Skip to main content
Threatstealth
Login
// AI.GOVERNANCE

30 AI governance frameworks, one reference

From the EU AI Act and NIST AI RMF to ISO 42001, MITRE ATLAS, and the OWASP LLM Top 10 — the complete catalogue of AI governance, ethics, and security standards.

Reviewed by Threatstealth Security Architects·Aligned to SOC 2 · ISO 27001 · NIST CSF · PCI DSS V 4.0.1
// DEFINITION

What is AI compliance automation?

AI governance frameworks address the ethical, legal, and technical challenges posed by artificial intelligence systems — fairness, transparency, accountability, safety, and security. As AI moves into production at scale, these frameworks set the baseline expectations for responsible deployment. This reference catalogues 30 of the most influential AI frameworks worldwide, from binding regulation (EU AI Act, China CAC rules) to certifiable management standards (ISO/IEC 42001) and security knowledge bases (MITRE ATLAS, OWASP LLM Top 10).

// THE.PROBLEM

Why AI demands its own governance layer

  • Traditional AppSec frameworks miss AI-specific risks (prompt injection, model poisoning, training-data leakage)
  • The EU AI Act imposes binding obligations on high-risk AI from 2024–2026 with fines up to €35M or 7% of global turnover
  • Procurement and customer due-diligence questionnaires increasingly require ISO 42001, NIST AI RMF, or equivalent attestations
  • Generative AI introduces new classes of risk (hallucination, IP infringement, sensitive-info disclosure) that pre-2023 frameworks do not cover
// HOW.IT.WORKS

A four-step operational model

1

Inventory your AI systems

Identify every model, prompt, and AI-driven workflow your organisation builds, deploys, or buys — including embedded AI in third-party SaaS.

2

Classify against the EU AI Act risk tiers

Unacceptable / High / Limited / Minimal risk drives the obligations that apply. High-risk systems trigger conformity assessment and registration.

3

Adopt a management standard

ISO/IEC 42001 and the NIST AI RMF give you the management-system structure to govern AI lifecycle, risk, and accountability.

4

Layer AI security testing

OWASP LLM Top 10, MITRE ATLAS and OWASP ML Top 10 supply the threat-side reference for red-teaming, detection, and CI-time security checks.

30
AI frameworks tracked
€35M
Maximum EU AI Act fine
4
EU AI Act risk tiers
10
OWASP LLM Top 10 risk classes
// REFERENCE.01

Complete AI Governance Frameworks Reference (30)

Every major AI governance, ethics, and security framework — full name, region, governing body, year, and adoption type.

FrameworkFull NameRegionBodyYearType
NIST AI RMFAI Risk Management FrameworkUSANIST2023Voluntary
EU AI ActEuropean Union Artificial Intelligence ActEUEU Commission2024Mandatory
ISO/IEC 42001AI Management System StandardInternationalISO/IEC2023Voluntary/Certifiable
ISO/IEC 23894AI Risk ManagementInternationalISO/IEC2023Voluntary
ISO/IEC 22989AI Concepts and TerminologyInternationalISO/IEC2022Voluntary
ISO/IEC 24027Bias in AI SystemsInternationalISO/IEC2021Voluntary
ISO/IEC 24028AI Trustworthiness OverviewInternationalISO/IEC2020Voluntary
IEEE 7000Model Process for Addressing Ethical ConcernsInternationalIEEE2021Voluntary
IEEE 7001Transparency of Autonomous SystemsInternationalIEEE2021Voluntary
IEEE 7010Wellbeing Metrics for Autonomous SystemsInternationalIEEE2020Voluntary
OECD AI PrinciplesPrinciples on Artificial IntelligenceInternationalOECD2019Voluntary
UNESCO AI EthicsRecommendation on the Ethics of AIInternationalUNESCO2021Voluntary
Google PAIRPeople + AI Research GuidebookUSAGoogle2019Voluntary
Microsoft RAIResponsible AI StandardUSAMicrosoft2022Voluntary
Anthropic AUPAcceptable Use Policy & Constitutional AIUSAAnthropic2023Voluntary
DARPA XAIExplainable Artificial Intelligence ProgramUSADARPA2017Research
UK AI Safety FrameworkAI Safety Institute Evaluation FrameworkUKUK Gov2023Voluntary
Canada AIDAArtificial Intelligence and Data ActCanadaCanada GovPendingProposed
Singapore AI GovernanceModel AI Governance FrameworkSingaporeIMDA / PDPC2020Voluntary
China AI RegulationsInterim Measures for Generative AI ServicesChinaCAC2023Mandatory
NIST SP 1270Towards a Standard for Identifying and Managing Bias in AIUSANIST2022Voluntary
AI HLEG Ethics GuidelinesEthics Guidelines for Trustworthy AIEUEU Commission2019Voluntary
ALTAIAssessment List for Trustworthy AIEUEU Commission2020Voluntary
MITRE ATLASAdversarial Threat Landscape for AI SystemsUSAMITRE2021Voluntary
OWASP ML Top 10Machine Learning Security Top 10InternationalOWASP2023Voluntary
OWASP LLM Top 10Large Language Model Security Top 10InternationalOWASP2023Voluntary
ENISA AI SecurityArtificial Intelligence Cybersecurity ChallengesEUENISA2020Voluntary
WEF AI GovernanceAI Governance Alliance FrameworkInternationalWEF2023Voluntary
Partnership on AITenets and Framework for Responsible AIInternationalPAI2016Voluntary
Montreal DeclarationResponsible Development of AIInternationalMontreal2018Voluntary
30 entries
// REFERENCE.02

