Independent · Vendor-Neutral · Evidence-Based

We publish the work first. The engagement follows.

ODA3 Institute engages the major AI security and governance frameworks from founding — through published research, normative control crosswalks, and public comment participation. We do not claim partnerships we have not earned, and we do not list standards body affiliations we do not hold. We publish the work, align to the frameworks at the article and subcategory level, and invite collaboration on honest terms.

Standards body engagement is a long-term commitment. ODA3 Institute is an early-stage organization. What we have is a published research record, a documented evidence methodology, and a normative control framework aligned to seven major regulatory and analytical standards. What we are building is the submission record, the working group participation, and the formal contributor status that turns alignment into recognized contribution.

Standards engagement: active from founding · Research publications: May 2026 · Collaboration: open · Enquiries: oda3.org
LICENSING & AUTHORIZATION

Commercial rights and programme authorization are separate gates.

The GEL v1.0 Licensing Scenarios Guide explains the boundary between Internal Use, Commercial Use and ODA3 authorization or empanelment for external professional delivery.

Read the Licensing Scenarios Guide →

Framework Engagement

Seven frameworks. One control implementation. Active engagement from founding.

The ODA3 Institute Control Framework is crosswalked to seven established frameworks simultaneously. A single ODA3 Institute control implementation addresses multiple regulatory and analytical obligations at once. Every crosswalk is published in the ODA3 Institute Control Framework Appendix A. Coverage methodology is documented; every gap is explicitly disclosed.

ODA3 Pvt Ltd is an independent applied research organization.

All framework engagements below reflect alignment, crosswalk implementation, and planned contribution activity through published research and public comment participation. None imply formal partnership with, membership in, or endorsement by the named organizations. ODA3 Institute does not claim co-authorship of any framework, standard, or publication that predates its founding. Coverage percentages reflect crosswalk mapping progress as of Framework v1.0 — methodology published in Control Framework Appendix A.

Government Framework

NIST AI Risk Management Framework 1.0

Crosswalks to all four NIST AI RMF functions — GOVERN, MAP, MEASURE, MANAGE. 94% of subcategories are addressed by at least one active control.

Gap: 6% — agentic AI subcategories under active prioritization, expected resolution Q3 2026.

Not claimed: No formal NIST partnership. No co-authorship. No NIST endorsement.

International Standard

ISO/IEC 42001:2023

Maps at clause level — context, planning, support, operation, performance evaluation, improvement. 87% of normative clauses addressed by at least one active control.

Gap: 13% — organization-specific management system design outside universal technical control scope.

Not claimed: No ISO/IEC membership. No SC 42 contributor status. No ISO endorsement.

Industry Framework

OWASP LLM Top 10

Maps to all ten risk categories. 91% addressed by at least one active control. Emerging agentic AI additions are tracked as working-group development, not a confirmed edition.

Gap: 9% — emerging agentic AI risk categories under active working group development.

Not claimed: No OWASP membership. No co-authorship. No OWASP endorsement.

Regulatory FrameworkEnforcement Imminent

EU AI Act 2024/1689

Maps to prohibited practices (Art. 5), risk management (Art. 9), human oversight (Art. 14), quality management (Art. 17), and GPAI obligations (Chapter V). 82% of high-risk obligations addressed.

Gap: 18% — provisions requiring organization-specific legal interpretation; qualified legal counsel recommended.

Not claimed: No EU advisory role. No European Commission endorsement.

Regulatory Framework

GDPR (EU) 2016/679

Maps to technical security measures (Art. 32), privacy by design (Art. 25), processor agreements (Art. 28), and breach notification (Art. 33). 79% of AI-relevant obligations addressed.

Gap: 21% — jurisdictional variation in supervisory authority interpretation.

Not claimed: No supervisory authority relationship. No regulatory endorsement.

Sector Regulatory Framework

FINRA RN 23-12 · Rule 4370

Maps AI supervision governance (RN 23-12) and business continuity/incident notification (Rule 4370, 36-hour clock) alongside SEC Item 1.05 coordination.

Coverage: Sector-specific, documented in the Financial Services Annex.

Not claimed: No FINRA relationship. No FINRA endorsement.

Analytical Methodology

MITRE ATT&CK + MITRE ATLAS

ATT&CK is applied as the primary classification system for the broader exploitation chain in every incident forensic reconstruction. ATLAS — the AI-specific extension covering model evasion, data poisoning, and model extraction — is applied for all AI-specific incident classification. Applying both produces more precise incident analysis than ATT&CK alone, visible in every published Technical Report.

