GAISSF DOCUMENTATION

Executive Summary

Public GAISSF v1.0 publication reproduced as accessible HTML from the final source document.

GAISSF™ v1.0

Executive Summary

Global AI Security & Safety Framework

Document IDGAISSF-NOR-002
Version1.0
StatusFinal Publication v1.0
ClassificationInformative
Publication date1 July 2026
PublisherODA3 Institute

Authoritative control baseline: 59 controls across nine domains. Canonical Foundational scope: 52 controls. Additional physical-AI controls: 7.

Document Control

Document titleGAISSF™ v1.0 Executive Summary
Document IDGAISSF-NOR-002
Version1.0
StatusFinal Publication v1.0
ClassificationInformative
PublisherODA3 Institute
Legal entityODA3 Pvt Ltd
Authoritative sourceGAISSF-NOR-001
Control baseline59 controls across D1-D9
Foundational scope52 controls (D1-D8)
Additional controls7 conditional physical-AI controls (D9)
SupersedesEarlier 45-control generated draft; withdrawn
Publication date1 July 2026

Precedence Statement

This Executive Summary is informative. It does not establish, amend, replace or override any GAISSF requirement. GAISSF-NOR-001 is the authoritative normative source and prevails where inconsistency exists.

1. Executive Overview

GAISSF is an evidence-based AI security and safety framework comprising 59 controls across nine domains. Its Foundational profile consists of 52 canonical controls in D1-D8. The seven D9 physical-AI controls become additionally mandatory whenever an assessed system can influence or actuate the physical world. GAISSF provides a common structure for governance, technical implementation, evidence, assurance and controlled claims; it does not replace applicable law, sector-specific safety engineering or an issued certification scheme.

2. Business Rationale

AI risk is frequently divided across cybersecurity, model risk, data governance, privacy, safety, procurement, legal, compliance and internal audit. GAISSF provides common control identifiers, evidence expectations and assessment procedures so these functions can work from one auditable baseline.

3. Domain Architecture

DomainTitleControlsFoundational scope
D1MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS9Yes
D2RUNTIME SECURITY & ADVERSARIAL DEFENSE6Yes
D3AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY7Yes
D4SUPPLY CHAIN & THIRD-PARTY AI SECURITY7Yes
D5CONTENT SAFETY & OUTPUT INTEGRITY6Yes
D6GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT7Yes
D7HUMAN & SOCIETAL HARMS5Yes
D8REGULATORY ALIGNMENT & COMPLIANCE5Yes
D9PHYSICAL AI SAFETY7Conditional — mandatory where physical AI is in scope

4. What Adoption Requires

Executives must approve scope, ownership, resources, risk appetite, exception authority, residual-risk acceptance and assurance arrangements. Organizations must inventory AI systems, determine applicability for all 59 controls, implement the 52 canonical controls and every applicable D9 control, collect operating evidence, remediate findings and maintain continuing conformance after material change.

5. Conformance and Certification

TierScopeExecutive implication
Foundational52 canonical controls in D1-D8Minimum canonical organizational and technical baseline
Operational52 canonical controls plus all applicable D9 controls and operating-effectiveness evidenceAdds physical-AI controls whenever cyber-physical actuation is in scope
OptimizedSame applicable control scope plus continuous monitoring and sustained higher-assurance evidenceRequires continuous assurance and stronger evidence over time

Where an issued GAISSF certification scheme is in force, a certificate represents a scoped assessment against defined requirements and evidence. NOR-001 alone does not authorize certification, use of certification marks, or public claims of certification. No certificate guarantees security, safety, legal compliance or absence of harmful outcomes.

6. Evidence and Assurance

Policy documents alone are insufficient. Evidence should demonstrate design, implementation, operation, monitoring and corrective action. Executives should expect traceability from every applicable control to a responsible owner, evidence artifact, test result, exception or remediation record.

7. Executive Decisions

DecisionRequired outcome
Assessment boundaryApproved systems, entities, locations, services and dependencies
Conformance targetFoundational, Operational or Optimized
Control ownershipNamed accountable and operational owners
Risk authorityDefined exception and residual-risk approval levels
Certification intentApproved scope, timing, claims and communications
Continuing conformanceMonitoring, change triggers, surveillance and remediation governance

8. Benefits and Limitations

Potential benefits include clearer accountability, more consistent technical and governance controls, better audit readiness, stronger evidence discipline and improved coordination. Outcomes depend on scope quality, implementation competence, evidence integrity and sustained operation. GAISSF is not a substitute for law, specialist safety engineering, privacy assessment, sector standards or system-specific testing.

9. Notably Absent

GAISSF does not provide universal performance thresholds, universal risk-acceptance thresholds, automatic regulatory equivalence, guaranteed certification, regulator endorsement, or authorization to use certification marks. Detailed framework mappings require controlled crosswalk artifacts, and certification requires a separately issued scheme, assessment rules and claims policy.

