PAI-SF / 3 / PAI-SF-ATT-001

Secure Boot and Model Attestation

Objective

Verify the model/firmware executing at the edge is the authorized version.

Control / requirement

Secure boot with hardware root of trust; runtime attestation at configurable interval; defined safety response (not merely a log entry) on attestation failure.

Applicability

Physical AI systems where model or firmware compromise could lead to unsafe behavior.

Expected evidence

Secure boot architecture documentation; attestation success/failure logs; attestation-failure response test records. [T2]

Assurance expectation

Architecture evidence plus test evidence of the failure response, not merely presence of the attestation mechanism.

Dependencies

PAI-SF-ATT-003 (key custody) — attestation is only as trustworthy as its key protection.

Exclusions

May be proportionally implemented for systems with negligible physical risk from model compromise.

Maturity / conformance relevance

Expected at Operational and High-Assurance levels; Foundational expects at minimum boot-time integrity verification.

Ecosystem relationship

Extends GAISSF™ model integrity/supply chain controls; provides attestation-failure incident categories for UAIF™; defines attestation failure as an AI-IRF™ trigger event.

Domain

Domain 3. Edge Hardware and Model Attestation

Download full Control Catalogue ↓