-TCR-HAI-001 | Page 3 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
Agentic Permissioning Pre-execution validation, task-scoped least-privilege, and G6 auto-expiring tokens
Regulatory Decision Logic Embedded jurisdictional decision trees mapping incident G7 type to notification deadlines
Safety-Security Convergence Integrated cyber-physical incident command for AI systems G8 with actuator control
Lifecycle-as-Control Immutable model identifiers, signed artifacts, and 15-minute G9 rollback SLA
Zero Trust Architecture Identity-first, micro-segmented, continuously verified AI G10 infrastructure
Detection Reliability Ensemble-validated auto-containment preventing false- G11 Engineering positive cascades and single-detector dependency risk
Agentic Threat Detection Prompt injection, tool abuse, and memory poisoning G12 detection distinct from the APA permission architecture
Deterministic Severity Algorithmic, versioned severity scoring and reportability G13 Classification determination removing case-by-case judgement under time pressure
Content Safety & Societal Harmful content filtering, copyright protection, synthetic G14 Harm media disclosure, bias/fairness monitoring, vulnerable population protections
Federated Learning Security Byzantine-robust aggregation, differential privacy, and client G15 authentication for distributed AI training
Model Merge Defense Pre-merge provenance vetting and post-merge backdoor G16 scanning for combined fine-tuned models
Quantization Backdoor Pre/post-quantization behavioural baseline comparison G17 Screening preventing precision-reduction-triggered backdoors
Hallucination Detection & RAG grounding verification, confidence calibration, cross- G18 Mitigation model consistency, and rate monitoring for factual AI failures
Post-Quantum Cryptographic Phased readiness assessment and algorithm migration for G19 Migration AI-BOM signing, endpoint auth, and regulatory evidence integrity
1.2 Framework Scope & Applicability
AI-IRF™ v1.0 applies to: large language models (LLMs), multimodal models, and foundation models in production; Retrieval-Augmented Generation (RAG) pipelines; agentic architectures with autonomous planning, tool execution, and memory persistence; AI systems with physical actuation capabilities; and hybrid cloud/edge/on-premises deployments.
NOTABLY ABSENT — Scope Limitation ◆ Traditional software incident response (addressed by NIST SP 800-61r3) — this framework does not replicate or replace general IR guidance. ◆ Non-AI data breach response governed by GDPR/NIST frameworks where AI is not a causal factor.
ODA3-2026-06-TCR-HAI-001 | Page 4 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◆ Ethical AI governance and algorithmic bias remediation (addressed by ISO/IEC 42001 and the EU AI Act prohibited practices articles). ◆ Federated learning security and differential privacy implementation are addressed in the AI-IRF™ v1.0 normative extension documents (ODA3-ECO-013: FL-1–4 controls). These controls are part of the AI-IRF™ v1.0 control scheme as of 1 June 2026. ◆ Detection Reliability, Agentic Threat Detection, and Severity Classification (Domains 11–13: REL-1–3, APT-1–3, SEV-CLS/SEV-RPT) are part of the AI-IRF™ v1.0 control scheme as of this revision. These domains were referenced in framework scope-planning documents prior to this revision but lacked a formal Technical Report specification; that gap is closed in Section 7 of this document. ◆ Content Safety and Societal Harm (Domain 14: CSS-1–7) is part of the AI-IRF™ v1.0 control scheme via ODA3-ECO-011. Model Merge Defense and Quantization Security (Domains 16–17: MMD-1–3, QBS-1–3) are part of the AI-IRF™ v1.0 control scheme via ODA3-ECO-013. ◆ Hallucination Detection (Domain 18: HAL-1–5) is part of the AI-IRF™ v1.0 control scheme via ODA3-ECO- 014. Post-Quantum Cryptography (Domain 19: PQC-1) operationalises the phased migration schedule in ODA3-ECO-015 across BOM-4, MCP-1, A2A-2, and REG-4. ◆ AI system design security (secure SDLC for AI) — this framework covers incident response, not pre-deployment design security.
ODA3-2026-06-TCR-HAI-001 | Page 5 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 2 — 2026 SECURITY ASSUMPTIONS & THREAT BASELINE
2.1 Threat and Operational Assumptions
The following assumptions are not theoretical forecasts — they reflect documented incident patterns from Q1–Q2 2026 and published threat intelligence. [T2]
Assumption Evidence Tier
Adversaries operate at machine speed Adaptive AI-Driven Infrastructure Campaign: T3 — Reported using LLMs to generate polymorphic 600+ FortiGate devices in 55 countries, prompt chains, automate distillation, and autonomous AI attack framework chain tool abuses across agents in seconds
MCP and A2A are primary attack surfaces OpenClaw/ClawHub Marketplace Crisis: 492 T2 — Secondary routinely exploited for lateral movement unauthenticated MCP servers, 1,184 malicious Verified and trust-boundary bypass skills, 21K+ exposed instances
Model extraction is commoditized — OpenAI/Anthropic model distillation via T1 — Primary proprietary models replicable from DeepSeek/MiniMax/Moonshot: 16M+ exchanges Verified sufficient API access documented
Shadow AI is the default organizational OpenClaw/ClawHub: 21K+ exposed AI instances T2 — Secondary state without continuous discovery across organizations unaware of deployment Verified controls scope
Agentic over-provisioning causes more Meta Internal AI Agent Sev 1: agent published T1 — Primary incidents than adversarial input sensitive data without approval — architectural, Verified not adversarial
Supply chain attacks target AI artifacts — Context AI/Vercel OAuth Supply Chain: T2 — Secondary training data, embeddings, MCP servers, infostealer → OAuth token harvest → cross- Verified orchestration dependencies tenant breach; $2M data listing
Regulators demand real-time structured EU AI Act Article 73 serious-incident reporting is T1 — Primary notifications — narrative reports are not a universal 72-hour rule: reporting is Verified insufficient immediate once the required causal link or reasonable likelihood is established, subject to statutory outer limits of 15 days, two days for specified widespread infringements or serious incidents, and 10 days where a death occurs. Application timing depends on the system category and the operative amended timetable. CIRCIA obligations depend on the final rule and its effective date
NOTABLY ABSENT — Scope Limitation ◆ Post-quantum cryptography (PQC) readiness for AI model signing is addressed in ODA3-ECO-015 (PQC-1 control) as a normative Tier 3 requirement of the AI-IRF™ v1.0 control scheme. Quantum computing attacks on AI inference infrastructure remain post-2026 in threat horizon. ◆ AI-generated disinformation at scale is partially addressed through ODA3-ECO-011 (CSS-4: Disinformation and Manipulation Prevention). For full content safety governance, see the Content Safety addendum (ODA3-ECO-011,
ODA3-2026-06-TCR-HAI-001 | Page 6 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
CSS-1–7 controls). ◆ AI system failures attributable to poor data quality or statistical drift without adversarial causation are excluded from this framework's incident taxonomy.
ODA3-2026-06-TCR-HAI-001 | Page 7 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 3 — CORE DESIGN PRINCIPLES
All seven design principles are normative: organizations implementing AI-IRF™ v1.0 SHALL comply with P1–P7 for any AI system within the framework's scope (see Section 1.2). SHOULD qualifiers are reserved for implementation methods where multiple valid approaches exist.
Principle Operational Definition Enforcement Mechanism Normative Level
P1: Never Trust, Every agent, tool call, inference SPIFFE/SPIRE workload SHALL Always Verify request, memory read, and A2A identity federation, per- message is authenticated and request policy evaluation, authorized per interaction. No implicit continuous re-authentication trust based on network location or prior approval.
P2: Machine- Automated detection and containment LLM-as-a-Judge (LLM-J) SHALL Speed Default, operate at adversarial velocity (ms– scoring, confidence- HITL for Critical seconds). High-impact actions require thresholded automation, explicit human approval via dual-control immutable approval audit workflow. trails
P3: Cryptographic Every model weight, embedding, ECDSA/RSA signing, SHA- SHALL Provenance by training dataset, prompt template, and 256 hashing; blockchain- Default MCP endpoint has an immutable, anchored audit logs SHOULD cryptographically signed manifest entry. be deployed for high-risk systems
P4: Discovery Continuous runtime discovery of AI Egress DLP with AI SHALL Over Inventory instances across network edges, SaaS fingerprinting, EDR with AI connectors, endpoints, and browser process signatures, CASB extensions — not periodic static CMDB with AI capability inventory updates.
