30 AI governance frameworks, one reference
From the EU AI Act and NIST AI RMF to ISO 42001, MITRE ATLAS, and the OWASP LLM Top 10 — the complete catalogue of AI governance, ethics, and security standards.
What is AI compliance automation?
AI governance frameworks address the ethical, legal, and technical challenges posed by artificial intelligence systems — fairness, transparency, accountability, safety, and security. As AI moves into production at scale, these frameworks set the baseline expectations for responsible deployment. This reference catalogues 30 of the most influential AI frameworks worldwide, from binding regulation (EU AI Act, China CAC rules) to certifiable management standards (ISO/IEC 42001) and security knowledge bases (MITRE ATLAS, OWASP LLM Top 10).
Why AI demands its own governance layer
- Traditional AppSec frameworks miss AI-specific risks (prompt injection, model poisoning, training-data leakage)
- The EU AI Act imposes binding obligations on high-risk AI from 2024–2026 with fines up to €35M or 7% of global turnover
- Procurement and customer due-diligence questionnaires increasingly require ISO 42001, NIST AI RMF, or equivalent attestations
- Generative AI introduces new classes of risk (hallucination, IP infringement, sensitive-info disclosure) that pre-2023 frameworks do not cover
A four-step operational model
Inventory your AI systems
Identify every model, prompt, and AI-driven workflow your organisation builds, deploys, or buys — including embedded AI in third-party SaaS.
Classify against the EU AI Act risk tiers
Unacceptable / High / Limited / Minimal risk drives the obligations that apply. High-risk systems trigger conformity assessment and registration.
Adopt a management standard
ISO/IEC 42001 and the NIST AI RMF give you the management-system structure to govern AI lifecycle, risk, and accountability.
Layer AI security testing
OWASP LLM Top 10, MITRE ATLAS and OWASP ML Top 10 supply the threat-side reference for red-teaming, detection, and CI-time security checks.
Complete AI Governance Frameworks Reference (30)
Every major AI governance, ethics, and security framework — full name, region, governing body, year, and adoption type.
| Framework | Full Name | Region | Body | Year | Type |
|---|---|---|---|---|---|
| NIST AI RMF | AI Risk Management Framework | USA | NIST | 2023 | Voluntary |
| EU AI Act | European Union Artificial Intelligence Act | EU | EU Commission | 2024 | Mandatory |
| ISO/IEC 42001 | AI Management System Standard | International | ISO/IEC | 2023 | Voluntary/Certifiable |
| ISO/IEC 23894 | AI Risk Management | International | ISO/IEC | 2023 | Voluntary |
| ISO/IEC 22989 | AI Concepts and Terminology | International | ISO/IEC | 2022 | Voluntary |
| ISO/IEC 24027 | Bias in AI Systems | International | ISO/IEC | 2021 | Voluntary |
| ISO/IEC 24028 | AI Trustworthiness Overview | International | ISO/IEC | 2020 | Voluntary |
| IEEE 7000 | Model Process for Addressing Ethical Concerns | International | IEEE | 2021 | Voluntary |
| IEEE 7001 | Transparency of Autonomous Systems | International | IEEE | 2021 | Voluntary |
| IEEE 7010 | Wellbeing Metrics for Autonomous Systems | International | IEEE | 2020 | Voluntary |
| OECD AI Principles | Principles on Artificial Intelligence | International | OECD | 2019 | Voluntary |
| UNESCO AI Ethics | Recommendation on the Ethics of AI | International | UNESCO | 2021 | Voluntary |
| Google PAIR | People + AI Research Guidebook | USA | 2019 | Voluntary | |
| Microsoft RAI | Responsible AI Standard | USA | Microsoft | 2022 | Voluntary |
| Anthropic AUP | Acceptable Use Policy & Constitutional AI | USA | Anthropic | 2023 | Voluntary |
| DARPA XAI | Explainable Artificial Intelligence Program | USA | DARPA | 2017 | Research |
| UK AI Safety Framework | AI Safety Institute Evaluation Framework | UK | UK Gov | 2023 | Voluntary |
| Canada AIDA | Artificial Intelligence and Data Act | Canada | Canada Gov | Pending | Proposed |
| Singapore AI Governance | Model AI Governance Framework | Singapore | IMDA / PDPC | 2020 | Voluntary |
| China AI Regulations | Interim Measures for Generative AI Services | China | CAC | 2023 | Mandatory |
