UAIF Executive Brief
Decision-level introduction to UAIF, its operating value, architecture, adoption profiles, limitations and licensing boundary.
Downloads and formats
No approved PDF edition was supplied with this build. A PDF link will be added only after publication approval.
Document status and notice
Document: ODA3-2026-06-EXB-STD-001 Status: FINAL — v1.0 PUBLICATION CANDIDATE Date: June 2026 Classification: PUBLIC Published By: ODA3 Institute (ODA3 Pvt Ltd) Audience: CISOs | AI Governance Leads | Compliance Officers | Board Members | Risk Committees
Methodology Note
This Executive Brief summarises UAIF v1.0 normative artefacts including TCR-STD-002, TCR-STD-003, the normative JSON Schema, and the official reference implementation. Financial estimates use stated assumptions and confidence ranges and are not derived from proprietary telemetry. Refer to the Technical Specification for normative behaviour, field definitions, and scoring details.
1. The Problem
Organisations deploying AI systems face fragmented reporting obligations and the absence of a shared machine-readable incident language.
| Regulation / Standard | Requires | Leaves Undefined |
|---|---|---|
| EU AI Act Article 73 | Serious-incident notification for high-risk AI | Severity thresholds, schema, reporting format |
| NIST AI RMF 1.0 | GOVERN and RESPOND functions | Operational incident structure |
| ISO/IEC 42001:2023 | AI incident record keeping | Cross-organisation comparability |
| DORA | ICT incident reporting | AI-specific taxonomy |
| NIS2 | Significant incident reporting | AI incident criteria |
2. What UAIF Delivers
| Capability | Business Value |
|---|---|
| Structured severity scoring | Consistent triage and board-reportable metrics |
| Regulatory trigger routing | Technical routing assistance for EU AI Act Article 73 serious-incident reporting. UAIF regulatory_trigger is a technical routing flag only; legal counsel determines definitive obligations. |
| Causal separation chain | Improved post-incident analysis and liability documentation |
| Generative and agentic classification | Coverage for RAG leakage, prompt injection and agent escalation |
| Reference implementation (oda3-uaif) | Immediate deployability and interoperability |
3. Architecture Overview
Architectural note: prior L7 AI Control Plane Extensions were merged into L5 in UAIF v1.0 for implementation simplicity.
| Layer | Name | Governance Relevance |
|---|---|---|
| L0 | Incident Identity & Workflow | Audit trail, deduplication, workflow state |
| L1 | Causal Separation Chain | Root cause isolation |
| L2 | Severity Scoring | Board-reportable severity tiers |
| L3 | Acute vs Chronic Harm | Long-term systemic risk |
| L4 | Incident vs Vulnerability | Separate exposure from realised incidents |
| L5 | Generative, Agentic & Control Plane | Prompt injection, RAG, MCP, OAuth, agent escalation |
| L6 | Regulatory & Cross-Sector Metadata | Jurisdictional routing, regulatory obligations mapping, sector classification |
Adoption Profiles
| Profile | Primary Use Case | Complexity |
|---|---|---|
| Core | Rapid deployment | Low |
| Enterprise | Governance maturity | Medium |
| Regulatory | Formal reporting obligations | High |
| SOC/SIEM | Security operations integration | Medium |
| AI Security Extension | Generative and agentic AI security | Medium |
4. Severity Scoring — Governance Implications
| Output | Range | Governance Use |
|---|---|---|
| Severity Analytical Score | 0.0-10.0 | Comparative analytics and prioritisation |
| Severity Presentation Score | 0.0-10.0 | Operational triage and regulatory proxy routing |
| Severity Level | 1-5 | Escalation and board thresholds |
| Regulatory Trigger | Boolean + confidence band | Technical routing assistance only; not a legal determination |
| Severity Rationale | JSON audit trail | Evidence and assurance documentation |
5. Regulatory Alignment
UAIF provides technical routing and interoperability support across major governance and regulatory frameworks. Legal counsel remains responsible for definitive reporting determinations.
6. Licensing and Commercial Terms
| Component | Licence | Notes |
|---|---|---|
| Core Specification | GEL v1.0 (Non-Commercial) | Commercial use requires separate written licence (GEL v1.0 §17). |
| Reference Implementation (oda3-uaif) | GEL v1.0 (Non-Commercial) | Commercial embedding requires separate written licence (GEL v1.0 §17). |
| UAIF-Compatible Mark | Authorised by ODA3 Institute | Use requires written authorisation (GEL v1.0 §9.3). |
| UAIF Certified Mark | ODA3 exclusive authority | Formal certification under GEL v1.0 §10.5. |
Mark Distinction
| Mark | Meaning | Typical Use |
|---|---|---|
| UAIF-Compatible | Authorised conformance claim | Internal deployment/vendor assurance |
| UAIF Certified | Formal ODA3 third-party certification | Regulated procurement and assurance |
7. Notably Absent
No legal determination of EU AI Act Article 73, GDPR, NIS2, DORA, or sectoral obligations.
No certification authority or right to claim UAIF Certified status from framework use alone.
No empirical claim that default harm weights are sector validated.
No operational SIEM/GRC integration warranty before platform testing.
No pre-incident AI safety certification capability.
8. Decision Guide for Leadership
General Counsel: review regulatory trigger confidence bands and establish legal review procedures for LOW-confidence outputs. UAIF regulatory triggers are technical routing assistance only.
9. Contact and Resources
ODA3 Institute: https://oda3.org UAIF resources: https://docs.oda3.org/uaif General enquiries: CONTACT_AT_ODA3_DOT_ORG
Licensed under GEL v1.0 | © 2026 ODA3 Pvt Ltd | Published by ODA3 Institute
Web edition notice
This HTML edition is provided for discovery, accessibility and search. Preserve the document identifier, version, publication status, limitations and GEL terms when citing or reusing it. The downloadable source remains available for recordkeeping.