P5: Safety- Cyber incidents with physical harm Joint cyber-safety tabletop SHALL for Security pathways require integrated incident exercises (quarterly), fail-safe physical AI Convergence command with functional safety teams fallback modes, hardware- systems; (ISO 26262 / IEC 61508). rooted trust attestation SHOULD for all others
P6: Audit-Ready All AI interactions are logged with Immutable SIEM ingestion, SHALL Telemetry cryptographic integrity, structured signed log chains, automated schemas, and PII-redaction capabilities redaction pipelines for regulatory submission and forensic reconstruction.
P7: Lifecycle-as- Model versioning, rollback, and CI/CD gates, signed artifact SHALL Security-Control retraining are enforced security controls deployment, 15-minute with defined SLAs — not optional rollback capability (monthly operational conveniences. drill required)
ODA3-2026-06-TCR-HAI-001 | Page 8 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 4 — REFERENCE ARCHITECTURE & AI CONTROL PLANE
4.1 AI Control Plane — Five-Layer Security Model
The AI Control Plane is the authoritative enforcement layer responsible for identity-bound execution, policy- constrained action authorization, and verifiable observability across AI-initiated operations spanning one or more trust domains. All AI-IRF™ v1.0 controls map to one or more Control Plane layers.
CP Layer Name Scope Primary Control IDs Layer
CP-1 Identity & Workload identity for agents, tools, MCP ZTA-1, ZTA-2, MCP-1, APA-2 Credentials servers; credential lifecycle; SPIFFE/SPIRE federation; per-request authentication
CP-2 Permissions & Pre-execution policy evaluation; task-scoped APA-1, APA-2, APA-3, APA-4, Scoping least-privilege; HITL authority; auto-expiring ZTA-4 tokens; permission audit trails
CP-3 Orchestration & MCP endpoint security (mTLS, semantic MCP-1, MCP-2, A2A-1, A2A-2, MCP inspection); A2A authorization; agent-to-agent A2A-3, ZTA-3 trust boundaries; micro-segmentation
CP-4 Validation Gates Pre-execution policy checks for all APA-1, BOM-4, MEX-1, MEX-2, consequential actions; manifest verification; MEX-3 RAG provenance validation; extraction detection
CP-5 Observability & Behavioral baseline monitoring; LLM-as-Judge MSR-1, MSR-2, REG-4, APA-4, Audit scoring; immutable telemetry; cryptographic MLC-4 log integrity; regulatory evidence packaging
MLC-5 Drift detection SHALL Drift-triggered retraining workflow thresholds SHALL audit (MTH-SEC-007) trigger a dual- approval retraining workflow; retraining without dual approval is blocked.
4.2 Logical Architecture Components
Layer Components Control Plane Primary Control IDs Layer
User / Entity Human users, other agents, CP-1 ZTA-1, ZTA-2 external systems
Application Interface Chat UI, API gateway, CLI, CP-1, CP-2 MCP-1, SAI-1 browser extensions
Agent Orchestration Planner, executor, memory CP-2, CP-3, APA-1, APA-2, APA-3
ODA3-2026-06-TCR-HAI-001 | Page 9 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
controller, tool router CP-4
Memory System Session memory, persistent KB, CP-4, CP-5 BOM-2, MSR-1 vector store, graph DB
Retrieval (RAG) Retriever, embedder, reranker, CP-4 BOM-3, APA-1 source connectors
LLM Core Base model, fine-tuned adapter, CP-4, CP-5 MEX-1, MLC-1, MSR-1 inference endpoint
Tools / Plugins MCP servers, APIs, code CP-3, CP-4 MCP-1, MCP-2, A2A-1 executors, web search
Data Sources Training data, documents, CP-4 BOM-1, BOM-2, BOM-3 external feeds
Infrastructure Compute, network, cloud IAM, CP-1, CP-2, ZTA-1, ZTA-3, ZTA-4 orchestration layer CP-3
4.3 Zero Trust Architecture for AI (ZTAI) — Mandatory Controls
ZTAI Principle AI-Specific Implementation Normative Validation Method Req.
Identity-First Every agent, tool, MCP server, and SHALL Monthly identity audit; automated A2A peer has a workload identity orphaned-identity detection (SPIFFE, JWT). No anonymous inference or tool execution permitted.
Continuous Per-request authorization for tool calls; SHALL Runtime enforcement logs; session Verification session timeouts ≤15 minutes; re- duration monitoring authentication for high-risk actions.
Micro-Segmentation Inference endpoints, vector stores, SHALL Network flow review; segmentation training pipelines, and orchestration policy-as-code validation layers reside in separate trust zones with explicit allow-lists.
Least-Privilege Agent tokens auto-expire after task SHALL Token lifetime monitoring; Runtime completion; no standing privileges; permission grant/deny audit trails permissions are task-scoped and time- bound.
Encrypt Everywhere All MCP/A2A traffic uses TLS 1.3 with SHALL TLS configuration scans; key mutual authentication; data at rest rotation compliance audits encrypted with customer-managed keys.
ODA3-2026-06-TCR-HAI-001 | Page 10 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 5 — INCIDENT SEVERITY CLASSIFICATION
AI-IRF™ v1.0 defines four incident severity levels. Severity determines automated response thresholds, HITL escalation requirements, regulatory notification obligations, and evidence preservation priority. Severity SHALL be assigned within 15 minutes of incident declaration and SHALL be reviewed at each triage milestone.
Physical harm potential; critical infrastructure AI compromise; multi-system agentic cascade; confirmed high-risk system failure under EU AI Act. Automated containment initiated immediately. P0 Safety team notified in parallel. Legal and Compliance engaged within 15 minutes. The internal CRITI escalation clock starts at P0 declaration; any statutory notification clock SHALL be calculated CAL separately under the applicable law, actor role, incident definition, awareness trigger, causal-link test, and operative application date. Two-person HITL approval required for all actions.
Active data exfiltration exceeding notification thresholds; confirmed MCP compromise or lateral P1 movement; model extraction confirmed; confirmed supply chain compromise affecting production. HIGH Automated containment active. CISO notified within 30 minutes. Legal and Compliance consulted. Regulatory notification decision tree executed within 1 hour.
Shadow AI discovered with sensitive data exposure; suspected but unconfirmed model extraction; P2 policy violation by AI agent without confirmed exfiltration; anomalous A2A traffic pattern. Rate- MEDIU limiting and session monitoring activated. Security architecture team engaged. Compliance notified M for awareness. 24-hour investigation window.
Behavioral baseline deviation within normal operational range; configuration drift detected; single P3 low-confidence anomaly alert; training data integrity warning without confirmed poisoning. Logged LOW and queued for analyst review. No automated containment unless confidence threshold exceeded. 72-hour investigation window.
5.1 Severity Escalation Rules
Severity SHALL be escalated (P3 → P2 → P1 → P0) when any of the following are confirmed: additional systems involved; physical harm pathway identified; regulatory notification threshold crossed; HITL approval requested for high-impact action; containment fails to reduce anomaly signal within response SLA. Severity SHALL NOT be de-escalated without documented evidence of containment and root cause determination. De-escalation requires security architect review and CISO acknowledgement for P0 and P1 incidents.
ODA3-2026-06-TCR-HAI-001 | Page 11 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 6 — AI-ADAPTED INCIDENT RESPONSE LIFECYCLE
Phase Traditional AI-IRF™ v1.0 Augmentation Time Target Alignment
0: Continuous Identify Runtime shadow AI detection, instance Continuous Discovery fingerprinting, manifest registry sync
1: Preparation Govern, Protect Manifest signing, ZTAI segmentation, adaptive Pre-incident playbook pre-approval, HITL authority designation, team readiness drills
2: Detection & Detect Machine-speed behavioral baselines, LLM-as- < 2 min (P0/P1) Triage Judge scoring, confidence-thresholded alerting, severity classification
3: Machine-Speed Respond Automated isolation < 500ms for high-confidence < 500ms auto; < 5 min Containment threats; HITL gates for critical actions HITL
4: Eradication Respond Signed rollback, poisoned data quarantine, < 15 min for critical manifest reverification, credential rotation
5: Recovery Recover Canary deployment of clean model, embedding Per recovery plan integrity check, adversarial regression testing
6: Post-Incident & Improve Regulatory decision tree execution, structured Per applicable law; use Regulatory notification submission, audit evidence jurisdiction- and packaging incident-specific triggers and deadlines
Phase 0: Continuous Discovery Control ID Control Telemetry Requirement Success Metric
SAI-1 SHALL deploy network-edge AI Egress DLP with AI 100% of external AI API discovery scanning all egress fingerprinting; proxy logs with calls discovered within 1 traffic for AI API patterns model inference signatures hour
SAI-2 SHALL scan endpoints for EDR with AI process signatures; < 24h latency from first personal AI instances and browser browser extension inventory execution to discovery AI extensions
SAI-3 SHALL monitor SaaS platforms for CASB with AI capability 100% of SaaS AI silent AI feature enablement via inventory; API connector upgrades detected before CASB monitoring first data exposure
SAI-4 SHALL classify each AI instance: Automated classification engine; ≥ 95% accuracy in data sensitivity, corporate vs. CMDB tagging instance risk classification personal, risk tier
SAI-5 Unauthorised AI deployments classified SHALL SOC alerting workflow test; as rogue SHALL trigger automated alert latency monitoring
ODA3-2026-06-TCR-HAI-001 | Page 12 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
SOC alert with risk classification within (MTH-SEC-007) 5 minutes of rogue designation.
