- AAT-01AATArtificial Intelligence (AI) & Autonomous Technologies Governance
Mechanisms exist to ensure policies, processes, procedures and practices related to the mapping, measuring and managing of Artificial Intelligence (AI) and Autonomous Technologies (AAT)-related risks are in place, transparent and implemented effectively.
- AAT-01.1AATAI & Autonomous Technologies-Related Legal Requirements Definition
Mechanisms exist to identify, understand, document and manage applicable statutory and regulatory requirements for Artificial Intelligence (AI) and Autonomous Technologies (AAT).
- AAT-01.2AATTrustworthy AI & Autonomous Technologies
Mechanisms exist to ensure Artificial Intelligence (AI) and Autonomous Technologies (AAT) are designed to be reliable, safe, fair, secure, resilient, transparent, explainable and data privacy-enhanced to minimize emergent properties or unintended consequences.
- AAT-01.3AATAI & Autonomous Technologies Value Sustainment
Mechanisms exist to sustain the value of deployed Artificial Intelligence (AI) and Autonomous Technologies (AAT).
- AAT-01.4AATAI Model & Agent Inventory & Lifecycle Management
Mechanisms exist to track the lifecycle of all AI models and AI agents, including ownership, intended purpose and status across: (1) Development; (2) Deployment; (3) Updates; and (4) Decommissioning.
- AAT-01.5AATArtificial Intelligence and Autonomous Technologies (AAT) & AI Agent Categorization
Mechanisms exist to assign defined classes to Artificial Intelligence and Autonomous Technologies (AAT) and AI agents based on their characteristics (e.g., intended use, autonomy, access, potential impact and risk) to determine applicable: (1) Approval requirements; (2) Security, compliance and/or resilience controls; (3) Testing rigor; (4) Monitoring requirements; (5) Supporting documentation; and (6) Oversight requirements.
- AAT-02AATSituational Awareness of AI & Autonomous Technologies
Mechanisms exist to develop and maintain an inventory of Artificial Intelligence (AI) and Autonomous Technologies (AAT) (internal and third-party).
- AAT-02.1AATAI & Autonomous Technologies Risk Mapping
Mechanisms exist to identify Artificial Intelligence (AI) and Autonomous Technologies (AAT) in use and map those components to potential legal risks, including statutory and regulatory compliance requirements.
- AAT-02.2AATAI & Autonomous Technologies Internal Controls
Mechanisms exist to identify and document internal security, compliance and resilience for Artificial Intelligence (AI) and Autonomous Technologies (AAT).
- AAT-02.3AATAdequate Protections For AI & Autonomous Technologies
Mechanisms exist to ensure Artificial Intelligence (AI) and Autonomous Technologies (AAT) include reasonable security, compliance and resilience protections that are commensurate with assessed risks and threats.
- AAT-02.4AATAI Threat Modeling & Risk Assessment
Mechanisms exist to conduct Artificial Intelligence (AI) and Autonomous Technologies (AAT)-specific threat modeling and risk assessments to address the following criteria across the lifecycle of the AAT: (1) Attack surfaces; (2) Adversarial threats; and (3) Abuse / misuse scenarios.
- AAT-03AATAI & Autonomous Technologies Context Definition
Mechanisms exist to establish and document the context surrounding Artificial Intelligence (AI) and Autonomous Technologies (AAT), including: (1) Intended purposes; (2) Potentially beneficial uses; (3) Context-specific laws and regulations; (4) Norms and expectations; and (5) Prospective settings in which the system(s) will be deployed.
- AAT-03.1AATAI & Autonomous Technologies Mission and Goals Definition
Mechanisms exist to define and document the organization's mission and defined goals for Artificial Intelligence (AI) and Autonomous Technologies (AAT).
- AAT-03.2AATModel & AI Agent Documentation
Mechanisms exist to create, maintain and provide access to documentation artifacts for AI models and agents, including: (1) Data lineage; (2) Intended use; and (3) Limitations.
- AAT-04AATAI & Autonomous Technologies Business Case
Mechanisms exist to benchmark capabilities, targeted usage, goals and expected benefits and costs of Artificial Intelligence (AI) and Autonomous Technologies (AAT).
- AAT-04.1AATAI & Autonomous Technologies Potential Benefits Analysis
Mechanisms exist to assess the potential benefits of proposed Artificial Intelligence (AI) and Autonomous Technologies (AAT).
