AI SECURITY STANDARDS · ASSURANCE · CERTIFICATION ECOSYSTEM

Building the operational assurance infrastructure for AI.

Where AI Governance meets Operational Reality.

ODA3 Institute develops the standards, assessment methods, certification infrastructure, and practitioner capabilities needed to translate AI governance requirements into demonstrable operational practice.

Our ecosystem brings together GAISSF™, UAIF™, and AI-IRF™ across organizational assurance, AI incident classification, and incident response. It supports organizations seeking evidence-based assessment of their implementation, practitioners responsible for evaluating it, and the evidence needed to substantiate assurance decisions.

Founded at the convergence of AI security, cybersecurity, and regulatory compliance, our work is grounded in applied research, documented evidence requirements, and clear limits on what the available evidence can support.

IDENTITY

An institute dedicated to the intersection of cybersecurity and AI.

Most cybersecurity organizations cover AI as one topic among many. Most AI organizations treat security as an afterthought. ODA3 Institute was built to occupy the space between them—where the operational assurance layer governing AI system behaviour is designed, specified, implemented, and evaluated.

We are not a general cybersecurity firm that has added an AI practice. We are not a pure AI product vendor. We are not a policy think tank. We are building an AI security standards, assurance, and certification ecosystem focused on cybersecurity, AI, and the growing intersection between them.

Applied research underpins everything we build: normative control specifications, assessment methodologies, organizational certification infrastructure, practitioner training and credentials, technical schemas, and implementation resources. Our work is designed for enterprise adoption and mapping to relevant international standards and regulatory frameworks, with future contributions to standards-development processes where appropriate.

What we explicitly do not do

We do not accept vendor sponsorship that determines research findings or assurance decisions.
We do not publish findings that the available evidence does not support.
We do not engage in policy advocacy or lobbying—our work is technical, operational, and standards-focused.
We do not present framework alignment as regulatory approval or legal compliance.
We do not represent assurance or certification capabilities beyond their documented operational scope.
We do not make certification decisions without evidence of real-world implementation.
VISION & MISSION

Vision

A world in which AI systems operate with demonstrable security, accountable governance, and evidence that organizations can use to substantiate assurance.

Mission

To build the operational assurance infrastructure that connects AI governance requirements with real-world system behaviour.

ODA3 Institute advances this mission through applied research, AI security standards, assessment methodologies, organizational certification infrastructure, practitioner training and credentials, technical schemas, and implementation resources. Together, these components help organizations specify controls, manage AI security incidents, evaluate implementation, and support evidence-based assurance decisions.

ODA3 Institute complements the work of regulators, international standards bodies, academic institutions, industry groups, and enterprise security teams. We translate governance expectations and supported research findings into operational requirements, assessment methods, evidence models, and practitioner capabilities for real-world implementation.

How the ODA3 ecosystem closes the assurance loop

StageODA3 contributionIntended outcome
Applied researchExamine AI security incidents, control challenges, evidence requirements, and implementation gapsEvidence-bounded findings with documented limitations
StandardsDevelop operational requirements, taxonomies, schemas, and implementation guidanceConsistent and implementable expectations
ImplementationSupport organizations in applying requirements within real-world environmentsImplemented controls and documented evidence
AssessmentEvaluate implementation against defined criteria and evidence requirementsTraceable findings and identified gaps
Assurance and certificationBuild governed pathways for organizational attestation and certificationDefensible assurance and certification decisions within the documented operational scope
Practitioner capabilityDevelop training and credentials for relevant implementation and assessment rolesPractitioners equipped to implement and evaluate
FeedbackUse appropriately governed implementation and assessment evidence to identify improvementsIterative refinement of standards, methods, and resources
WHAT WE DO

From evidence to operational assurance.

ODA3 Institute connects research, standards, assessment, certification infrastructure, and practitioner capability in one integrated AI security ecosystem.

Threat Intelligence & Applied Research

We investigate AI security incidents, emerging threats, control failures, and evidence gaps.

  • Incident and threat analysis
  • Control-effectiveness and evidence research
  • Documented limitations and notably absent events

Standards Development

We translate supported findings and governance requirements into operational frameworks, controls, taxonomies, schemas, and mappings.

  • GAISSF™, UAIF™, and AI-IRF
  • Normative control specifications
  • Implementation guidance and crosswalks

Organizational Assurance & Assessment

We are building methods and certification infrastructure for evaluating organizational implementation against documented criteria.

  • Assessment and evidence requirements
  • Attestation and certification pathways
  • Decisions bounded by documented operational scope

Practitioner Training & Credentials

We are developing role-based pathways for practitioners who implement, assess, and improve AI security controls.

  • Control implementation and validation
  • Incident classification and response
  • Role-based training and credentials
IMPLEMENTATION SUPPORT

Compliance Advisory & Implementation Support

We help organizations interpret framework requirements, structure implementation, prepare evidence, and understand relevant standards and regulatory mappings—without presenting alignment as legal advice, regulatory approval, or guaranteed compliance.