Phase 1: Preparation [NEW — addresses gap in prior versions] Phase 1 was not addressed in the prior framework draft. This is a CRITICAL gap: machine-speed containment (Phase 3) fails without pre-approved playbooks, pre-established HITL authority, and verified manifest signing infrastructure. Organizations SHOULD complete all Phase 1 controls before declaring AI-IRF™ v1.0 operational readiness.
Control ID Preparation Control Normative Completion Criterion Level
PREP-1 Sign cryptographic manifests (AI-BOM) for all SHALL 100% manifest coverage on production AI systems before deployment; production systems unsigned artifacts blocked by CI/CD gates
PREP-2 Implement ZTAI micro-segmentation isolating SHALL Architecture review passed; inference, vector storage, and orchestration segmentation policy-as-code layers with documented allow-lists validated
PREP-3 Pre-approve adaptive playbooks for all six SHALL All six playbooks signed, tested, priority incident types (see Section 8.2); obtain and accessible in < 30 seconds CISO sign-off
PREP-4 Designate and document HITL approval SHALL HITL authority matrix documented authority for each consequential action and tested in tabletop exercise category; establish dual-control workflow
PREP-5 Conduct AI-specific incident response drills SHALL Drill completion log; response time quarterly including at least one machine-speed benchmarks recorded containment simulation
PREP-6 Establish behavioral baselines for all SHALL 7-day rolling baseline established; production AI systems; sign and version baseline signing verified baselines for audit integrity
PREP-7 Verify rollback capability for critical AI services; SHALL Monthly rollback drill passed; demonstrate < 15-minute rollback execution in rollback artifacts cryptographically drill signed
Phase 2: Machine-Speed Adaptive Detection Detection Layer Technology Response FP Tolerance Auto-Action Time Threshold
Statistical anomaly Token usage spikes, < 100ms High — triggers N/A — escalates only latency deviations, error LLM-J validation rate changes
LLM-as-Judge Fine-tuned classifier on < 500ms Medium — analyst > 95% confidence (LLM-J) prompt/response pairs for review for medium malicious intent confidence
ODA3-2026-06-TCR-HAI-001 | Page 13 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
Semantic similarity Embedding drift from < 1s Low — auto-contain > 95% confidence baseline; query pattern if > 95% confidence clustering
Graph-based Cross-session attack chain 5s–30s Very low — HITL Mandatory HITL correlation reconstruction; A2A lateral review mandatory movement detection
Mandatory: Every production AI system SHALL maintain a 7-day rolling behavioral baseline with automated alerting on > 3σ deviation. Baselines SHALL be versioned and signed for audit integrity.
Phase 3: Machine-Speed Containment with HITL Gates Incident Type Auto Action (0–500ms) HITL Threshold HITL Action
Prompt injection Isolate session, rate-limit to 1 High confidence OR Revoke API key, quarantine user req/min, capture context P1/P0 account, notify app owner snapshot
Model extraction Dynamic rate limiting, Pattern confirmed Revoke access, initiate legal hold, cryptographic output across sessions preserve query logs perturbation, session throttling
Poisoned RAG Remove from vector index, Before reindexing Human review of source; reindex from entry quarantine source document, trusted source only invalidate cache
Compromised Network isolate endpoint, All destructive Rotate workload identities in trust MCP server revoke all credentials issued actions domain; forensic capture (two-person) to server, notify connected agents
Agent privilege Auto-expire tokens, disable Permission scope Security architecture review; abuse agent execution graph, freeze remediation permission scope remediation sign-off memory writes
Physical safety Trigger fail-safe mode, isolate ALL actions — no Joint safety-engineering dual approval threat control plane, notify safety exceptions required team
Mandatory: All automated containment actions SHALL be logged with justification (confidence score, triggered rule, timestamp). HITL override SHALL require two-person approval with immutable audit trail. Evidence capture SHALL NOT be bypassed by any automated action.
Phase 6: Post-Incident & Regulatory Response Regulatory Notification Decision Tree STEP 1 — Is the organisation a provider of a high-risk AI system placed on the Union market, or a deployer to whom Article 73 applies mutatis mutandis, and does the event meet the Article 3(49) definition of a serious incident? YES → Apply Article 73 timing: report immediately after establishing the required causal link or reasonable likelihood, and no later than 15 days after awareness; no later than two days for a widespread infringement or an Article 3(49)(b) serious incident; and no later than 10 days where a death occurs. Confirm the operative application date and any sectoral reporting route. An incomplete initial report may be followed by a complete report where necessary.
ODA3-2026-06-TCR-HAI-001 | Page 14 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
NO → Record the determination and proceed to Step 2. STEP 2 — Was personal data (PII or sensitive categories) accessed, exfiltrated, or exposed? YES → Notify supervisory authority (DPA) within 72 hours (GDPR Art. 33). Notify data subjects "without undue delay" if high risk to their rights. NO → Proceed to Step 3. STEP 3 — Does the incident affect critical infrastructure or essential services? YES → CIRCIA: notify CISA within 24 hours once final rule is in effect (final rule pending as of 1 June 2026 — monitor CISA for effective date). NIS2: early warning within 24 hours, full report within 72 hours. NO → Proceed to Step 4. STEP 4 — Does the incident involve AI-assisted consequential decisions affecting consumers (Colorado AI Act)? YES → Document for consumer appeal rights within 30 days. Engage compliance officer. STEP 5 — Does the incident involve PHI or healthcare AI systems? YES → HIPAA Breach Notification Rule: notify HHS and affected individuals within 60 days. If > 500 individuals, also notify prominent media in affected state. STEP 6 — Does the incident involve AI-assisted financial transactions or AI capability disclosure (FINRA / SEC)? YES → Notify relevant SRO promptly. Engage legal counsel for disclosure obligations under FINRA Rule 4370 and SEC guidance.
Mandatory Evidence Package for Regulators Evidence Type Content Normative Req.
Immutable timeline Signed timestamps from SIEM, orchestrator, safety systems, SHALL and HITL approval workflows; blockchain-anchored for P0 incidents
Affected artifact Signed AI-BOM of all affected models, embeddings, data SHALL manifest sources, and dependencies with provenance chain
Telemetry sample Sample of prompts/responses, tool calls, memory reads, SHALL retrieval results — automated PII redaction applied before submission
Containment evidence Automated action logs, confidence scores, triggered rules, SHALL HITL approval signatures, timestamps
Root cause Adversarial attack vs. structural permission failure vs. supply SHALL classification chain compromise; control gap mapping; remediation plan
Regulatory mapping Jurisdictional determination with citation to applicable SHALL rationale regulation and notification deadline calculation
ODA3-2026-06-TCR-HAI-001 | Page 15 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 7 — CONTROL DOMAINS & TECHNICAL REQUIREMENTS
All controls use normative language: SHALL indicates a mandatory requirement. SHOULD indicates a recommended control where multiple valid implementations exist. MUST has been normalized to SHALL throughout this document for consistency. This Technical Report defines 79 controls across 19 domains, comprising the original 10 domains (Domains 1–10, 48 controls), three domains formalised in this revision (Domains 11–13: Detection Reliability, Agentic Threat Detection, Severity Classification — 8 controls, newly authored; see Section 7 provenance notes), and six normative extension domains (Domains 14–19, drawn from ODA3-ECO-011/013/014/015 — 23 controls). This is the single authoritative control count for the AI-IRF™ v1.0 AI-IRF™ v1.0 control scheme.