Control Index

Control IDControl titleDomainFoundational scope
D1-CTL-01DATASET PROVENANCE & POISONING PREVENTIOND1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-02MODEL EXTRACTION RESISTANCED1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-03BEHAVIORAL DRIFT DETECTIOND1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-04FEDERATED LEARNING POISONING PREVENTIOND1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-05EMBEDDING SPACE ROBUSTNESSD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-06POST-QUANTUM MODEL SIGNING & CRYPTO HARDENINGD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-07LORA/ADAPTER INTEGRITY VERIFICATIOND1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-08MODEL MERGE ATTACK DETECTIOND1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-09QUANTIZATION BACKDOOR SCREENINGD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D2-CTL-01DIRECT PROMPT INJECTION PREVENTIOND2: RUNTIME SECURITY & ADVERSARIAL DEFENSEYes
D2-CTL-02INDIRECT PROMPT INJECTION PREVENTIOND2: RUNTIME SECURITY & ADVERSARIAL DEFENSEYes
D2-CTL-03JAILBREAK RESISTANCE TESTINGD2: RUNTIME SECURITY & ADVERSARIAL DEFENSEYes
D2-CTL-04MULTI-MODAL INJECTION DEFENSED2: RUNTIME SECURITY & ADVERSARIAL DEFENSEYes
D2-CTL-05FUNCTION CALL/TOOL CALL INJECTION PREVENTIOND2: RUNTIME SECURITY & ADVERSARIAL DEFENSEYes
D2-CTL-06CROSS-CONTEXT HIJACKING MITIGATIOND2: RUNTIME SECURITY & ADVERSARIAL DEFENSEYes
D3-CTL-01LEAST AGENCY ENFORCEMENTD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D3-CTL-02INTER-AGENT COMMUNICATION SECURITYD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D3-CTL-03AGENTIC PROMPT CHAINING DETECTIOND3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D3-CTL-04EMBODIED AI SAFETY CONTROLSD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D3-CTL-05MULTI-AGENT TRUST CHAIN ATTESTATIOND3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D3-CTL-06PERSISTENT MEMORY EXFILTRATION PREVENTIOND3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D3-CTL-07SECURE MEMORY LIFECYCLE MANAGEMENTD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D4-CTL-01AI BILL OF MATERIALS (AI BOM) MAINTENANCED4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D4-CTL-02MODEL FILE & ARTIFACT SCANNINGD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D4-CTL-03MODEL HUB & REGISTRY VETTINGD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D4-CTL-04MCP SERVER BEHAVIORAL MONITORINGD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D4-CTL-05THIRD-PARTY AI API SECURITY ASSESSMENTD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D4-CTL-06SHADOW AI DISCOVERY & GOVERNANCED4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D4-CTL-07AI SOFTWARE COMPOSITION ANALYSIS (SCA)D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D5-CTL-01HARMFUL CONTENT BLOCKINGD5: CONTENT SAFETY & OUTPUT INTEGRITYYes
D5-CTL-02PII LEAKAGE PREVENTIOND5: CONTENT SAFETY & OUTPUT INTEGRITYYes
D5-CTL-03COPYRIGHT DETECTIOND5: CONTENT SAFETY & OUTPUT INTEGRITYYes
D5-CTL-04AI WATERMARKING ROBUSTNESSD5: CONTENT SAFETY & OUTPUT INTEGRITYYes
D5-CTL-05PRIVACY-BY-DESIGN VERIFICATIOND5: CONTENT SAFETY & OUTPUT INTEGRITYYes
D5-CTL-06PRIVACY-PRESERVING ML VALIDATIOND5: CONTENT SAFETY & OUTPUT INTEGRITYYes
D6-CTL-01HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONSD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D6-CTL-02AUDIT TRAIL COMPLETENESSD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D6-CTL-03AI MODEL CARD COMPLETENESSD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D6-CTL-04AI INCIDENT RESPONSE READINESSD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D6-CTL-05MODEL DEPRECATION & DECOMMISSIONINGD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D6-CTL-06THIRD-PARTY AI VENDOR GOVERNANCED6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D6-CTL-07AI RESILIENCE & BUSINESS CONTINUITYD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D7-CTL-H01AI-GENERATED PHISHING SIMULATIOND7: HUMAN & SOCIETAL HARMSYes
D7-CTL-H02DEEPFAKE DETECTION TRAININGD7: HUMAN & SOCIETAL HARMSYes
D7-CTL-H03OUT-OF-BAND AUTHENTICATIOND7: HUMAN & SOCIETAL HARMSYes
D7-CTL-H04AI SOCIAL ENGINEERING IRD7: HUMAN & SOCIETAL HARMSYes
D7-CTL-H05AI-ENHANCED EXTERNAL ATTACK DEFENSED7: HUMAN & SOCIETAL HARMSYes
D8-CTL-01EU AI ACT RISK TIER MAPPINGD8: REGULATORY ALIGNMENT & COMPLIANCEYes
D8-CTL-02ISO 42001 GAP ANALYSISD8: REGULATORY ALIGNMENT & COMPLIANCEYes
D8-CTL-03GPAI TECHNICAL DOCUMENTATION VERIFICATIOND8: REGULATORY ALIGNMENT & COMPLIANCEYes
D8-CTL-04DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)D8: REGULATORY ALIGNMENT & COMPLIANCEYes
D8-CTL-05NIST SP 800-218A COMPLIANCE CHECKD8: REGULATORY ALIGNMENT & COMPLIANCEYes
D9-CTL-01PHYSICAL HARM BOUNDARY ENFORCEMENTD9: PHYSICAL AI SAFETYConditional — mandatory where physical AI is in scope
D9-CTL-02SAFE STATE AND GRACEFUL DEGRADATIOND9: PHYSICAL AI SAFETYConditional — mandatory where physical AI is in scope
D9-CTL-03HUMAN OVERRIDE AND EMERGENCY STOPD9: PHYSICAL AI SAFETYConditional — mandatory where physical AI is in scope
D9-CTL-04CYBER-PHYSICAL ATTACK DETECTIOND9: PHYSICAL AI SAFETYConditional — mandatory where physical AI is in scope
D9-CTL-05PHYSICAL ENVIRONMENT INTEGRITY MONITORINGD9: PHYSICAL AI SAFETYConditional — mandatory where physical AI is in scope
D9-CTL-06ACTUATOR COMMAND VERIFICATIOND9: PHYSICAL AI SAFETYConditional — mandatory where physical AI is in scope
D9-CTL-07PHYSICAL INCIDENT EVIDENCE PRESERVATIOND9: PHYSICAL AI SAFETYConditional — mandatory where physical AI is in scope

