Security
The Security team maps public standards and voluntary frameworks to practice for generative and agentic AI systems.
Our research investigates how generative AI systems can be governed, measured, and secured — so that powerful tools stay useful without becoming unverifiable.
The Security team maps public standards and voluntary frameworks to practice for generative and agentic AI systems.
Life, health, property, and environment.
Does the system do what it claims, with documented limits.
Who is responsible, and can others inspect what happened.
Can people understand outputs and behavior.
Anonymity, confidentiality, and control of data.
Harmful bias and discrimination risk.
A filter is not a boundary. This paper compares isolation, allowlists, and output filters for tool-using agents, and files the harmful-action case under Safety rather than as a jailbreak score.
There is no single NIST document titled the AI Security Framework. This paper maps the AI RMF 1.0 suite, locates security inside the seven trustworthiness characteristics, and shows how later NIST instruments attach without substituting for the parent program.
A toggle is not a Measure program. This paper describes a workspace trust-layer pattern — policy, gateway gates, an honest coverage strip, and same-request events — that operationalizes *secure and resilient* for tool-using agents without claiming Safety or the full AI RMF.