Domain 1: Mcp & A2A Protocol Security — Cp-3
ID Requirement Normati Validation Method ve
MCP- MCP endpoints SHALL require mutual TLS (mTLS) SHALL Monthly port scan + configuration audit; 1 or workload identity federation. No unauthenticated automated certificate validation endpoints permitted.
MCP- All MCP message traffic SHALL be inspected at SHALL SIEM rule testing weekly; red-team 2 semantic level for injection patterns, malicious skill semantic injection exercises payloads, or protocol tampering.
MCP- Unregistered MCP servers SHALL be automatically SHALL Automated quarantine workflow testing; 3 quarantined upon detection; notifications sent to quarantine latency monitoring orchestrator and platform owner within 5 minutes.
MCP- MCP server manifests SHALL be registered with SHALL Orchestrator manifest registry audit; 4 the agent orchestrator before endpoints go live; registration gate enforcement testing unregistered servers blocked at network layer.
A2A-1 Inter-agent authorization SHALL enforce least- SHALL Policy validation in CI/CD; runtime privilege action scopes. Policy-as-code permission audit logs enforcement mandatory.
A2A-2 All inter-agent messages SHALL be SHALL Tabletop exercise quarterly; automated cryptographically signed (ECDSA) and integrity- playbook testing verified before processing. Unsigned or tampered messages SHALL be rejected and logged with SIEM alert.
A2A-3 A2A communication SHALL enforce per-agent-pair SHALL Network flow analysis; segmentation rate limits and anomaly detection to prevent agent policy compliance scans loop amplification attacks. Circuit-breaker SHALL trigger on >3 anomalies per hour, freezing the amplifying agent and alerting SOC.
Domain 2: Shadow Ai & Continuous Visibility — Cp-1, Cp-5
ID Requirement Normati Validation Method
ODA3-2026-06-TCR-HAI-001 | Page 16 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
ve
SAI-1 Organizations SHALL deploy instance-aware SHALL Weekly coverage report; automated discovery across network edges, SaaS connectors, discovery latency monitoring endpoints, and browser environments.
SAI-2 DLP controls SHALL inspect all AI data egress points SHALL Monthly DLP policy testing; simulated for sensitive data exposure. data leakage drills
SAI-3 Shadow AI instances SHALL be automatically SHALL Automated workflow testing; classified into risk tiers (sanctioned, shadow, rogue) quarantine effectiveness metrics within 1 hour of discovery. Classification logged to CMDB with tier assignment, timestamp, and rationale. Unclassified instances default to rogue tier.
SAI-4 Rogue AI instances SHALL trigger automated SHALL CMDB tagging audit; classification quarantine and incident declaration within 15 minutes accuracy validation of classification. AI Security Lead SHALL be paged automatically. Incident declared at SEV-2 minimum via SOAR workflow.
Domain 3: Adaptive Machine-Speed Response — Cp-5
ID Requirement Normati Validation Method ve
MSR- Response frameworks SHALL integrate LLM-as- SHALL Detection latency SLA < 500ms; false 1 Judge (LLM-J) metrics for real-time behavioral positive rate monitoring validation with confidence scoring.
MSR- Playbooks SHALL support conditional branching SHALL Weekly playbook dry runs; purple- 2 based on live telemetry deltas with confidence- team branching logic tests thresholded automation.
MSR- Behavioral baselines SHALL trigger automated SHALL A/B testing with red team; 3 containment for high-confidence attacks (confidence > containment efficacy metrics 95%) without human delay.
MSR- HITL SHALL be required for actions with blast radius SHALL Approval audit trail review; HITL 4 > 10 users, financial impact > $10K, or safety-critical compliance monitoring system involvement.
MSR-5 MTTC (mean time to containment) for agentic threat SHALL MTTC measurement across simulated events SHALL be 2 seconds or less. agentic threat events (MTH-SEC-007)
Domain 4: Model Extraction & Distillation Defenses — Cp-4
ID Requirement Normati Validation Method ve
MEX- Behavioral distillation detection SHALL analyze query SHALL Detection rule testing with emulated 1 patterns for systematic extraction via embedding extraction campaigns
ODA3-2026-06-TCR-HAI-001 | Page 17 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
similarity tracking across sessions.
MEX- Dynamic rate limiting SHALL use per-user/session SHALL Rate limit effectiveness review; 2 quotas with semantic clustering to detect sustained extraction campaign simulation extraction patterns.
MEX- Cryptographic output perturbation SHALL be applied SHALL A/B testing detection rate; 3 for high-confidence suspected extraction attempts (> perturbation impact on legitimate use 85% similarity score across sessions). assessed
MEX- API key revocation workflow SHALL execute within 5 SHALL Incident simulation quarterly; 4 minutes of confirmed extraction detection. Legal hold revocation latency monitoring preservation SHALL be initiated in parallel.
Domain 5: Ai-Bom & Supply Chain Integrity — Cp-4
ID Requirement Normati Validation Method ve
BOM- Every production AI system SHALL have a SHALL Pre-deployment gate enforcement; 1 cryptographically signed manifest before deployment; signature validation audits unsigned artifacts blocked by CI/CD gates.
BOM- Training data and model weights SHALL be SHALL Integrity check on data load; hash 2 cryptographically hashed before ingestion; hashes mismatch alerting SHALL be recorded and verified at load time.
BOM- External data sources SHALL undergo source SHALL Quarterly vendor assessment; 3 authenticity checks including vendor attestation attestation validation testing before integration.
BOM- Incident playbooks SHALL include supply chain SHALL Tabletop exercise; vendor escalation 4 rollback and vendor notification SLA (≤ 24 hours from path testing incident declaration).
BOM- Runtime BOM validation SHALL occur on every model SHALL Deployment pipeline log showing BOM 5 load; mismatch between loaded model and registered validation gate executed (MTH-SEC- BOM blocks inference. 007)
Domain 6: Agentic Permission Architecture (Apa) — Cp-2
ID Requirement Normati Validation Method ve
APA-1 Pre-execution validation gates SHALL enforce policy SHALL Policy enforcement audit; pre- checks before any consequential action. No bypass execution bypass testing permitted.
APA-2 Agents SHALL operate under least-privilege, task- SHALL Token lifetime monitoring; permission scoped permissions with auto-expiration (≤ 15 scope violation alerts minutes from task completion).
APA-3 HITL SHALL be required for: data export > 1K SHALL HITL approval logs; dual-control
ODA3-2026-06-TCR-HAI-001 | Page 18 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
records, payment initiation, production delete, PII compliance monitoring access, safety override.
APA-4 All permission grants, denials, and overrides SHALL SHALL Root cause classification in post- be logged with immutable timestamps and mortems; triage accuracy metrics cryptographic signing. SIEM ingestion mandatory; retention minimum 3 years.
APA-5 Tool use SHALL require a pre-execution approval gate, SHALL Tool invocation gate configuration audit separate from the general APA-1 action validation gate, (MTH-SEC-007) specific to tool invocation.
Domain 7: Regulatory & Compliance Operations
ID Requirement Normati Validation Method ve
REG- Incident playbooks SHALL include a regulatory SHALL Playbook validation with legal 1 notification decision tree mapping blast radius, data counsel; deadline simulation testing type, and AI risk tier to jurisdiction-specific deadlines.
REG- Legal and Compliance SHALL be embedded as SHALL RACI adherence audit; triage timeline 2 Consulted/Accountable roles in initial triage within 1 review hour of incident declaration.
REG- Organizations SHALL maintain incident-to-regulation SHALL Quarterly review documentation; 3 mapping tables reviewed quarterly with compliance mapping accuracy validation team.
REG- Audit-ready documentation SHALL be preserved with SHALL Retention policy audit; evidence chain 4 cryptographic integrity for minimum 3 years (GDPR integrity verification baseline); 5 years for critical infrastructure (NIS2); 10 years for health AI (HIPAA/HITECH).
Domain 8: Physical Ai & Safety Integration — Cp-2, Cp-5
ID Requirement Normati Validation Method ve
PHY-1 Separate incident playbooks SHALL exist for SHALL Playbook library review; safety physical-harm scenarios with explicit escalation paths scenario coverage audit to safety teams.
PHY-2 Safety and cybersecurity teams SHALL operate in SHALL Exercise attendance logs; joint integrated incident command structures with joint command effectiveness metrics tabletop exercises quarterly.
PHY-3 Systems SHALL mandate fail-safe fallback modes SHALL Safety validation testing; fail-safe upon cyber anomaly detection or attestation failure. activation drills Human-safe-stop states are the default.