OWASP LLM Top 10 — quick reference

The acceptance bar for shipping production LLM endpoints. Threatstealth's LLM Security Scanner tests every endpoint against this catalogue.

IDRisk ClassSummary
LLM01Prompt InjectionDirect or indirect manipulation of model instructions to override system prompt or trigger unintended actions.
LLM02Insecure Output HandlingTreating model output as trusted — leading to XSS, SSRF, or RCE in downstream systems.
LLM03Training Data PoisoningAdversarial corruption of training corpora to bias model behaviour or insert backdoors.
LLM04Model Denial of ServiceCrafted inputs that cause excessive resource consumption or service degradation.
LLM05Supply Chain VulnerabilitiesCompromise of pretrained weights, datasets, plugins, or model registries.
LLM06Sensitive Information DisclosureUnintended leakage of secrets, PII, or proprietary data through model responses.
LLM07Insecure Plugin DesignOver-permissioned tool/plugin interfaces enabling escalation through model output.
LLM08Excessive AgencyGranting model-driven agents authority beyond what business logic actually requires.
LLM09OverrelianceTrusting model output without human review in safety-critical or high-impact workflows.
LLM10Model TheftExtraction of model weights or behaviour through query attacks or insider exfiltration.
10 entries
// WHY.IT.MATTERS

Outcomes for security teams

Regulation is here, not coming

The EU AI Act is law. China's CAC interim measures are enforced. Canada's AIDA, US executive orders, and UK AI safety guidance are advancing in parallel.

Customers will require attestations

Procurement teams already ask for ISO 42001 readiness, NIST AI RMF mapping, and OWASP LLM Top 10 test results — long before regulators do.

AI risk is unlike traditional IT risk

Probabilistic, opaque, and continuously-trained systems require governance models built for them — not retrofitted from ISO 27001.

// FAQ

Direct answers

Is the EU AI Act in force?+

Yes. It was adopted in 2024, with prohibitions on unacceptable-risk AI taking effect in early 2025 and the bulk of high-risk obligations applying from 2026. Maximum penalties reach €35M or 7% of global turnover.

Should I get certified to ISO/IEC 42001?+

ISO/IEC 42001 is the first international certifiable AI management system standard. Certification is currently voluntary but is rapidly becoming a procurement expectation, particularly in regulated industries and EU-facing markets.

How does the OWASP LLM Top 10 differ from MITRE ATLAS?+

OWASP LLM Top 10 is a developer-facing catalogue of security risks specific to LLM applications. MITRE ATLAS is a broader knowledge base of adversary tactics and techniques against AI systems — closer to ATT&CK in style and intended for red teams and detection engineering.

Do voluntary AI frameworks have any teeth?+

Yes — voluntary frameworks like NIST AI RMF and ISO 42001 are increasingly cited in customer contracts, procurement RFPs, and enterprise risk assessments. They also serve as the de-facto baseline of due care that regulators look to when interpreting new AI laws.

Closed · Expert Access

Ready to see it in your environment?

Request a private security demo from the Threatstealth team.