We publish the work first. The engagement follows.
ODA3 Institute engages the major AI security and governance frameworks from founding — through published research, normative control crosswalks, and public comment participation. We do not claim partnerships we have not earned, and we do not list standards body affiliations we do not hold. We publish the work, align to the frameworks at the article and subcategory level, and invite collaboration on honest terms.
Standards body engagement is a long-term commitment. ODA3 Institute is an early-stage organization. What we have is a published research record, a documented evidence methodology, and a normative control framework aligned to seven major regulatory and analytical standards. What we are building is the submission record, the working group participation, and the formal contributor status that turns alignment into recognized contribution.
Commercial rights and programme authorization are separate gates.
The GEL v1.0 Licensing Scenarios Guide explains the boundary between Internal Use, Commercial Use and ODA3 authorization or empanelment for external professional delivery.
Seven frameworks. One control implementation. Active engagement from founding.
The ODA3 Institute Control Framework is crosswalked to seven established frameworks simultaneously. A single ODA3 Institute control implementation addresses multiple regulatory and analytical obligations at once. Every crosswalk is published in the ODA3 Institute Control Framework Appendix A. Coverage methodology is documented; every gap is explicitly disclosed.
All framework engagements below reflect alignment, crosswalk implementation, and planned contribution activity through published research and public comment participation. None imply formal partnership with, membership in, or endorsement by the named organizations. ODA3 Institute does not claim co-authorship of any framework, standard, or publication that predates its founding. Coverage percentages reflect crosswalk mapping progress as of Framework v1.0 — methodology published in Control Framework Appendix A.
NIST AI Risk Management Framework 1.0
Crosswalks to all four NIST AI RMF functions — GOVERN, MAP, MEASURE, MANAGE. 94% of subcategories are addressed by at least one active control.
Gap: 6% — agentic AI subcategories under active prioritization, expected resolution Q3 2026.
Not claimed: No formal NIST partnership. No co-authorship. No NIST endorsement.
ISO/IEC 42001:2023
Maps at clause level — context, planning, support, operation, performance evaluation, improvement. 87% of normative clauses addressed by at least one active control.
Gap: 13% — organization-specific management system design outside universal technical control scope.
Not claimed: No ISO/IEC membership. No SC 42 contributor status. No ISO endorsement.
OWASP LLM Top 10
Maps to all ten risk categories. 91% addressed by at least one active control. Emerging agentic AI additions are tracked as working-group development, not a confirmed edition.
Gap: 9% — emerging agentic AI risk categories under active working group development.
Not claimed: No OWASP membership. No co-authorship. No OWASP endorsement.
EU AI Act 2024/1689
Maps to prohibited practices (Art. 5), risk management (Art. 9), human oversight (Art. 14), quality management (Art. 17), and GPAI obligations (Chapter V). 82% of high-risk obligations addressed.
Gap: 18% — provisions requiring organization-specific legal interpretation; qualified legal counsel recommended.
Not claimed: No EU advisory role. No European Commission endorsement.
GDPR (EU) 2016/679
Maps to technical security measures (Art. 32), privacy by design (Art. 25), processor agreements (Art. 28), and breach notification (Art. 33). 79% of AI-relevant obligations addressed.
Gap: 21% — jurisdictional variation in supervisory authority interpretation.
Not claimed: No supervisory authority relationship. No regulatory endorsement.
FINRA RN 23-12 · Rule 4370
Maps AI supervision governance (RN 23-12) and business continuity/incident notification (Rule 4370, 36-hour clock) alongside SEC Item 1.05 coordination.
Coverage: Sector-specific, documented in the Financial Services Annex.
Not claimed: No FINRA relationship. No FINRA endorsement.
MITRE ATT&CK + MITRE ATLAS
ATT&CK is applied as the primary classification system for the broader exploitation chain in every incident forensic reconstruction. ATLAS — the AI-specific extension covering model evasion, data poisoning, and model extraction — is applied for all AI-specific incident classification. Applying both produces more precise incident analysis than ATT&CK alone, visible in every published Technical Report.
Not claimed: No formal partnership with MITRE Corporation. No contributor status. Used under MITRE's standard public terms of use.
Structured collaboration for AI security research and standards development.