PHY-4 Hardware-rooted trust SHALL default to human SHALL Architecture review; attestation failure oversight or safe-stop states if cryptographic simulation testing
ODA3-2026-06-TCR-HAI-001 | Page 19 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
attestation fails. No autonomous action permitted post-attestation failure.
Domain 9: Model Lifecycle Security — Cp-4, Cp-5
ID Requirement Normati Validation Method ve
MLC- Every production model SHALL have a unique SHALL CI/CD gate enforcement; signature 1 immutable identifier and cryptographic signature; validation at inference time unsigned models blocked from deployment.
MLC- Automated rollback capability SHALL execute within SHALL Monthly recovery drills with 2 15 minutes of compromise detection for critical documented results; rollback latency services. Monthly drills required. monitoring
MLC- Recovery playbooks SHALL include rollback SHALL Post-recovery audit; validation gate 3 validation gates confirming integrity before traffic is compliance monitoring restored.
MLC- Model version changes SHALL be logged in SHALL Audit log review; change management 4 immutable audit trail with signer identity, timestamp, compliance validation and approval record.
Domain 10: Zero Trust Architecture For Ai (Ztai) — Cp-1, Cp-2, Cp-3
ID Requirement Normati Validation Method ve
ZTA-1 AI infrastructure SHALL adopt explicit zero-trust SHALL Architecture review; ZTAI compliance design with documented architecture reviewed at assessment least annually.
ZTA-2 Continuous verification SHALL require re- SHALL Session duration audit; re- authentication every 15 minutes or per high-risk authentication enforcement testing action; no persistent sessions permitted.
ZTA-3 Micro-segmentation SHALL isolate inference, vector SHALL Network flow analysis; segmentation storage, and orchestration layers with explicit allow- policy compliance scans lists enforced in policy-as-code.
ZTA-4 Runtime least-privilege enforcement SHALL include SHALL Policy decision point logs; permission per-request authorization for tool execution with full grant/deny audit trails audit trail.
Domain 11: Detection Reliability
Provenance Note
NEWLY AUTHORED. No ODA3-ECO addendum exists for this domain. The control IDs and SHALL statements (REL-1, REL-2, REL-3) were first introduced in ODA3-2026-06-MTH-SEC-007 (Statement of Applicability) without an accompanying normative specification. This specification is authored to close that gap and bring Domain 11 to the same documentation standard as the originally-specified domains.
ODA3-2026-06-TCR-HAI-001 | Page 20 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
ID Requirement Normati Validation Method ve
REL-1 Auto-containment SHALL require >=3 ensemble SHALL Detection architecture documentation signals, agreement >=0.7 showing >=3 independent signal sources
REL-2 Confidence scores SHALL decay 10% per SHALL Decay function configuration and rolling consecutive similar alert window parameters
REL-3 Circuit-breaker SHALL disable automation after 3 FP SHALL Circuit breaker configuration showing 3- within 1h FP/1-hour trip threshold
Domain 12: Agentic Threat Detection
Provenance Note
NEWLY AUTHORED. No ODA3-ECO addendum exists for this domain. The control IDs and SHALL statements (APT-1, APT-2, APT-3) were first introduced in ODA3-2026-06-MTH-SEC-007 without an accompanying normative specification. Note: APT-2's wording overlaps substantially with APA-1/APA-5 (pre-execution gates). This specification distinguishes APT-2 as the THREAT DETECTION layer that triggers the APA permission gates, rather than duplicating the gate mechanism itself — APA controls the permission architecture; APT detects when that architecture is being abused or attacked.
ID Requirement Normati Validation Method ve
APT-1 Prompt injection detection >=90% across all channels SHALL Injection detection test report showing >=90% detection rate across channel types
APT-2 Tool abuse prevention via pre-execution gate on every SHALL Tool abuse pattern library documentation tool call
APT-3 Memory poisoning detection with automated SHALL Memory write scanning configuration and quarantine <=60s pattern library
Domain 13: Severity Classification
Provenance Note
NEWLY AUTHORED. No ODA3-ECO addendum exists for this domain. SEV-CLS and SEV-RPT were first introduced in ODA3-2026-06-MTH-SEC-007 without an accompanying normative specification, despite TCR-HAI-001 containing extensive prose discussion of severity concepts (SEV-1 through SEV-4 levels referenced throughout the document) without ever formalising that discussion into an auditable control. This specification closes that gap and is structurally aligned with the existing UAIF severity_presentation_score model (UAIF TCR-STD-002 §4.7-4.8) for cross-framework consistency, per the precedent already established in AIIS v1.0 (ODA3-2026-06-TCR-HAI-003).
ID Requirement Normati Validation Method ve
SEV- Deterministic severity scoring algorithm implemented SHALL Severity scoring algorithm documentation CLS and versioned with version history
SEV- Reportability thresholds evaluated deterministically SHALL Reportability threshold table covering all RPT applicable jurisdictions and regulations
Domain 14: Content Safety
Provenance Note
CSS-1, CSS-3, CSS-5 fully specified in ODA3-ECO-011 (normative). CSS-2, CSS-4, CSS-6, CSS-7 EXTENDED FROM SUMMARY: ECO-011 provided only control name, tier, and regulatory mapping for these four; full tiered implementation
ODA3-2026-06-TCR-HAI-001 | Page 21 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
detail authored separately and available in the extended specification package.
ID Requirement Normati Validation Method ve
CSS-1 Harmful content detection pipeline SHALL achieve SHALL See ODA3-ECO-011 full specification >99.9% block rate for CSAM (zero-tolerance); alert and log all blocked outputs.
CSS-2 Maintain a sufficiently detailed summary of content SHALL Published training data summary meeting used to train the GPAI model, published per EU AI Act Art. 53(1)(c) template requirements Art. 53(1)(c) template requirements. Implement output filtering to detect verbatim or near-ver
CSS-3 AI-generated synthetic media SHALL carry machine- SHALL See ODA3-ECO-011 full specification readable provenance marker (C2PA recommended) and human-facing disclosure label.
CSS-4 Design review SHALL confirm the AI system does not SHALL Design review documentation confirming employ subliminal techniques (content presented absence of subliminal/exploitative below the threshold of conscious perception) or techniques techniques designed to exploit known vulnerabilities
CSS-5 Monthly statistical analysis of AI outputs across SHALL See ODA3-ECO-011 full specification protected demographic groups SHALL be conducted; cumulative_bias_index > 0.05 triggers Chronic Harm Feedback Loop.
CSS-6 Conduct a quarterly Demographic Impact Assessment SHALL Quarterly DIA reports showing (DIA) for all high-risk AI systems. The DIA SHALL demographic parity difference and evaluate: demographic parity difference (<0.10 equalised odds difference results threshold), equalised odds difference (<0.10 threshol
CSS-7 Tier 1 + documented vulnerable population impact SHALL Vulnerable population identification and assessment, conducted alongside CSS-6's DIA, use-case mapping documentation specifically evaluating outcomes for identified vulnerable groups rather than aggregate demographic catego
Domain 15: Federated Learning Security
ID Requirement Normati Validation Method ve
FL-1 Federated clients authenticated via mutual TLS with SHALL Client certificate registry; update client-specific certificates; unregistered/revoked clients acceptance/rejection logs (ODA3-ECO- rejected. 013)
FL-2 Byzantine-robust aggregation (FedAvg with clipping; SHALL Gradient norm distribution logs; anomaly Krum/Bulyan for high-threat); gradients >3 sigma from flag rate (ODA3-ECO-013) epoch mean flagged; clients with anomaly rate >5% rejected.
FL-3 Differential privacy (DP-SGD) applied; epsilon <=1 for SHALL DP configuration audit; privacy budget high-sensitivity data, epsilon <=8 maximum ceiling for consumption log (ODA3-ECO-013) lower-sensitivity data; epsilon=10 not recommended for production.
FL-4 Global model signed with ECDSA (or CRYSTALS- SHALL Signed model checkpoint registry; Dilithium per PQC-1) after each aggregation round; aggregation audit log (ODA3-ECO-013)
ODA3-2026-06-TCR-HAI-001 | Page 22 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
signed checkpoint stored in AI-BOM registry.
Domain 16: Model Merge Defense
ID Requirement Normati Validation Method ve
MMD- Pre-merge source model vetting: AI-BOM provenance, SHALL Pre-merge vetting checklist; source model 1 absence of known malicious fine-tuning datasets, AI-BOM records (ODA3-ECO-013) training data manifest completeness verified; incomplete provenance rejected.