Annex A — Executive Source Traceability

Executive topicNormative source
59-control architectureGAISSF-NOR-001, Framework Architecture and Control Catalogue
52-control Foundational scopeGAISSF-NOR-001, Conformance and Annex A
Conditional D9 controlsGAISSF-NOR-001, D9, Statement of Applicability and Annex A
Evidence requirementsGAISSF-NOR-001, Evidence Requirements
Certification limitationsGAISSF-NOR-001, Conformance and Certification, Limitations, and issued certification scheme

Controlled Profile Reconciliation Notice

The Foundational profile comprises the 52 canonical controls in D1-D8. The seven D9 controls are additional mandatory controls whenever physical AI or cyber-physical actuation is within the assessed scope.

Any earlier wording that described the Foundational profile as spanning all nine domains, or treated D9 as universally mandatory or universally excluded, is superseded. D9 applicability must be determined and justified for every assessed scope.

Executive Decision Framework

Executives should treat GAISSF adoption as an enterprise risk and operating-model decision. The essential questions are whether the organization knows where AI is used, understands material consequences, has accountable owners, operates effective controls, can produce evidence and can respond when assumptions fail.

Executive questionRequired evidence
What is in scope?Approved AI inventory, scope statement and supplier map.
Who is accountable?Named executive, system and control owners.
What can go wrong?Risk, threat, impact and hazard assessments.
Are controls operating?Current control-health and assurance evidence.
What remains unresolved?Exceptions, findings, incidents and residual-risk decisions.
What is claimed externally?Approved conformance, certification and public-claim register, limited to claims permitted by issued instruments.

Board and Executive Oversight Agenda

  • Material changes in AI scope and risk exposure
  • Red or unknown control-health states
  • Significant incidents, near misses and harmful outcomes
  • Overdue corrective actions and expiring exceptions
  • Supplier and regulatory changes
  • Certification status and claim accuracy
  • Resources, competence and improvement priorities

Implementation Priorities by Horizon

HorizonPriority
First 30 daysSponsor, inventory, scope, high-risk containment and program charter.
Days 31-90Profile selection, baseline assessment, ownership, roadmap and evidence repository.
Months 4-6Critical remediation, technical validation and operating evidence.
Months 7-12Independent assurance, management review and certification-readiness decision; certification only under an issued scheme.
OngoingMonitoring, incident learning, supplier oversight and release migration.

Publication Completeness and Intended Use

This publication edition of GAISSF-NOR-002 is designed to stand on its own as executive interpretation and decision support. It summarizes purpose, scope, governance, adoption decisions, evidence expectations, limitations and implementation priorities, but GAISSF-NOR-001 remains the authoritative normative source.

Completeness does not mean that the document replaces the normative control statements, applicable law, sector-specific engineering, organizational procedures or professional judgement. Cross-referenced GAISSF documents remain part of the controlled document system.

Completeness dimensionTreatment in this edition
Normative alignmentReconciled to the authoritative 59-control baseline and controlled profile structure.
Operational usabilityIncludes roles, workflows, gates, evidence, metrics, escalation and examples where relevant.
TraceabilityIdentifies dependencies and preserves the distinction between requirements, guidance and examples.
LimitationsStates what the document does not establish or guarantee.
MaintenanceIncludes review triggers, change control and publication status.