- AAT-04.2AATAI & Autonomous Technologies Potential Costs Analysis
Mechanisms exist to assess potential costs, including non-monetary costs, resulting from expected or realized Artificial Intelligence (AI) and Autonomous Technologies (AAT)-related errors or system functionality and trustworthiness.
- AAT-04.3AATAI & Autonomous Technologies Targeted Application Scope
Mechanisms exist to specify and document the targeted application scope of the proposed use and operation of Artificial Intelligence (AI) and Autonomous Technologies (AAT).
- AAT-04.4AATAI & Autonomous Technologies Cost / Benefit Mapping
Mechanisms exist to map risks and benefits for all components of Artificial Intelligence (AI) and Autonomous Technologies (AAT), including third-party software and data.
- AAT-05AATAI & Autonomous Technologies Training
Mechanisms exist to ensure personnel and external stakeholders are provided with position-specific risk management training for Artificial Intelligence (AI) and Autonomous Technologies (AAT).
- AAT-06AATAI & Autonomous Technologies Fairness & Bias
Mechanisms exist to prevent Artificial Intelligence (AI) and Autonomous Technologies (AAT) from unfairly identifying, profiling and/or statistically singling out a segmented population defined by race, religion, gender identity, national origin, religion, disability or any other politically-charged identifier.
- AAT-07AATAI & Autonomous Technologies Risk Management Decisions
Mechanisms exist to leverage decision makers from a diversity of demographics, disciplines, experience, expertise and backgrounds for mapping, measuring and managing Artificial Intelligence (AI) and Autonomous Technologies (AAT)-related risks.
- AAT-07.1AATAI & Autonomous Technologies Impact Assessment
Mechanisms exist to assess the impact(s) of proposed Artificial Intelligence (AI) and Autonomous Technologies (AAT) on individuals, groups, communities, organizations and society (e.g., Fundamental Rights Impact Assessment (FRIA)).
- AAT-07.2AATAI & Autonomous Technologies Likelihood & Impact Risk Analysis
Mechanisms exist to define the potential likelihood and impact of each identified risk based on expected use and past uses of Artificial Intelligence (AI) and Autonomous Technologies (AAT) in similar contexts.
- AAT-07.3AATAI & Autonomous Technologies Continuous Improvements
Mechanisms exist to continuously improve Artificial Intelligence (AI) and Autonomous Technologies (AAT) capabilities to maximize benefits and minimize negative impacts associated with AAT.
- AAT-08AATAssigned Responsibilities for AI & Autonomous Technologies
Mechanisms exist to define and differentiate roles and responsibilities for: (1) Artificial Intelligence (AI) and Autonomous Technologies (AAT) configurations; and (2) Oversight of AAT systems.
- AAT-09AATAI & Autonomous Technologies Risk Profiling
Mechanisms exist to document the risks and potential impacts of Artificial Intelligence (AI) and Autonomous Technologies (AAT) that are: (1) Designed; (2) Developed; (3) Deployed; (4) Evaluated; and/or (5) Used.
- AAT-09.1AATAI & Autonomous Technologies High Risk Designations
Mechanisms exist to designate Artificial Intelligence (AI) and Autonomous Technologies (AAT) "High Risk" if one (1), or more, of the following criteria are met: (1) AAT is used as a safety component of a product or service; (2) AAT poses a significant risk of harm to an individual's health, safety or fundamental rights; and/or (3) AAT materially influences the outcome of an individual's decision making.
- AAT-10AATArtificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV)
Mechanisms exist to implement Artificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV) practices to enable Artificial Intelligence (AI) and Autonomous Technologies (AAT)-related security, resilience and compliance-related conformity testing throughout the lifecycle of the AAT.
- AAT-10.1AATAI TEVV Trustworthiness Assessment
Mechanisms exist to evaluate Artificial Intelligence (AI) and Autonomous Technologies (AAT) for trustworthy behavior and operation including security, anonymization and disaggregation of captured and stored data for approved purposes.
- AAT-10.10AATAI TEVV Results Evaluation
Mechanisms exist to evaluate the results of Artificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV) to determine the viability of the proposed Artificial Intelligence (AI) and Autonomous Technologies (AAT).
- AAT-10.11AATAI TEVV Effectiveness
Mechanisms exist to evaluate the effectiveness of the processes utilized to perform Artificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV).