MMD- Post-merge backdoor scan (Neural Cleanse or ABS); SHALL Backdoor scan results with tool version; 2 semantic consistency testing across 500+ prompt anomaly cluster analysis (ODA3-ECO-013) templates; embedding space anomaly analysis.
MMD- Model merge operations performed in isolated SHALL Merge environment isolation configuration; 3 compute environment with no internet access; all artifact hash verification log (ODA3-ECO- artifacts hash-verified entering and leaving. 013)
Domain 17: Quantization Security
ID Requirement Normati Validation Method ve
QBS-1 Pre-quantization behavioural baseline established on SHALL Baseline output corpus; signed baseline 1,000+ representative inputs; stored as signed artefact artefact (ODA3-ECO-013) in AI-BOM.
QBS-2 Post-quantization differential analysis against SHALL Differential analysis report; divergence rate baseline; divergence >5% flagged; divergence >10% by input category (ODA3-ECO-013) rejects model.
QBS-3 Only trusted, audited quantization toolchains used SHALL Toolchain hash verification log (ODA3- (ONNX Runtime, TensorRT, PyTorch quantization); ECO-013) toolchain integrity hash-verified; third-party pre- quantized models screened via QBS-1/QBS-2.
Domain 18: Hallucination Detection
Provenance Note
EXTENDED. HAL-4 and HAL-5 are fully specified in ODA3-ECO-014 but were omitted from prior framework scope- planning documents (Statement of Applicability listed only HAL-1/2/3). Both are restored here to bring the AI-IRF™ v1.0 control scheme into alignment with the source addendum.
ID Requirement Normati Validation Method ve
HAL-1 RAG factual grounding verification: all factual claims SHALL D2-CTL-04 alignment evidence (ODA3- grounded in retrieved source documents; citation ECO-014) extraction and source verification; ungrounded claims flagged for human review.
HAL-2 Model confidence scoring implemented; outputs below SHALL D5-CTL-03 alignment evidence (ODA3-
0.7 confidence for consequential decisions require ECO-014)
human review before action; uncertainty surfaced to end users.
HAL-3 For high-stakes outputs (medical, legal, financial, SHALL D2-CTL-06 alignment evidence (ODA3- safety-critical): parallel inference with second model or ECO-014)
ODA3-2026-06-TCR-HAI-001 | Page 23 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
rule-based verifier; inconsistencies >10% divergence flagged for human review.
HAL-4 Hallucination rate tracked via human correction SHALL UAIF trust_erosion_rate field evidence feedback loop; alert at >3% of evaluated outputs; (ODA3-ECO-014) escalate to AI-IRF corrective action at >5% (trust_erosion_rate threshold).
HAL-5 For regulated domains (medical diagnosis, legal SHALL D6-CTL-03 Model Card alignment analysis, financial advice): external fact-checking API evidence (ODA3-ECO-014) or knowledge graph verification integrated for domain- specific claims.
Domain 19: Post-Quantum Cryptography
Provenance Note
PQC-1 operationalises the phased migration schedule established in ODA3-ECO-015 (Alignment Note) across four existing controls (BOM-4, MCP-1, A2A-2, REG-4). This control does not mandate immediate PQC implementation beyond what ECO-015 itself specifies — it mandates the readiness assessment and adherence to the documented timeline (Q1
2027 / Q3 2027 / Q3 2028).
ID Requirement Normati Validation Method ve
PQC-1 PQC readiness assessment SHALL be completed SHALL PQC readiness assessment document; covering BOM-4, MCP-1, A2A-2, and REG-4 migration plan with dated milestones cryptographic use cases. Migration to CRYSTALS- (ODA3-ECO-015) Dilithium (BOM-4, A2A-2) at Tier 3 from Q1 2027; hybrid Kyber-1024 (MCP-1) from Q3 2027; hybrid ECDSA+Dilithium (REG-4, all tiers) from Q3 2027.
Telemetry Integration Requirement: AI-IRF™ v1.0 requires SIEM/SOAR/XDR integration for all control domains with structured event schemas. Telemetry retention SHALL support forensic reconstruction and regulatory audit (minimum 3 years; see REG-4 for sector-specific requirements).
ODA3-2026-06-TCR-HAI-001 | Page 24 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 8 — REGULATORY & COMPLIANCE OPERATIONS
8.1 Comprehensive Regulatory Mapping
Regulation Applicable AI Incident Notification Maximum AI-IRF™ v1.0 Controls Types Deadline Penalty
EU AI Act Art. 73 A serious incident meeting Immediate after Not an Article 73- REG-1, REG-2, PHY-2 Article 3(49), within Article causal-link specific tariff; 73 scope; malfunction, threshold; outer provider- safety event, or near-miss limits: 15 days obligation is not automatically generally, 2 infringements may reportable days for fall under Article specified cases, 99(4): up to €15M 10 days where or 3% worldwide death occurs annual turnover, subject to the Regulation, Member-State rules, and SME treatment
GDPR Art. 33–34 Personal data breach from 72 hours to €20M or 4% REG-3, BOM-2, SAI-2 AI inference, training data DPA + without global turnover exposure, embedding undue delay to exfiltration data subjects
NIS2 Directive Critical infrastructure AI 24h early €10M or 2% REG-4, ZTA-1, BOM-4 incident, supply chain warning; 72h turnover compromise affecting detailed report essential services
Colorado AI Act Consequential decision 30 days for $20,000 per REG-1 with impact systems with bias, security consumer violation assessment, APA-3 flaws affecting Colorado appeal rights; consumers documentation mandatory
CIRCIA (US) Critical infrastructure AI 24 hours to Variable; CISA REG-4, ZTA-1, PHY-3 compromise (covered CISA for may issue entity) significant subpoena for non- cyber incidents compliance (final rule pending — obligations active upon rule effectiveness)
HIPAA / HITECH PHI exposure via AI 60 days — Up to $2.19M per REG-1, REG-4, BOM-2, inference pipeline, training HHS and violation category SAI-2 data, RAG retrieval, or affected per year (Tier 4 agent action individuals; willful neglect) media notification if > 500 in state
ODA3-2026-06-TCR-HAI-001 | Page 25 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
FINRA / SEC AI-assisted transaction Prompt report Suspension, fines, REG-1, REG-2, APA-3, anomaly, unauthorized to relevant licence MSR-4 algorithmic action, AI SRO; Rule revocation, capability disclosure failure 4370 Business disgorgement Continuity requirements
ISO/IEC 42001 All AI incidents in certified Annex C Certification All controls; audit-ready systems; management incident withdrawal; documentation review required management reputational timelines impact
8.2 Retention Requirements by Sector
Sector / Regulation Minimum Retention Notes
General (GDPR baseline) 3 years minimum All AI incidents involving EU data subjects
Critical infrastructure (NIS2) 5 years Essential services and critical infrastructure operators
Health AI (HIPAA / HITECH) 10 years AI systems touching PHI or clinical decision support
Financial AI (FINRA / SEC) 6 years (Books and Trade records, AI decision logs, capability Records Rule 17a-4) disclosures
Criminal investigation Indefinite — legal hold All evidence preservation obligations supersede standard retention
8.3 Ethical Guardrails
Principle Requirement Normative Level
Proportional Response Automated containment SHALL NOT exceed the blast radius SHALL necessary to contain the identified threat. Disproportionate containment is a governance failure.
Human Accountability HITL decisions SHALL be attributed to specific individuals SHALL with cryptographic sign-off. No anonymous approvals permitted.
Non-Discrimination Incident classification SHALL NOT use protected SHALL characteristics (race, religion, gender, national origin, etc.) as classification factors.
Transparency Automated containment decisions SHALL be explainable: the SHALL triggering rule, confidence score, and evidence basis SHOULD be available for audit and appeal within 24 hours.
Beneficence Response actions SHALL prioritize minimizing harm to SHALL individuals over operational continuity when these goals conflict.
ODA3-2026-06-TCR-HAI-001 | Page 26 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 9 — NEXT-GENERATION PLAYBOOK FRAMEWORK
9.1 Adaptive Playbook Library — Q2 2026 Priority Incidents
Playbook Trigger Branch Logic HITL Escalation Path Required?