Closing the loop

Research informs standards; standards guide implementation and assessment; and appropriately authorized evidence, governed by applicable confidentiality and data-handling requirements, informs continuous improvement.

OPERATING MODEL

An evidence-to-assurance operating model.

ODA3 Institute operates as an integrated assurance ecosystem rather than a collection of disconnected services. Each stage produces defined inputs for the next, while feedback is incorporated only within documented operational, confidentiality, and data-governance boundaries.

STAGE 01 — RESEARCH

Identify supported findings

We examine AI security incidents, emerging threats, control failures, and evidence gaps. Findings are tiered by evidence quality, bounded by documented limitations, and explicit about what the available evidence does not establish.

STAGE 02 — STANDARDS

Translate findings into requirements

Supported findings and governance requirements inform normative controls, taxonomies, technical schemas, implementation guidance, and mappings across the GAISSF™, UAIF™, and AI-IRF™ ecosystem.

STAGE 03 — IMPLEMENTATION & CAPABILITY

Put requirements into practice

Implementation resources, technical guidance, and developing training pathways help organizations and practitioners apply controls, manage incidents, and produce evidence for evaluation.

STAGE 04 — ASSESSMENT & ASSURANCE

Build the evaluation pathway

ODA3 Institute is developing methods for evaluating implementation against documented criteria and evidence requirements. As capabilities become operational, findings may support improvement and defined attestation or certification pathways within their documented operational scope.

Operating principles

Evidence-bounded

Findings and requirements are limited to what documented evidence can support.

Traceable

Controls, mappings, assessment criteria, and findings maintain a clear basis and defined scope.

Status-transparent

Capabilities and artifacts are identified accurately as Published, Operational, Pilot, or Planned.

Governed feedback

Internal review can inform current research and framework development. Implementation or assessment evidence may inform improvement only where its use is expressly authorized and governed by applicable confidentiality, privacy, independence, and data-handling requirements.

Closing the loop

Research informs standards. Standards guide implementation. Assessment evaluates evidence as the capability becomes operational. Governed feedback supports continuous improvement.

WHAT SETS ODA3 INSTITUTE APART

Designed for evidence, implementation, and assurance.

ODA3 Institute focuses on the operational gap between AI governance requirements and real-world system behaviour. Our differentiation comes from how research, standards, assessment, and practitioner capability are designed to work together.

AI Security Specialization

Our work focuses on AI security and its intersection with cybersecurity, assurance, and regulatory requirements—not general cybersecurity or general-purpose AI development.

Integrated Framework Ecosystem

GAISSF™, UAIF™, and AI-IRF™ connect organizational assurance, AI incident classification, and incident response within a shared operational ecosystem.

Normative Specificity

We develop controls, taxonomies, schemas, and implementation guidance using defined terminology, evidence expectations, and assessment criteria—not guidance alone.

Evidence Discipline

Findings are tiered by evidence quality, bounded by documented limitations, and explicit about unsupported conclusions and notably absent events.

Assessment-Ready Design

Controls and implementation guidance are structured to support traceable evaluation against documented criteria as assessment capabilities become operational.

Transparent Status and Scope

Capabilities and artifacts are identified accurately as Published, Operational, Pilot, or Planned, and represented only within their documented operational scope.

Our standard

We do not differentiate through claims of guaranteed security, regulatory approval, or universal compliance. We differentiate through documented requirements, traceable evidence, explicit limitations, and transparent operational status.

SCOPE BOUNDARIES

Where ODA3 Institute’s mandate begins—and where it ends.

Clear boundaries protect the integrity of our research, standards, advisory work, assessments, and developing certification infrastructure. We accept work only where it falls within our documented AI security and operational-assurance scope.

General Cybersecurity Engagements

We do not provide broad enterprise cybersecurity services unrelated to AI systems. Cybersecurity architecture, testing, and incident-response work must directly support an AI security, assurance, or framework objective.

General-Purpose AI Products

We do not develop general-purpose AI products or endorse vendors through our research and standards work. Any software developed by ODA3 Institute will support the implementation, evidence, assessment, or assurance functions of the ODA3 ecosystem.

Legal Advice, Lobbying & Regulatory Representation

We do not provide legal advice, guarantee regulatory compliance, or lobby on behalf of clients. We may contribute technical evidence, standards expertise, and documented mappings to standards-development and regulatory-consultation processes.

Assurance & Certification Claims

We do not represent assessment, attestation, certification, or credentialing capabilities beyond their documented operational scope. Planned and pilot capabilities are identified explicitly and are not presented as operational services.

Boundary principle

When a requirement falls outside our mandate, we state the limitation clearly. Where appropriate, we may identify the type of qualified specialist an organization should engage, without implying endorsement or responsibility for that provider’s work.

AUDIENCES

Built for practitioners. Structured for decision-makers.

ODA3 Institute develops technical and assurance resources for the people who implement, evaluate, govern, and oversee AI security. The evidence standard remains consistent, while the format and level of detail reflect each audience’s responsibilities.

Primary audiences

CISOs & Security Architects

Operational frameworks, control specifications, implementation guidance, and evidence requirements for designing and governing AI security programmes.

AI Governance & Compliance Leaders

Documented mappings, implementation criteria, and developing assurance resources for connecting governance obligations with technical implementation and evidence.

Security Operations & Incident Response Teams

Taxonomies, schemas, response methods, and practitioner resources for identifying, classifying, investigating, and managing AI security incidents.

Standards, Assessment & Assurance Practitioners

Normative requirements, evidence models, and assessment-ready materials for standards participation, implementation evaluation, and developing assurance pathways.

Secondary audiences

Executives, Boards & Risk Committees

Concise, evidence-bounded information for understanding organizational exposure, implementation status, material limitations, and assurance priorities.

General Counsel & Enterprise Risk Leaders

Documented technical findings and regulatory mappings that support legal and risk analysis without representing framework alignment as legal advice or guaranteed compliance.

Researchers & Institutional Collaborators

Published frameworks, schemas, research methods, and technical materials that support review, comparison, further research, and potential standards contributions.

Audience principle

The format changes with the decision context; the evidence discipline does not. Every audience receives conclusions bounded by documented evidence, limitations, operational status, and scope.

RESEARCH INTEGRITY

Research claims bounded by evidence.

ODA3 Institute applies documented evidence discipline to its research, standards, mappings, and technical publications. The strength of each conclusion is limited by the quality, relevance, corroboration, and limitations of the available evidence.

Source Traceability

Material findings identify their source basis and distinguish direct evidence, corroborating material, reported information, and modelled estimates where applicable.

Claim-to-Evidence Proportionality

The strength of a claim must not exceed what its supporting evidence can establish. Single-source or unresolved information is not presented as verified fact.

Limitations & Notably Absent

Publications identify material evidence gaps, unresolved questions, and relevant events or patterns that were not observed within the defined scope and reporting period.

Method Transparency & Version Control

Methods, assumptions, material corrections, and changes are documented at a level appropriate to the publication and maintained through defined versioning practices.

Application principle

Evidence classification does not by itself establish control effectiveness, regulatory compliance, assessment conformity, or certification eligibility. Those conclusions require separate criteria, methods, and evidence within their documented operational scope.

Where a publication uses evidence tiers, confidence statements, or quantitative estimates, it identifies the applicable method, assumptions, source basis, limitations, and version.

STANDARDS ENGAGEMENT

Mapping, monitoring, and contribution—without implied endorsement.

ODA3 Institute maps its frameworks to relevant standards and regulatory requirements, monitors material developments, and may contribute technical evidence through appropriate public or formal processes. Each activity is represented according to its documented status and scope.

Standards & Regulatory Mapping

Where published, ODA3 mappings identify defined relationships between GAISSF™, UAIF™, AI-IRF™, and relevant external requirements. Mappings document correspondence; they do not establish regulatory approval, legal compliance, equivalence, or endorsement.

Standards Monitoring

ODA3 monitors developments that may affect its frameworks, implementation guidance, schemas, and assessment-ready materials. Monitoring does not imply membership, participation, or a formal relationship with the organization being monitored.

Technical Contribution

ODA3 may submit public comments, technical proposals, research findings, or implementation evidence through processes open to eligible contributors. Planned activity is not described as submitted, accepted, or active until the relevant status can be documented.

Relationship Boundaries

Reference to an external standard, regulator, industry group, or standards-development organization does not imply membership, partnership, authorization, approval, or endorsement. Any formal relationship is identified separately and supported by an appropriate record.

Status principle

ODA3 artifacts and capabilities are identified as:

Published
a public, versioned ODA3 artifact is available.
Operational
an approved capability or process is active within its documented scope.
Pilot
a limited activity is being evaluated within defined boundaries.
Planned
work is approved or under development but has not been published or made operational.

A public status is displayed only where supporting evidence exists. External engagement is recorded separately according to its documented procedural state.

Research collaboration

Research collaboration

ODA3 Institute evaluates research, technical, and evidence-collaboration opportunities within documented scope and governance requirements.

Explore Research Collaboration →
Get Started

Three ways to engage with ODA3 Institute today.

Read the Research

Start with the OAuth Pivot — ODA3 Institute's inaugural Technical Report. Forensic reconstruction of AI-mediated OAuth exploitation, MITRE ATT&CK mapping, and an SEC Item 1.05 disclosure playbook.

Download the OAuth Pivot Report →

ODA3-2026-05-TCR-SEC-003 · Evidence cutoff: Q1 2026 · Free · Registration required

Access the Framework

Normative controls crosswalked to NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, EU AI Act, GDPR Art. 32, and MITRE ATLAS. Every control carries incident provenance and audit-ready implementation criteria.

Access the Control Framework →

Framework v1.0 · Updated quarterly

Request a Briefing

60-minute evidence-based briefing for CISOs, compliance officers, and board risk committees — covering incident analysis, control implications, and regulatory deadline mapping. No vendor pitch. Evidence and controls only.

Request a Briefing →

Enquiries via oda3.org