Building the operational assurance infrastructure for AI.
Where AI Governance meets Operational Reality.
ODA3 Institute develops the standards, assessment methods, certification infrastructure, and practitioner capabilities needed to translate AI governance requirements into demonstrable operational practice.
Our ecosystem brings together GAISSF™, UAIF™, and AI-IRF™ across organizational assurance, AI incident classification, and incident response. It supports organizations seeking evidence-based assessment of their implementation, practitioners responsible for evaluating it, and the evidence needed to substantiate assurance decisions.
Founded at the convergence of AI security, cybersecurity, and regulatory compliance, our work is grounded in applied research, documented evidence requirements, and clear limits on what the available evidence can support.
An institute dedicated to the intersection of cybersecurity and AI.
Most cybersecurity organizations cover AI as one topic among many. Most AI organizations treat security as an afterthought. ODA3 Institute was built to occupy the space between them—where the operational assurance layer governing AI system behaviour is designed, specified, implemented, and evaluated.
We are not a general cybersecurity firm that has added an AI practice. We are not a pure AI product vendor. We are not a policy think tank. We are building an AI security standards, assurance, and certification ecosystem focused on cybersecurity, AI, and the growing intersection between them.
Applied research underpins everything we build: normative control specifications, assessment methodologies, organizational certification infrastructure, practitioner training and credentials, technical schemas, and implementation resources. Our work is designed for enterprise adoption and mapping to relevant international standards and regulatory frameworks, with future contributions to standards-development processes where appropriate.
What we explicitly do not do
Vision
A world in which AI systems operate with demonstrable security, accountable governance, and evidence that organizations can use to substantiate assurance.
Mission
To build the operational assurance infrastructure that connects AI governance requirements with real-world system behaviour.
ODA3 Institute advances this mission through applied research, AI security standards, assessment methodologies, organizational certification infrastructure, practitioner training and credentials, technical schemas, and implementation resources. Together, these components help organizations specify controls, manage AI security incidents, evaluate implementation, and support evidence-based assurance decisions.
ODA3 Institute complements the work of regulators, international standards bodies, academic institutions, industry groups, and enterprise security teams. We translate governance expectations and supported research findings into operational requirements, assessment methods, evidence models, and practitioner capabilities for real-world implementation.
How the ODA3 ecosystem closes the assurance loop
| Stage | ODA3 contribution | Intended outcome |
|---|---|---|
| Applied research | Examine AI security incidents, control challenges, evidence requirements, and implementation gaps | Evidence-bounded findings with documented limitations |
| Standards | Develop operational requirements, taxonomies, schemas, and implementation guidance | Consistent and implementable expectations |
| Implementation | Support organizations in applying requirements within real-world environments | Implemented controls and documented evidence |
| Assessment | Evaluate implementation against defined criteria and evidence requirements | Traceable findings and identified gaps |
| Assurance and certification | Build governed pathways for organizational attestation and certification | Defensible assurance and certification decisions within the documented operational scope |
| Practitioner capability | Develop training and credentials for relevant implementation and assessment roles | Practitioners equipped to implement and evaluate |
| Feedback | Use appropriately governed implementation and assessment evidence to identify improvements | Iterative refinement of standards, methods, and resources |
From evidence to operational assurance.
ODA3 Institute connects research, standards, assessment, certification infrastructure, and practitioner capability in one integrated AI security ecosystem.
Threat Intelligence & Applied Research
We investigate AI security incidents, emerging threats, control failures, and evidence gaps.
- Incident and threat analysis
- Control-effectiveness and evidence research
- Documented limitations and notably absent events
Standards Development
We translate supported findings and governance requirements into operational frameworks, controls, taxonomies, schemas, and mappings.
- GAISSF™, UAIF™, and AI-IRF™
- Normative control specifications
- Implementation guidance and crosswalks
Organizational Assurance & Assessment
We are building methods and certification infrastructure for evaluating organizational implementation against documented criteria.
- Assessment and evidence requirements
- Attestation and certification pathways
- Decisions bounded by documented operational scope
Practitioner Training & Credentials
We are developing role-based pathways for practitioners who implement, assess, and improve AI security controls.