PB-Agent- Tool call outside High confidence Payment Service owner → IAM Privilege-Abuse permission scope; (>95%): auto-disable initiation, data team → Compliance anomalous agent, revoke tokens. export > 1K officer write/export pattern Medium: rate-limit + records, request review. Low: production log + baseline update delete, PII access
PB-MCP- Unauthenticated MCP Immediate: isolate All destructive Platform owner → Compromise request; malicious skill broker, revoke actions require Vendor security → SOC payload detected; credentials, notify two-person lead semantic anomaly in connected agents, approval A2A traffic forensic snapshot
PB-Model- Query similarity > 0.85 Dynamic throttling → API key Abuse desk → SOC → Extraction across sessions + output perturbation → revocation, Product owner → Legal sustained high volume session isolation → legal hold + embedding legal hold if pattern initiation convergence confirmed
PB-Poisoned- Retrieved content fails Auto-remove from Human review Data owner → Platform RAG provenance check; vector index; before team → Supplier embedding outlier + quarantine source; reindexing; security user flag; index invalidate cache source integrity mismatch validation required
PB-Shadow-AI- Unregistered inference Quarantine endpoint Approval App owner → DLP Discovery endpoint detected; (block or rate-limit); required to team → Compliance sensitive data egress notify administrator; allowlist; data via unsanctioned AI preserve evidence exposure assessment
PB-Physical- Combined cyber Emergency stop → Override Safety commander → Safety-Trigger anomaly + safety fail-safe mode → requires joint Operations → sensor alert; unsafe isolate control plane → safety- Regulator (if required) actuator command notify safety team engineering detected dual approval
9.2 Playbook Integration Requirements
All playbooks SHALL expose REST APIs or MCP endpoints for SOAR integration with standardized input/output schemas.
Automation Safeguard Requirement Normative
ODA3-2026-06-TCR-HAI-001 | Page 27 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
Evidence preservation Automated containment SHALL never bypass evidence SHALL capture; all actions logged with immutable timestamps before execution
AI recommendation AI-generated recommendations for containment SHALL be SHALL validation validated by LLM-J scoring before executing high-impact actions
Rollback signing Rollback procedures SHALL be cryptographically signed SHALL and tested monthly against production-equivalent environments
Playbook version control All playbooks SHALL be version-controlled with signed SHALL commits; unauthorized modifications blocked by CI/CD gates
ODA3-2026-06-TCR-HAI-001 | Page 28 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 10 — IMPLEMENTATION ROADMAP & MATURITY MODEL
10.1 Phased Adoption Roadmap
Phase Timeline Priority Key Activities Success Criteria Gaps
1: Critical 0–60 days G1, G2, Deploy continuous AI discovery. 100% AI instances discovered Foundations G6 Enforce mTLS for all MCP endpoints. < 24h. All MCP endpoints Implement pre-execution validation authenticated. Pre-execution gates. Register HITL approval authority. policy blocks validated. Phase Complete PREP-1 through PREP-7. 1 preparation controls complete.
2: Regulatory 60–120 G7, G3, Embed regulatory decision trees. Documented EU AI Act Readiness days G5 Deploy LLM-as-Judge detection. Sign operational-readiness posture manifests for top 20 production models. established against the Tabletop exercises with Legal applicable actor role, system embedded. category, current application timetable, and unresolved dependencies; this criterion does not assert legal compliance. Auto-containment latency < 500ms. Manifest signing rate 100% for critical models.
3: Advanced Q3–Q4 G4, G9, Implement behavioral distillation Extraction detection rate > Capabilities 2026 G10 detection. Achieve < 15-min automated 90%. Recovery drill passed rollback. Complete ZTAI architecture with < 15-min rollback. ZTAI documentation. Integrate physical AI architecture review passed. safety playbooks.
4: 2027 G8, Full cyber-safety integrated incident < 2-min safety escalation Autonomous advance command. Autonomous HITL exception verified in drill. Regulatory Security d handling with formal verification. Cross- audit with zero critical findings. automati organizational threat intelligence on sharing.
10.2 Capability Maturity Model
Level Name Key Capabilities MTTD MTTC Auto-Containment Target Target
Level Legacy Baseline Static playbooks; inventory- > 60 min > 4 hours < 10% 1 centric visibility; human-speed triage
Level Managed Shadow AI discovery; basic < 15 min < 60 min 40% 2 MCP authentication; pre- execution gates
ODA3-2026-06-TCR-HAI-001 | Page 29 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
Level Advanced LLM-J detection; automated < 2 min < 10 min > 80% 3 containment (< 500ms); signed manifests; regulatory DTs
Level Autonomous Predictive detection; < 30 sec < 2 min > 95% 4 autonomous HITL exception handling; cyber-safety convergence
10.3 KPI Dashboard
KPI Target (Level 3) Measurement Method Frequency
Mean Time to Detect (MTTD) < 2 minutes SIEM detection-to-alert time; LLM- Real-time dashboard J scoring latency
Mean Time to Contain < 10 minutes Playbook execution logs; Post-incident report (MTTC) containment action timestamps
Automated containment rate > 80% of incidents IR records; automation trigger vs. Monthly review HITL override ratio
False positive rate < 5% for auto- Post-incident review; analyst Quarterly audit containment validation of automated actions
Regulatory submission 100% within Compliance audit; notification Per-incident accuracy deadline receipt verification
Manifest coverage 100% production CI/CD gate logs; signature Weekly models validation reports
Shadow AI discovery latency < 24h from first Discovery tool reports; instance Daily activity registration timestamps
MCP endpoint authentication 100% mTLS Port scan + configuration audit; Monthly certificate validation
Rollback execution time < 15 min for critical Recovery drill logs; rollback Monthly drill services completion timestamps
HITL compliance rate 100% for high- Approval audit trail; dual-control Per-incident impact actions verification logs
ODA3-2026-06-TCR-HAI-001 | Page 30 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 11 — NOTABLY ABSENT — FRAMEWORK SCOPE LIMITATIONS
This section documents what AI-IRF™ v1.0 explicitly does not cover and why. Documenting scope limitations is as important as documenting scope inclusions. It prevents threat inflation, sets accurate expectations for practitioners, and identifies areas requiring complementary frameworks or future research.
Out-of-Scope Area Rationale Complementary Framework
AI system design security Pre-deployment design security requires a OWASP ASVS, NIST SSDF, ISO/IEC (Secure SDLC for AI) separate framework; incident response 27034 assumes production deployment
Algorithmic bias and Bias is a governance and design matter; ISO/IEC 42001, EU AI Act Art. 9, NIST fairness remediation only security-incident-causing bias (e.g., AI RMF GOV function discriminatory classification) is in scope
Federated learning attack Federated learning security lacks Research corpus; future AI-IRF™ response operationalized incident response revision standards; active research area
AI watermarking and Content provenance is a separate C2PA, EU AI Act Art. 50 (disclosure provenance for synthetic standards track (C2PA); not a security obligations) media incident response matter
Post-quantum PQC migration is a preparedness NIST SP 800-208, CISA PQC guidance cryptographic migration program, not an incident response domain; AI infrastructure PQC readiness addressed in companion research
AI model interpretability and Explainability is a design and regulatory EU AI Act Art. 13, NIST AI RMF explainability compliance requirement; AI-IRF™ v1.0 MANAGE requires explainability of containment decisions, not of model internals
Non-AI data breaches If AI is not a causal factor in the breach, NIST SP 800-61r3, GDPR Art. 33–34 where AI is incidental NIST SP 800-61r3 and GDPR breach response frameworks apply
Criminal investigation and Chain of custody for criminal proceedings ACPO Digital Evidence principles, digital forensics standards requires jurisdiction-specific forensic ISO/IEC 27042 standards beyond this framework's scope
ODA3-2026-06-TCR-HAI-001 | Page 31 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 12 — STANDARDS CROSSWALK
Note: MITRE ATLAS technique IDs below use AML.T format (ATLAS v2.1). Specific technique IDs should be validated against the current ATLAS matrix at attack.mitre.org/resources/atlas before operational deployment. [T3]
Control Domain NIST AI RMF ISO/IEC MITRE ATLAS OWASP LLM OWASP Agentic
1.0 42001 v2.1 Top 10 2026