Not claimed: No formal partnership with MITRE Corporation. No contributor status. Used under MITRE's standard public terms of use.

RESEARCH COLLABORATION

Structured collaboration for AI security research and standards development.

ODA3 Institute invites expressions of interest from researchers, technical practitioners, standards participants, and organizations working on relevant AI security challenges. Collaboration opportunities are evaluated against documented scope, evidence, confidentiality, data-handling, intellectual-property, and publication requirements.

Planned

Research Collaboration

For academic groups, researchers, and technical institutions interested in research questions that may inform AI security controls, taxonomies, schemas, assessment methods, or implementation guidance.

Potential activities

  • Joint or complementary research
  • Methodology and technical review
  • Taxonomy, schema, or control development
  • Publication and implementation pathways

A governed intake form is not yet operational. Enquiries will open only after the required notice and consent controls are in place.

Planned

Standards & Technical Contribution

For practitioners and subject-matter experts with relevant standards-development experience who are interested in contributing technical knowledge to ODA3 frameworks, mappings, schemas, or standards-development activity.

Participation does not imply representation of, affiliation with, or endorsement by any external standards organization.

Potential activities

  • Technical review and public-comment development
  • Framework and crosswalk analysis
  • Domain-specific control input
  • Schema and implementation review

A governed intake form is not yet operational. No submission is accepted through a generic contact route.

Planned

Enterprise Evidence Collaboration

For organizations interested in discussing appropriately authorized evidence that may support bounded AI security research.

Do not submit incident records, personal data, privileged information, regulated data, credentials, system details, or other sensitive material through the initial enquiry form.

Potential activities

  • Scoping a governed evidence contribution
  • Establishing permitted-use and disclosure boundaries
  • Defining confidentiality and data-handling requirements
  • Determining whether a contribution is appropriate

A governed intake form is not yet operational. Evidence and attachments are not accepted.

Collaboration governance

An enquiry does not create a partnership, contributor status, confidentiality obligation, or authorization to submit sensitive information.

Any collaboration proceeds only under an appropriate written agreement defining, as applicable:

  • Scope and responsibilities
  • Confidentiality and permitted disclosure
  • Privacy, security, retention, and deletion
  • Intellectual-property and licensing terms
  • Attribution and publication review
  • Conflicts of interest
  • Research-integrity and evidence requirements
  • Applicable GEL terms
  • Withdrawal, correction, and termination arrangements

GEL v1.0 may apply to the use of ODA3 framework materials, but it does not replace the written agreements required to govern confidential information, research participation, or incident evidence.

Where We Are Headed

The partnerships ODA3 Institute is working toward — stated honestly.

These are stated as objectives, not current status. When an objective is achieved, this page is updated with specific engagement details and verifiable evidence — the update history is published, not quietly revised.

ObjectiveTargetStatus
NIST AI RMF 2.0 public comment submissionQ3 2026In preparation
OWASP project contributor applicationQ3 2026In preparation
First confirmed enterprise incident contributionQ3 2026Enquiries open
ISO/IEC JTC 1/SC 42 observer enquiryQ4 2026Planned
IETF AI agent identity & authorization protocol participationQ4 2026Tracking
First confirmed academic research partnershipQ4 2026Actively recruiting

Achieved — with verifiable evidence: None as of this publication. An organization that only publishes its successes is not applying its own evidence standards to its own operations — this section stays visible and empty until an objective is genuinely met.

Framework Coverage Summary

All framework crosswalks — at a glance.

Coverage percentages reflect the proportion of framework subcategories, articles, or functions addressed by at least one active ODA3 Institute control as of Framework v1.0. Full methodology published in Control Framework Appendix A.

FrameworkTypeCoverageGap
NIST AI RMF 1.0Government94%6% — agentic AI subcategories, Q3 2026 resolution
ISO/IEC 42001:2023International Standard87%13% — org-specific management system design
OWASP LLM Top 10Industry91%9% — emerging agentic additions, working group development
EU AI Act 2024/1689Regulatory82%18% — provisions requiring legal interpretation
GDPR 2016/679Regulatory79%21% — jurisdictional variation
FINRA RN 23-12 · Rule 4370Sector RegulatorySector-specificEvolving guidance, updated within 30 days of publication
MITRE ATT&CK + ATLASAnalytical MethodologyApplied in all published reportsExpanding with corpus — no coverage ceiling

Framework alignment documentation is for reference purposes — not a substitute for professional compliance assessment. ODA3 Institute research does not constitute legal advice.