Compliance ≠ security. A framework tells you what to think about; it does not make your prompt-injection defenses work. Treat the list below as a checklist for organizing your work — not a substitute for it.
At a glance · 14 frameworks

Side-by-side comparison

Type column uses colour: green = certifiable, amber = voluntary / influential guidance, red = binding with enforcement teeth.

14 AI security frameworks & standards — jurisdiction, type, scope, and what each one is actually for.
Framework Year(s) Jurisdiction Type Scope Key value
OWASP LLM Top 10
Top 10 for LLM Apps
2023, rev. 2025 Global Voluntary LLM apps Top 10 LLM risks
NIST AI RMF 1.0
+ AI 600-1
2023, 2024 US Voluntary AI lifecycle / GenAI Govern · Map · Measure · Manage
ISO/IEC 42001
AIMS
2023 ISO (Global) Certifiable AI management system Certifiable AIM system
ISO/IEC 23894 2023 ISO (Global) Voluntary AI risk management ISO 31000 risk guidelines for AI
EU AI Act 2024 / phased EU Binding All AI in EU market Risk-based regulation
CoE AI Convention 2024 Global (treaty) Voluntary AI & human rights First int'l AI treaty
UK AISI
AI Security Institute
2023, relabel 2025 UK Voluntary Frontier model eval Pre-deployment model evaluation
US AISI
under NIST
2023 US Voluntary Frontier model eval US federal safety institute
Bletchley Decl. 2023 Global (28 states) Voluntary Frontier AI safety First int'l AI safety declaration
Anthropic RSP 2023, rev. 2024 Vendor (US) Vendor policy Anthropic models Capability-tied ASL commitments
OpenAI Preparedness 2023 Vendor (US) Vendor policy OpenAI models Risk-category evals before release
Google SAIF 2023 Vendor (US) Vendor policy Google AI products Six-element security framework
OECD AI Principles 2019, rev. 2024 Global Voluntary All AI policy First intergov't AI principles
China GenAI Measures 2023 China Binding Public GenAI services Mandatory GenAI service rules
OWASP & NIST · community and federal guidance

OWASP & NIST

Two voluntary frameworks that together define how most engineering teams talk about LLM and AI risk.

OWASP · 2025

OWASP Top 10 for LLM Applications

Voluntary Jurisdiction: Global Scope: LLM apps

The community-maintained list of the ten most critical risks for applications built on large language models, published by the OWASP Foundation and revised in November 2025. The 2025 edition was reorganized around the themes of impact — separating prompt-injection vectors from sensitive-information disclosure and supply-chain / model handling. It is the de facto reference that every LLM security document maps its findings back to.

LLM01 prompt injection LLM02 sensitive info disclosure LLM03 supply chain LLM04 data & model poisoning LLM05 improper output handling LLM06 excessive agency LLM07 system prompt leakage LLM08 vector & embedding weaknesses LLM09 misinformation LLM10 unbounded consumption
NIST · 2023 / 2024

NIST AI RMF 1.0 + AI 600-1 GenAI Profile

Voluntary Jurisdiction: US Scope: AI lifecycle / GenAI

Released January 2023 by NIST, the AI Risk Management Framework organises AI risk work into four functions — Govern, Map, Measure, Manage — meant to be embedded across an organisation, not run as a one-off audit. On July 29, 2024 NIST published the Generative AI Profile (AI 600-1), which translates the four functions into roughly 200 concrete risk actions grouped under twelve characteristic risk categories specific to generative AI systems.

Govern Map Measure Manage 12 GenAI risk categories ~200 risk actions
ISO · the certifiable baseline

ISO & IEC standards

Where NIST is voluntary guidance, ISO publishes conformance standards you can actually be audited and certified against.

ISO/IEC · Dec 2023

ISO/IEC 42001:2023 — AI Management System

Certifiable Jurisdiction: Global (ISO) Scope: AI management system

Published December 2023 and maintained by ISO/IEC JTC1/SC42, ISO/IEC 42001 is the first international, certifiable standard for an AI management system (AIMS) — the "ISO 27001 for AI". It defines requirements for establishing, implementing, maintaining and continually improving an organisation-wide approach to governing AI, and can be audited and certified by accredited bodies against a fixed conformance bar.

AIMS requirements PDCA cycle Annex A controls 3rd-party certifiable JTC1/SC42
ISO/IEC · Feb 2023

ISO/IEC 23894:2023 — AI risk management

Voluntary Jurisdiction: Global (ISO) Scope: AI risk management

Published February 2023, ISO/IEC 23894 provides risk-management guidelines for AI systems, building on the generic ISO 31000 risk-management process and adapting it to AI-specific risks across the system life cycle. It is the closest ISO companion to NIST AI RMF — both describe a structured risk process, but 23894 plugs into the broader ISO management-system ecosystem and 42001's AIMS in particular.

ISO 31000-aligned risk identification risk assessment risk treatment lifecycle
EU · binding law

European regulation & treaty

The EU regime is the only one in this guide with multi-million-euro enforcement teeth — and now an international treaty sits alongside it.

EU · in force 2024 / phased

Regulation (EU) 2024/1689 — EU AI Act

Binding Jurisdiction: EU Scope: All AI placed on EU market

Adopted June 13, 2024 and entered into force August 1, 2024, the AI Act is the world's first comprehensive AI law. It uses a risk-based tier: prohibited practices (banned from Feb 2025), general-purpose AI (GPAI) obligations, high-risk rules, and limited-risk transparency duties. Note carefully — GPAI obligations take effect August 2, 2025: GPAI model providers must publish a sufficiently detailed summary of training-data content, prepare technical documentation, and provide downstream-system documentation. High-risk obligations phase in across 2026-27.

Enforcement is significant. Fines can reach €35 million or 7% of worldwide annual turnover for prohibited-practice violations, with lower tiers for GPAI / high-risk / incorrect-information breaches. National market-surveillance authorities and the new AI Office handle enforcement.

prohibited practices (Feb 2025) GPAI obligations (Aug 2025) high-risk (2026-27) training-content summary AI Office fines up to €35M / 7%
Council of Europe · Sept 2024

Framework Convention on Artificial Intelligence

Voluntary treaty Jurisdiction: Global (treaty) Scope: AI & human rights

Opened for signature on September 5, 2024 by the Council of Europe, this is the first binding international treaty on AI — though it is binding only on the states that ratify it, not directly on companies. It aligns AI lifecycle activity with human rights, democracy and the rule of law. Initial signatories included the US, UK, EU and several Council of Europe member states.

human rights democracy rule of law risk & impact assessments first int'l AI treaty
AI Safety Institutes · government evaluation bodies

AI Safety Institutes

National bodies evaluating frontier models before deployment — and the international declarations that brought them into being.

UK · Nov 2023

UK AI Security Institute (AISI)

Voluntary Jurisdiction: UK Scope: Frontier model eval

Announced November 1-2, 2023 at the Bletchley Park AI Safety Summit, the UK AISI is a government body that evaluates frontier models pre-deployment. In February 2025 it was renamed from "AI Safety Institute" to "AI Security Institute" to sharpen its focus on security misuse — especially chemical, biological, and cyber misuse — rather than broader societal risks.

pre-deployment eval CBRN misuse cyber misuse relabeled Feb 2025
US / NIST · Oct 2023

US AI Safety Institute (US AISI)

Voluntary Jurisdiction: US Scope: Frontier model eval

Established under NIST following Executive Order 14110 of October 30, 2023, US AISI released the GenAI Profile (AI 600-1) in July 2024 and conducts voluntary pre-deployment safety testing of frontier models. Its status under subsequent administrations is fluid — established under EO 14110, it has been the subject of sunset / reorganisation considerations during the 2025 change in administration.

EO 14110 origin GenAI Profile (Jul 2024) voluntary eval status fluid 2025+
28 countries · Nov 2023

Bletchley Declaration on AI Safety

Voluntary declaration Jurisdiction: Global (28 states) Scope: Frontier AI safety

Signed November 1-2, 2023 at the AI Safety Summit hosted at Bletchley Park, the Declaration is the first international AI safety declaration. Twenty-eight countries — including the US, China, the EU and the UK — committed to cooperate on identifying frontier-AI safety risks and to support a shared research and evaluation agenda. It is the political foundation underneath both the UK and US AISI work.

28 signatories US + China + EU + UK frontier risks summit series
Vendor frameworks · self-binding commitments

Vendor frameworks

Public, voluntary policies published by the frontier labs themselves — important context, but enforced by the vendors' own discretion.

Anthropic · Sept 2023, rev. 2024

Responsible Scaling Policy (RSP)

Vendor policy Jurisdiction: Vendor (US) Scope: Anthropic models

First version published September 2023 and updated through 2024, the RSP ties model capabilities — measured on an AI Safety Level (ASL) scale running ASL-1 through ASL-5 — to required security and safety commitments that must be met before a model at that level is deployed. Current Claude models operate at ASL-2. ASL-3 commitments are required when a model approaches meaningfully elevated risk of enabling banned weapons-information, paired with safety cases for deployment and continued operation.