MCP/A2A Security PR.AI-P3 9.3 (Third- AML.T0051 (LLM LLM07: AGA-05: party risk) Prompt Injection) Insecure Plugin Tool/Plugin Design Exploitation
Shadow AI Visibility ID.AI-P1 6.2 (Asset AML.T0000 (ML N/A AGA-09: Shadow management Reconnaissance) AI )
Machine-Speed RS.AI-P2 8.2 (Incident N/A (response, LLM06: AGA-06: Response response) not attack) Excessive Autonomous Agency Action Abuse
Model Extraction PR.AI-P5 8.4 (IP AML.T0005 LLM04: Model N/A (pre- Defense protection) (Create Proxy ML Denial of deployment Model) Service concern)
AI-BOM & Supply ID.AI-P3 6.4 (Supply AML.T0010 LLM09: AGA-08: Supply Chain chain (Backdoor ML Overreliance Chain Poisoning security) Model) (supply chain)
Agentic Permissions PR.AI-P2 8.3 (Access AML.T0040 (ML LLM06: AGA-01: Excessive management Attack Staging) Excessive Permissions ) Agency
Physical AI Safety GV.AI-P4 8.7 AML.T0043 (Craft N/A N/A (Health/safet Adversarial Data y integration) — physical)
Regulatory GV.AI-P1 5.3 N/A N/A N/A Operations (Legal/regula tory)
Model Lifecycle PR.AI-P4 8.1 (AI AML.T0020 LLM09 AGA-08 lifecycle (Poison Training management Data) )
Zero Trust (ZTAI) PR.AI-P1 8.3 (Access AML.T0016 LLM08: AGA-01, AGA-02 management (Obtain Excessive ) Capabilities) Agency (boundary)
ODA3-2026-06-TCR-HAI-001 | Page 32 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 13 — GAP RESOLUTION MATRIX
Gap Gap Root Cause in AI-IRF™ v1.0 Resolution Validation Method ID Description Existing Frameworks
G1 MCP & A2A Treated as MCP-1 through MCP-4, A2A-1 Red-team MCP/A2A protocol observable through A2A-3: mTLS, semantic compromise exercise; security blind telemetry, not inspection, peer authorization, broker denied-lateral-movement spot primary attack isolation, manifest registration testing surface
G2 Shadow AI & Inventory-centric SAI-1 through SAI-4: Continuous Discovery coverage KPI visibility gaps model assumes discovery, DLP at egress, automated reporting; unauthorized AI visibility rather quarantine, instance classification detection testing than mandating discovery
G3 Static vs. Human-speed MSR-1 through MSR-4: LLM-J Purple-team timing tests on adaptive bounded scoring, conditional branching, containment latency; FP response playbooks; static confidence-thresholded automation rate monitoring IOC matching; no machine-speed automation
G4 Model Threat MEX-1 through MEX-4: Behavioral Simulated distillation extraction & acknowledged but extraction analytics, dynamic rate campaign detection rate; distillation — no detection limiting, output perturbation, extraction containment not methodology or automated key revocation efficacy operationalized response workflow
G5 AI-BOM & Traditional SBOM BOM-1 through BOM-4: Signed Provenance audit drills; supply chain mindset; no manifest, hashed artifacts, supplier rollback reconstruction integrity cryptographic attestation, supply chain rollback SLA testing provenance for AI artifacts
G6 Agentic Assumes APA-1 through APA-4: Pre-execution Agent overreach simulation permission adversarial intent policy checks, task-scoped testing; policy-block architecture only; missing pre- permissions, auto-expiration, HITL evidence collection execution for high-impact validation gates
G7 Regulatory Regulation-aware REG-1 through REG-4: Jurisdictional Tabletop exercises with mapping not but no decision decision tree, embedded mapped deadlines; RACI operational logic, deadlines, legal/compliance roles, audit-ready adherence audits or embedded evidence packages compliance roles
G8 Physical AI & Entirely absent or PHY-1 through PHY-4: Joint cyber- Safety incident simulation safety-security explicitly excluded safety command, fail-safe fallback, drills; fail-safe activation excluded from all reviewed hardware-rooted trust testing frameworks
ODA3-2026-06-TCR-HAI-001 | Page 33 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
G9 Model lifecycle Treated as MLC-1 through MLC-4: Immutable Integrity-verification testing; as operational operational signed lifecycle, 15-min rollback SLA, rollback-time drills — not security process, not integrity verification gates control enforceable security control with SLAs
G10 Zero trust not Individual controls ZTA-1 through ZTA-4: Identity-first, Architecture review against systematized present but not continuous verification, micro- ZTAI principles; control for AI unified under segmentation, runtime least-privilege enforcement validation zero-trust paradigm
ODA3-2026-06-TCR-HAI-001 | Page 34 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 14 — RACI MATRIX
Activity CISO AI Sec SOC AI/ML Legal/ Safety Product Lead Analyst Eng Comp Eng Owner
Declare Incident A R R C C C I (PHY)
Execute Auto-Containment I C R R I R I (PHY)
HITL Approval (Critical) A R C C C R (PHY C override )
Forensic Investigation I R R R C C I (PHY)
Manifest Verification I A C R C I I
Regulatory Notification A C C I R C I (PHY)
Model Rollback Execution I C I R I I C
Post-Mortem & Remediation A R C R C C R
Severity Classification A R R C C C I (PHY)
HITL Authority Designation A R I I C C I (PREP-4)
Legend: R = Responsible | A = Accountable | C = Consulted | I = Informed | PHY = applies only to physical AI incidents
ODA3-2026-06-TCR-HAI-001 | Page 35 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
◯ ◯ ◯
Section 15 — GLOSSARY
Term Definition
A2A (Agent-to-Agent) Protocol for inter-agent communication, trust establishment, and orchestration. A primary attack surface in agentic systems for lateral movement and trust-boundary bypass.
AI-BOM / Manifest Cryptographically signed manifest documenting model lineage, training data sources, embeddings, dependencies, MCP endpoints, and provenance chain. Equivalent to SBOM for AI systems.
Agentic Permission Framework enforcing pre-execution validation, task-scoped least-privilege permissions, Architecture (APA) and auto-expiring tokens for autonomous AI agents. Addresses both adversarial and structural permission failures.
CASB Cloud Access Security Broker. Security enforcement layer for SaaS applications used in AI-IRF™ v1.0 for shadow AI detection across SaaS connectors.
CI/CD Continuous Integration / Continuous Deployment pipeline. In AI-IRF™ v1.0, CI/CD gates enforce manifest signing requirements and prevent unsigned AI artifacts from reaching production.
CIRCIA Cyber Incident Reporting for Critical Infrastructure Act (US). Requires covered entities to report significant cyber incidents to CISA within 24 hours.
CMDB Configuration Management Database. In AI-IRF™ v1.0, CMDB must reflect continuously discovered AI instances, not periodic static inventory.
Consequential Action Any agent action with significant potential impact: data export > 1K records, payment initiation, production delete, PII access, safety-relevant command. Requires HITL approval.
HITL (Human-in-the- Mandatory human approval workflow for high-impact automated actions. Requires dual- Loop) control sign-off and immutable audit trail. Cannot be bypassed by automated systems.
LLM-as-Judge (LLM-J) Fine-tuned language model used to classify prompt/response pairs, tool calls, or behavioral patterns as malicious or benign with confidence scoring. Enables machine- speed triage.
Machine-Speed Automated detection and containment operating at adversarial velocity (milliseconds to Response seconds). Defined in contrast to human-speed triage which is structurally inadequate for agentic attacks.
MCP (Model Context Protocol for LLM-agent tool calling, context exchange, and orchestration. Treated in AI- Protocol) IRF™ v1.0 as a primary security boundary requiring authentication and semantic inspection.
mTLS Mutual TLS — both client and server authenticate via certificates. Mandatory for all MCP endpoint traffic under AI-IRF™ v1.0 (MCP-1).
RAG (Retrieval- Architecture pattern combining LLM inference with real-time retrieval from external Augmented Generation) knowledge sources. Retrieval pipeline is an attack surface for data poisoning and provenance attacks.
ODA3-2026-06-TCR-HAI-001 | Page 36 | ODA3 Pvt Ltd ODA3 Institute | Technical Report | AI Incident Response Framework v1.0
Shadow AI Unmanaged or unsanctioned AI instances including personal deployments, SaaS AI upgrades, embedded AI features, or browser AI extensions operating outside organizational control.
SPIFFE/SPIRE Secure Production Identity Framework for Everyone / SPIRE Runtime Environment. Open standards for workload identity federation used in AI-IRF™ v1.0 to authenticate agents, tools, and MCP servers.
ZTAI (Zero Trust Application of zero-trust principles specifically to AI systems. Defined in AI-IRF™ v1.0 Architecture for AI) as: identity-first authentication for every AI component, per-request authorization, micro- segmentation of AI infrastructure layers, runtime least-privilege enforcement, and continuous verification.
ODA3-2026-06-TCR-HAI-001 | Page 37 | ODA3 Pvt Ltd