ODA3 Institute invites expressions of interest from researchers, technical practitioners, standards participants, and organizations working on relevant AI security challenges. Collaboration opportunities are evaluated against documented scope, evidence, confidentiality, data-handling, intellectual-property, and publication requirements.
Research Collaboration
For academic groups, researchers, and technical institutions interested in research questions that may inform AI security controls, taxonomies, schemas, assessment methods, or implementation guidance.
Potential activities
- Joint or complementary research
- Methodology and technical review
- Taxonomy, schema, or control development
- Publication and implementation pathways
A governed intake form is not yet operational. Enquiries will open only after the required notice and consent controls are in place.
Standards & Technical Contribution
For practitioners and subject-matter experts with relevant standards-development experience who are interested in contributing technical knowledge to ODA3 frameworks, mappings, schemas, or standards-development activity.
Participation does not imply representation of, affiliation with, or endorsement by any external standards organization.
Potential activities
- Technical review and public-comment development
- Framework and crosswalk analysis
- Domain-specific control input
- Schema and implementation review
A governed intake form is not yet operational. No submission is accepted through a generic contact route.
Enterprise Evidence Collaboration
For organizations interested in discussing appropriately authorized evidence that may support bounded AI security research.
Do not submit incident records, personal data, privileged information, regulated data, credentials, system details, or other sensitive material through the initial enquiry form.
Potential activities
- Scoping a governed evidence contribution
- Establishing permitted-use and disclosure boundaries
- Defining confidentiality and data-handling requirements
- Determining whether a contribution is appropriate
A governed intake form is not yet operational. Evidence and attachments are not accepted.
Collaboration governance
An enquiry does not create a partnership, contributor status, confidentiality obligation, or authorization to submit sensitive information.
Any collaboration proceeds only under an appropriate written agreement defining, as applicable:
- Scope and responsibilities
- Confidentiality and permitted disclosure
- Privacy, security, retention, and deletion
- Intellectual-property and licensing terms
- Attribution and publication review
- Conflicts of interest
- Research-integrity and evidence requirements
- Applicable GEL terms
- Withdrawal, correction, and termination arrangements
GEL v1.0 may apply to the use of ODA3 framework materials, but it does not replace the written agreements required to govern confidential information, research participation, or incident evidence.
The partnerships ODA3 Institute is working toward — stated honestly.
These are stated as objectives, not current status. When an objective is achieved, this page is updated with specific engagement details and verifiable evidence — the update history is published, not quietly revised.
| Objective | Target | Status |
|---|---|---|
| NIST AI RMF 2.0 public comment submission | Q3 2026 | In preparation |
| OWASP project contributor application | Q3 2026 | In preparation |
| First confirmed enterprise incident contribution | Q3 2026 | Enquiries open |
| ISO/IEC JTC 1/SC 42 observer enquiry | Q4 2026 | Planned |
| IETF AI agent identity & authorization protocol participation | Q4 2026 | Tracking |
| First confirmed academic research partnership | Q4 2026 | Actively recruiting |
Achieved — with verifiable evidence: None as of this publication. An organization that only publishes its successes is not applying its own evidence standards to its own operations — this section stays visible and empty until an objective is genuinely met.
All framework crosswalks — at a glance.
Coverage percentages reflect the proportion of framework subcategories, articles, or functions addressed by at least one active ODA3 Institute control as of Framework v1.0. Full methodology published in Control Framework Appendix A.
| Framework | Type | Coverage | Gap |
|---|---|---|---|
| NIST AI RMF 1.0 | Government | 94% | 6% — agentic AI subcategories, Q3 2026 resolution |
| ISO/IEC 42001:2023 | International Standard | 87% | 13% — org-specific management system design |
| OWASP LLM Top 10 | Industry | 91% | 9% — emerging agentic additions, working group development |
| EU AI Act 2024/1689 | Regulatory | 82% | 18% — provisions requiring legal interpretation |
| GDPR 2016/679 | Regulatory | 79% | 21% — jurisdictional variation |
| FINRA RN 23-12 · Rule 4370 | Sector Regulatory | Sector-specific | Evolving guidance, updated within 30 days of publication |
| MITRE ATT&CK + ATLAS | Analytical Methodology | Applied in all published reports | Expanding with corpus — no coverage ceiling |
Framework alignment documentation is for reference purposes — not a substitute for professional compliance assessment. ODA3 Institute research does not constitute legal advice.