- Control implementation and validation
- Incident classification and response
- Role-based training and credentials
Compliance Advisory & Implementation Support
We help organizations interpret framework requirements, structure implementation, prepare evidence, and understand relevant standards and regulatory mappings—without presenting alignment as legal advice, regulatory approval, or guaranteed compliance.
Closing the loop
Research informs standards; standards guide implementation and assessment; and appropriately authorized evidence, governed by applicable confidentiality and data-handling requirements, informs continuous improvement.
Designed for evidence, implementation, and assurance.
ODA3 Institute focuses on the operational gap between AI governance requirements and real-world system behaviour. Our differentiation comes from how research, standards, assessment, and practitioner capability are designed to work together.
AI Security Specialization
Our work focuses on AI security and its intersection with cybersecurity, assurance, and regulatory requirements—not general cybersecurity or general-purpose AI development.
Integrated Framework Ecosystem
GAISSF™, UAIF™, and AI-IRF™ connect organizational assurance, AI incident classification, and incident response within a shared operational ecosystem.
Normative Specificity
We develop controls, taxonomies, schemas, and implementation guidance using defined terminology, evidence expectations, and assessment criteria—not guidance alone.
Evidence Discipline
Findings are tiered by evidence quality, bounded by documented limitations, and explicit about unsupported conclusions and notably absent events.
Assessment-Ready Design
Controls and implementation guidance are structured to support traceable evaluation against documented criteria as assessment capabilities become operational.
Transparent Status and Scope
Capabilities and artifacts are identified accurately as Published, Operational, Pilot, or Planned, and represented only within their documented operational scope.
Our standard
We do not differentiate through claims of guaranteed security, regulatory approval, or universal compliance. We differentiate through documented requirements, traceable evidence, explicit limitations, and transparent operational status.
Where ODA3 Institute’s mandate begins—and where it ends.
Clear boundaries protect the integrity of our research, standards, advisory work, assessments, and developing certification infrastructure. We accept work only where it falls within our documented AI security and operational-assurance scope.
General Cybersecurity Engagements
We do not provide broad enterprise cybersecurity services unrelated to AI systems. Cybersecurity architecture, testing, and incident-response work must directly support an AI security, assurance, or framework objective.
General-Purpose AI Products
We do not develop general-purpose AI products or endorse vendors through our research and standards work. Any software developed by ODA3 Institute will support the implementation, evidence, assessment, or assurance functions of the ODA3 ecosystem.
Legal Advice, Lobbying & Regulatory Representation
We do not provide legal advice, guarantee regulatory compliance, or lobby on behalf of clients. We may contribute technical evidence, standards expertise, and documented mappings to standards-development and regulatory-consultation processes.
Assurance & Certification Claims
We do not represent assessment, attestation, certification, or credentialing capabilities beyond their documented operational scope. Planned and pilot capabilities are identified explicitly and are not presented as operational services.
Boundary principle
When a requirement falls outside our mandate, we state the limitation clearly. Where appropriate, we may identify the type of qualified specialist an organization should engage, without implying endorsement or responsibility for that provider’s work.
Built for practitioners. Structured for decision-makers.
ODA3 Institute develops technical and assurance resources for the people who implement, evaluate, govern, and oversee AI security. The evidence standard remains consistent, while the format and level of detail reflect each audience’s responsibilities.
Primary audiences
CISOs & Security Architects
Operational frameworks, control specifications, implementation guidance, and evidence requirements for designing and governing AI security programmes.
AI Governance & Compliance Leaders
Documented mappings, implementation criteria, and developing assurance resources for connecting governance obligations with technical implementation and evidence.
Security Operations & Incident Response Teams
Taxonomies, schemas, response methods, and practitioner resources for identifying, classifying, investigating, and managing AI security incidents.
Standards, Assessment & Assurance Practitioners
Normative requirements, evidence models, and assessment-ready materials for standards participation, implementation evaluation, and developing assurance pathways.
Secondary audiences
Executives, Boards & Risk Committees
Concise, evidence-bounded information for understanding organizational exposure, implementation status, material limitations, and assurance priorities.
