| EU AI Act | EU regulation classifying AI systems by risk levels (minimal, limited, high, unacceptable) with corresponding obligations | Operationalizes the EU AI Act by aligning with its requirements. Certification against AIUC-1 is a strong step towards compliance with the EU AI Act as it:
Enables alignment towards minimal and limited risk systems Enables alignment towards high risk systems only if specific control activities are met (AIUC can help guide AI companies through this process) Provides documentation for internal conformity assessments for high risk systems as required in Annex VI EU AI Act crosswalk by article -> |
| NIST AI RMF | US government framework for managing AI risks throughout the AI lifecycle with four core functions: Govern, Map, Measure, Manage | Operationalizes the NIST AI RMF. Certification against AIUC-1:
Translates NIST’s high-level actions into specific, auditable controls Provides concrete implementation guidance for key areas such as harmful output prevention, third-party testing and risk management practices NIST AI RMF crosswalk by function -> |
| ISO 42001 | International standard for AI management systems (AIMS) covering responsible AI development and deployment | Aligns with ISO 42001. Certification against AIUC-1:
Incorporates the majority of controls from ISO 42001 Translates ISO’s management system approach into concrete, auditable requirements Extends ISO 42001 with third-party testing requirements of, e.g., hallucinations and jailbreak attempts Addresses additional key concerns such as AI failure plans and AI-specific system security ISO 42001 crosswalk by clause -> |
| MITRE ATLAS | Knowledge base of adversarial tactics, techniques and mitigation strategies for machine learning systems, similar to MITRE ATT&CK for cybersecurity | Integrates MITRE ATLAS, which is a technical contributor to AIUC-1. Certification against AIUC-1:
Incorporates ATLAS mitigation strategies in requirements and controls Strengthens robustness against the adversarial tactics and techniques identified in ATLAS Goes beyond ATLAS’s focus on security alone MITRE ATLAS crosswalk by mitigation strategy -> |
| OWASP Top 10 for LLM Applications | Curated list of the most critical security threats to LLM and generative AI systems | Integrates OWASP’s Top 10 for LLM Applications. Certification against AIUC-1:
Addresses Top 10 threats in requirements and controls Strengthens robustness against the threats identified with concrete requirements and controls Goes beyond OWASP’s focus on security alone OWASP Top 10 crosswalk by threat -> |
| OWASP AIVSS | Scoring system for quantifying how agentic capabilities amplify security risks, producing numerical scores (0-10) that combine technical vulnerability severity with agent-specific factors | Integrates the OWASP AIVSS, which is a technical contributor to AIUC-1. Certification against AIUC-1:
Covers all agent risks identified in AIVSS Enables organizations to mitigate risks quantified in OWASP AIVSS Incorporates AIVSS agent risk amplification factors in standard requirements OWASP AIVSS crosswalk by risk -> |
| OWASP Top 10 for Agentic Applications | Curated list of the most critical security threats to autonomous AI agent systems | Integrates OWASP’s Top 10 for Agentic Applications. Certification against AIUC-1:
Addresses Top 10 agentic threats in requirements and controls Strengthens robustness against the threats identified with concrete requirements and controls Goes beyond OWASP’s focus on agentic risk alone OWASP Top 10 for Agentic Applications crosswalk by threat -> |
| IBM AI Risk Atlas | Comprehensive taxonomy of risks associated with ML models, GenAI, and AI Agents from IBM Research | Integrates IBM Research’s AI Risk Atlas, where IBM Research is a technical contributor to AIUC-1. Certification against AIUC-1:
Maps AI Risk Atlas risks to concrete requirements and controls Strengthens robustness against risks with concrete requirements and controls Goes beyond AI Risk Atlas’s risk identification alone IBM AI Risk Atlas crosswalk by risk -> |
| Cisco AI Security & Safety Framework | Comprehensive AI threat landscape taxonomy identifying 19 attacker objectives with 150+ subtechniques | Integrates Cisco’s AI Security Framework, where Cisco is a technical contributor to AIUC-1. Certification against AIUC-1:
Maps Cisco’s AI threat taxonomy to concrete requirements and controls Strengthens robustness against the attacker objectives and subtechniques identified by Cisco Goes beyond threat identification to provide actionable, auditable requirements Cisco AI Security Framework crosswalk by threats -> |
| CSA AI Controls Matrix | Cloud Security Alliance’s AI Controls Matrix providing security controls framework specifically designed for AI/ML systems | Certification against AIUC-1:
Addresses key controls for AI vendors from the AICM such as adversarial robustness, system transparency, and documentation of criteria for cloud and on-prem processing Enables a compliance burden significantly lower than CSA’s AICM due to its targeted focus on top AI enterprise concerns Avoids duplicating controls in areas where CSA is industry-leading, such as data center infrastructure, physical server security, and other domains outside of the AIUC-1 scope CSA AICM crosswalk by control -> |
| Regional U.S. regulation | e.g. NYC Local Law 144, California TFAIA, Colorado AI Act (SB 24-205) | Simplifies alignment with regional U.S. regulation. Certification against AIUC-1:
Addresses top concerns of emerging regional U.S. regulations such as the Colorado AI Act (SB 24-205) and NYC Local Law 144 Integrates controls for compliance obligations such as human-in-the-loop, appropriate data handling, and labelling AI clearly Helps organizations proactively prepare for obligations from emerging AI legislation before entering into force NYC Local Law 144 crosswalk by section -> Colorado AI Act crosswalk by section -> California TFAIA crosswalk by section -> |
| Sector-specific regulation | e.g. HIPAA, Fair Credit Reporting Act, Fair Housing Act, FTC guidance on AI & algorithms | Simplifies alignment with AI requirements in sector-specific regulation. Certification against AIUC-1:
Prepares organizations to comply with, e.g., FTC guidance on AI & algorithms Addresses top concerns in sector-specific regulations such as discrimination and bias, human-in-the-loop, monitoring and logging, third-party interactions, and data handling in base requirements Offers AI companies optional add-on requirements for relevant use cases, e.g., for financial transactions and PII handling |
| OECD AI Principles | First inter-governmental AI standard (2019, updated 2024) with five principles for trustworthy AI adopted by 47+ countries | Operationalizes OECD’s AI Principles. Certification against AIUC-1:
Translates OECD’s five principles into concrete, auditable requirements Addresses additional key areas such as third-party testing, AI failure plans, and adversarial resilience |