| NIST SP 1270 | Towards a Standard for Identifying and Managing Bias in AI | USA | NIST | 2022 | Voluntary |
| AI HLEG Ethics Guidelines | Ethics Guidelines for Trustworthy AI | EU | EU Commission | 2019 | Voluntary |
| ALTAI | Assessment List for Trustworthy AI | EU | EU Commission | 2020 | Voluntary |
| MITRE ATLAS | Adversarial Threat Landscape for AI Systems | USA | MITRE | 2021 | Voluntary |
| OWASP ML Top 10 | Machine Learning Security Top 10 | International | OWASP | 2023 | Voluntary |
| OWASP LLM Top 10 | Large Language Model Security Top 10 | International | OWASP | 2023 | Voluntary |
| ENISA AI Security | Artificial Intelligence Cybersecurity Challenges | EU | ENISA | 2020 | Voluntary |
| WEF AI Governance | AI Governance Alliance Framework | International | WEF | 2023 | Voluntary |
| Partnership on AI | Tenets and Framework for Responsible AI | International | PAI | 2016 | Voluntary |
| Montreal Declaration | Responsible Development of AI | International | Montreal | 2018 | Voluntary |
OWASP LLM Top 10 — quick reference
The acceptance bar for shipping production LLM endpoints. Threatstealth's LLM Security Scanner tests every endpoint against this catalogue.
| ID | Risk Class | Summary |
|---|---|---|
| LLM01 | Prompt Injection | Direct or indirect manipulation of model instructions to override system prompt or trigger unintended actions. |
| LLM02 | Insecure Output Handling | Treating model output as trusted — leading to XSS, SSRF, or RCE in downstream systems. |
| LLM03 | Training Data Poisoning | Adversarial corruption of training corpora to bias model behaviour or insert backdoors. |
| LLM04 | Model Denial of Service | Crafted inputs that cause excessive resource consumption or service degradation. |
| LLM05 | Supply Chain Vulnerabilities | Compromise of pretrained weights, datasets, plugins, or model registries. |
| LLM06 | Sensitive Information Disclosure | Unintended leakage of secrets, PII, or proprietary data through model responses. |
| LLM07 | Insecure Plugin Design | Over-permissioned tool/plugin interfaces enabling escalation through model output. |
| LLM08 | Excessive Agency | Granting model-driven agents authority beyond what business logic actually requires. |
| LLM09 | Overreliance | Trusting model output without human review in safety-critical or high-impact workflows. |
| LLM10 | Model Theft | Extraction of model weights or behaviour through query attacks or insider exfiltration. |
Outcomes for security teams
Regulation is here, not coming
The EU AI Act is law. China's CAC interim measures are enforced. Canada's AIDA, US executive orders, and UK AI safety guidance are advancing in parallel.
Customers will require attestations
Procurement teams already ask for ISO 42001 readiness, NIST AI RMF mapping, and OWASP LLM Top 10 test results — long before regulators do.
AI risk is unlike traditional IT risk
Probabilistic, opaque, and continuously-trained systems require governance models built for them — not retrofitted from ISO 27001.
Direct answers
Is the EU AI Act in force?+
Yes. It was adopted in 2024, with prohibitions on unacceptable-risk AI taking effect in early 2025 and the bulk of high-risk obligations applying from 2026. Maximum penalties reach €35M or 7% of global turnover.
Should I get certified to ISO/IEC 42001?+
ISO/IEC 42001 is the first international certifiable AI management system standard. Certification is currently voluntary but is rapidly becoming a procurement expectation, particularly in regulated industries and EU-facing markets.
How does the OWASP LLM Top 10 differ from MITRE ATLAS?+
OWASP LLM Top 10 is a developer-facing catalogue of security risks specific to LLM applications. MITRE ATLAS is a broader knowledge base of adversary tactics and techniques against AI systems — closer to ATT&CK in style and intended for red teams and detection engineering.
Do voluntary AI frameworks have any teeth?+
Yes — voluntary frameworks like NIST AI RMF and ISO 42001 are increasingly cited in customer contracts, procurement RFPs, and enterprise risk assessments. They also serve as the de-facto baseline of due care that regulators look to when interpreting new AI laws.