General Counsel & Enterprise Risk Leaders
Documented technical findings and regulatory mappings that support legal and risk analysis without representing framework alignment as legal advice or guaranteed compliance.
Researchers & Institutional Collaborators
Published frameworks, schemas, research methods, and technical materials that support review, comparison, further research, and potential standards contributions.
Audience principle
The format changes with the decision context; the evidence discipline does not. Every audience receives conclusions bounded by documented evidence, limitations, operational status, and scope.
Research claims bounded by evidence.
ODA3 Institute applies documented evidence discipline to its research, standards, mappings, and technical publications. The strength of each conclusion is limited by the quality, relevance, corroboration, and limitations of the available evidence.
Source Traceability
Material findings identify their source basis and distinguish direct evidence, corroborating material, reported information, and modelled estimates where applicable.
Claim-to-Evidence Proportionality
The strength of a claim must not exceed what its supporting evidence can establish. Single-source or unresolved information is not presented as verified fact.
Limitations & Notably Absent
Publications identify material evidence gaps, unresolved questions, and relevant events or patterns that were not observed within the defined scope and reporting period.
Method Transparency & Version Control
Methods, assumptions, material corrections, and changes are documented at a level appropriate to the publication and maintained through defined versioning practices.
Application principle
Evidence classification does not by itself establish control effectiveness, regulatory compliance, assessment conformity, or certification eligibility. Those conclusions require separate criteria, methods, and evidence within their documented operational scope.
Where a publication uses evidence tiers, confidence statements, or quantitative estimates, it identifies the applicable method, assumptions, source basis, limitations, and version.
Mapping, monitoring, and contribution—without implied endorsement.
ODA3 Institute maps its frameworks to relevant standards and regulatory requirements, monitors material developments, and may contribute technical evidence through appropriate public or formal processes. Each activity is represented according to its documented status and scope.
Standards & Regulatory Mapping
Where published, ODA3 mappings identify defined relationships between GAISSF™, UAIF™, AI-IRF™, and relevant external requirements. Mappings document correspondence; they do not establish regulatory approval, legal compliance, equivalence, or endorsement.
Standards Monitoring
ODA3 monitors developments that may affect its frameworks, implementation guidance, schemas, and assessment-ready materials. Monitoring does not imply membership, participation, or a formal relationship with the organization being monitored.
Technical Contribution
ODA3 may submit public comments, technical proposals, research findings, or implementation evidence through processes open to eligible contributors. Planned activity is not described as submitted, accepted, or active until the relevant status can be documented.
Relationship Boundaries
Reference to an external standard, regulator, industry group, or standards-development organization does not imply membership, partnership, authorization, approval, or endorsement. Any formal relationship is identified separately and supported by an appropriate record.
Status principle
ODA3 artifacts and capabilities are identified as:
- Published
- a public, versioned ODA3 artifact is available.
- Operational
- an approved capability or process is active within its documented scope.
- Pilot
- a limited activity is being evaluated within defined boundaries.
- Planned
- work is approved or under development but has not been published or made operational.
A public status is displayed only where supporting evidence exists. External engagement is recorded separately according to its documented procedural state.
Research collaboration
ODA3 Institute evaluates research, technical, and evidence-collaboration opportunities within documented scope and governance requirements.
Explore Research Collaboration →Three ways to engage with ODA3 Institute today.
Read the Research
Start with the OAuth Pivot — ODA3 Institute's inaugural Technical Report. Forensic reconstruction of AI-mediated OAuth exploitation, MITRE ATT&CK mapping, and an SEC Item 1.05 disclosure playbook.
Download the OAuth Pivot Report →ODA3-2026-05-TCR-SEC-003 · Evidence cutoff: Q1 2026 · Free · Registration required
Access the Framework
Normative controls crosswalked to NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, EU AI Act, GDPR Art. 32, and MITRE ATLAS. Every control carries incident provenance and audit-ready implementation criteria.
Access the Control Framework →Framework v1.0 · Updated quarterly
Request a Briefing
60-minute evidence-based briefing for CISOs, compliance officers, and board risk committees — covering incident analysis, control implications, and regulatory deadline mapping. No vendor pitch. Evidence and controls only.
Request a Briefing →Enquiries via oda3.org