ASL-1 ASL-2 (current) ASL-3 (CBRNE info) ASL-4 autonomy ASL-5 safety cases
OpenAI · Nov 2023

Preparedness Framework

Vendor policy Jurisdiction: Vendor (US) Scope: OpenAI models

Published November 2023, the Preparedness Framework is OpenAI's voluntary process for evaluating frontier models before release against a fixed set of risk categories — cybersecurity, CBRN (chemical, biological, radiological, nuclear), persuasion, and model autonomy. Each category is scored, and thresholds trigger additional safety work. The framework is run by OpenAI's Preparedness team, with results feeding internal release decisions.

cybersecurity CBRN persuasion model autonomy risk scoring
Google · May 2023

Secure AI Framework (SAIF)

Vendor policy Jurisdiction: Vendor (US) Scope: Google AI products

Announced May 2023, Google's Secure AI Framework is a voluntary conceptual framework for securing AI systems articulated around six core elements: expand security protections to the AI-ecosystem level; extend detection and response to AI-specific threats; automate defenses to keep pace with AI speed; harmonise platform-level controls across the stack; adapt controls to mitigate new AI risks; and govern deployments with the right context for use cases.

expand to ecosystem extend detection & response automate defenses harmonise controls adapt controls govern with context
Other & related · intergovernmental principles, national mandates, subnational laws

Other & related frameworks

Influential intergovernmental principles, a binding national GenAI regime, and four US subnational developments worth knowing.

OECD · 2019, rev. May 2024

OECD AI Principles

Voluntary Jurisdiction: Global (47+ states) Scope: AI policy

Adopted in May 2019 and updated May 2024, the OECD AI Principles were the first intergovernmental AI principles and remain one of the most widely referenced. They have been adopted by 47+ countries and underpin the OECD's hosted AI Policy Observatory. The principles consist of five values-based principles (inclusive growth, human-centred values, transparency, robustness, accountability) and five recommendations to implementers covering investment, human-capacity, cross-sector co-operation, international co-operation, and oversight.

inclusive growth human-centred values transparency robustness accountability 47+ adopters
China (CAC) · Aug 2023

Interim Measures for Generative AI Services

Binding Jurisdiction: China Scope: Public GenAI services

Issued by the Cyberspace Administration of China (CAC) on July 10, 2023 and effective August 15, 2023, the Interim Measures are mandatory rules for providers of generative AI services to the Chinese public. They impose obligations on training-data sourcing and labelling, content moderation aligned with "socialist core values", security assessments for public-facing services, and real-name registration of users of public-facing GenAI services. They are binding on providers operating in mainland China.

training-data obligations content moderation security assessment real-name registration mandatory CAC

Related: US executive orders & subnational laws

Not separate framework cards — but referenced because they shape who has to act, and when.

US EO 14110 (Biden, Oct 30 2023) rescinded by EO 14179 (Trump, Jan 20 2025) "AI for America" policy 90-day safety-testing requirement — gone

US Executive Order 14110 ("Safe, Secure, and Trustworthy Development and Use of AI", October 30, 2023) was the original US federal framework anchoring NIST AISI and the 90-day safety-testing requirement on frontier models. It was rescinded on January 20, 2025 by EO 14179 ("Removing Barriers to American Leadership in Artificial Intelligence"), which replaced the safety-testing regime with an "AI for America" policy of encouraging deployment.

Colorado SB 24-205 — passed May 17, 2024 first US state high-risk AI law effective Feb 2026

Colorado Senate Bill 24-205 — passed May 17, 2024 — is the first US state law on high-risk AI decision systems. It imposes obligations on developers and deployers of high-risk AI used in consequential decisions (employment, finance, housing, insurance, healthcare, government services). Effective February 2026.

California SB 53 — signed Sept 2024 California SB 1040 — vetoed Sept 2024

California SB 53 (signed September 2024) addresses frontier-model safety incident reporting and critical-infrastructure protections. SB 1040 — the broader, more controversial California AI safety bill — was vetoed in September 2024 over concerns that it would drive developers out of the state.

NYC Local Law 144 — effective Jul 5, 2023 AEDT bias audits

NYC Local Law 144 (New York City, effective July 5, 2023) requires that automated employment decision tools (AEDTs) used in hiring and promotion be subject to an independent bias audit, with results published summarised by category.

Decision guide · which one applies to you?

Which one applies to you?

Pick the entry point that matches what you ship; everything else is supporting context.

01

You ship an LLM-based product

Start with the OWASP Top 10 for LLM Apps — it tells you the ten attack surfaces to threat-model against. Then layer the NIST AI RMF four functions (Govern, Map, Measure, Manage) over the organisation, not just the model. Use the GenAI Profile (AI 600-1) for the ~200 concrete GenAI risk actions.

02

You serve the EU market

You must comply with the EU AI Act. First decision: is your system a GPAI model provider, a high-risk system deployer, or a limited-risk / minimal-risk application? GPAI obligations took effect August 2, 2025 — including the training-content summary and documentation duties. High-risk obligations phase in across 2026-27.

03

You're auditing an AIM system

If the brief is to audit an organisation's AI management system against a conformance bar, ISO/IEC 42001:2023 is the certifiable baseline. Pair it with ISO/IEC 23894 for the underlying risk-management process, and use NIST AI RMF for the functional checklist against which gaps get reported.