- AAT-10.12AATAI TEVV Comparable Deployment Settings
Mechanisms exist to evaluate Artificial Intelligence (AI) and Autonomous Technologies (AAT)-related performance or the assurance criteria demonstrated for conditions similar to deployment settings.
- AAT-10.13AATAI TEVV Post-Deployment Monitoring
Mechanisms exist to proactively and continuously monitor deployed Artificial Intelligence (AI) and Autonomous Technologies (AAT).
- AAT-10.14AATUpdating AI & Autonomous Technologies
Mechanisms exist to integrate continual improvements for deployed Artificial Intelligence (AI) and Autonomous Technologies (AAT).
- AAT-10.15AATAI TEVV Reporting
Mechanisms exist to report the status and results of Artificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV) to relevant stakeholders, including governing bodies, as required.
- AAT-10.16AATAI TEVV Empirically Validated Methods
Mechanisms exist to evaluate claims of Artificial Intelligence (AI) and Autonomous Technologies (AAT) model capabilities using empirically validated methods.
- AAT-10.17AATAI TEVV Benchmarking Content Provenance
Mechanisms exist to benchmark the verifiable lineage and origin of content used by Artificial Intelligence (AI) and Autonomous Technologies (AAT) according to industry-recognized standards.
- AAT-10.18AATAI TEVV Model Collapse Mitigations
Mechanisms exist to mitigate concerns of model collapse by: (1) Assessing the proportion of synthetic to non-synthetic training data; and (2) Verifying training data is not overly homogenous or Artificial Intelligence (AI) and Autonomous Technologies (AAT) system-produced.
- AAT-10.19AATAI TEVV Third-Party Risk Management
Mechanisms exist to assess, approve and continuously monitor third-party Artificial Intelligence (AI) and Autonomous Technologies (AAT): (1) Components; (2) Application Programming Interfaces (APIs); and/or (3) Services used by AI agents for security, privacy and compliance.
- AAT-10.2AATAI TEVV Tools
Mechanisms exist to document test sets, metrics and details about the tools used during Artificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV) practices.
- AAT-10.3AATAI TEVV Trustworthiness Demonstration
Mechanisms exist to demonstrate the Artificial Intelligence (AI) and Autonomous Technologies (AAT) to be deployed are: (1) Valid; (2) Reliable; and (3) Operate as intended, based on approved designs.
- AAT-10.4AATAI TEVV Safety Demonstration
Mechanisms exist to demonstrate the Artificial Intelligence (AI) and Autonomous Technologies (AAT) to be deployed are safe, residual risk does not exceed the organization's risk tolerance and can fail safely, particularly if made to operate beyond its knowledge limits.
- AAT-10.5AATAI TEVV Security & Resiliency Assessment
Mechanisms exist to evaluate the security and resilience of Artificial Intelligence (AI) and Autonomous Technologies (AAT) to be deployed.
- AAT-10.6AATAI TEVV Transparency & Accountability Assessment
Mechanisms exist to examine risks associated with transparency and accountability of Artificial Intelligence (AI) and Autonomous Technologies (AAT) to be deployed.
- AAT-10.7AATAI TEVV Privacy Assessment
Mechanisms exist to examine the data privacy risk of Artificial Intelligence (AI) and Autonomous Technologies (AAT) to be deployed.
- AAT-10.8AATAI TEVV Fairness & Bias Assessment
Mechanisms exist to examine fairness and bias of Artificial Intelligence (AI) and Autonomous Technologies (AAT) to be deployed.
- AAT-10.9AATAI & Autonomous Technologies Model Validation
Mechanisms exist to validate the Artificial Intelligence (AI) and Autonomous Technologies (AAT) model.
- AAT-11AATRobust Stakeholder Engagement for AI & Autonomous Technologies
Mechanisms exist to compel ongoing engagement with relevant Artificial Intelligence (AI) and Autonomous Technologies (AAT) stakeholders to encourage feedback about positive, negative and unanticipated impacts.
- AAT-11.1AATAI & Autonomous Technologies Stakeholder Feedback Integration
Mechanisms exist to regularly collect, consider, prioritize and integrate risk-related feedback from those external to the team that developed or deployed Artificial Intelligence (AI) and Autonomous Technologies (AAT).
Powered by the Secure Controls Framework
The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.
© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer