Your result, crosswalked to the rules that are arriving.
A Provael report maps each finding to the frameworks buyers and regulators cite. Dates verified against EUR-Lex and ISO on 26 Jul 2026 - always confirm the current legal text.
Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.
Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.
Framework crosswalk
| Framework | What Provael maps to it | Timing |
|---|---|---|
| EU AI Act · Article 15 | Accuracy, robustness & cybersecurity evidence for high-risk AI. | Applies 2 Aug 2028 (Annex I, product-embedded) · was 2 Aug 2027; deferred by the adopted AI Digital Omnibus |
| EU Machinery Regulation 2023/1230lead hook | Robustness evidence for AI-driven machinery safety functions. | Applies 20 Jan 2027 |
| IEC 61508 · functional safety | Adversarial-robustness input to a systematic-capability argument. | In force · maintained series |
| ISO 13849-1/-2 · safety-related parts of control systems | Adversarial fault cases for the Part 2 validation argument. | In force · maintained series |
| ISO 25785-1 · dynamically stable robots | Anticipatory: balance and fall hazards, measured before the standard lands. | Committee Draft (ISO/CD) · not published; no fixed date |
| ISO 10218-1/-2:2025 | Cybersecurity clauses for industrial robots & integration. | Published 5 Feb 2025 |
| NIST AI RMF | Measure & Manage functions for AI risk. | Referenced by auditors |
| ISO/IEC TR 5469:2024 | AI functional safety: adversarial V&V evidence for an AI element in a safety function. | Published Jan 2024 · technical report, not certifiable |
| ISO/IEC 23894:2023 | AI risk management: the EAI taxonomy as risk context, measured rates as assessment input. | Published 6 Feb 2023 · guidance, not certifiable |
| ISO/IEC 42001:2023 | AI management system: red-teaming as an operational control. | Published Dec 2023 |
| IEC 62443 | Industrial security levels for automation & control systems. | Referenced by auditors |
| EU Cyber Resilience Act 2024/2847 | Software security posture: SBOM, vulnerability handling, secure-by-default, support period. | Reporting 11 Sep 2026 · full 11 Dec 2027 |
The Cyber Resilience Act's Article 14 reporting duties run on a clock measured in hours, not the crosswalk's years. What happens in the first 24 hours after an exploited vulnerability is reported to you.
Not legal advice; verify the live EUR-Lex / ISO text before relying on these dates (re-verified 26 July 2026). The EU Machinery Regulation 2023/1230 applies 20 January 2027 (Art. 54, as corrected by the Corrigendum of 4 July 2023). Regulation (EU) 2026/1744 (the Digital Omnibus on AI, published OJ 24 July 2026 and in force 27 July 2026) defers Annex I product-embedded high-risk AI from 2 August 2027 to 2 August 2028, and moves stand-alone Annex III high-risk to 2 December 2027. It also moves Machinery Regulation 2023/1230 from AI Act Annex I Section A to Section B, so AI Act Chapter III (including Art. 15) no longer applies directly to AI-enabled machinery - the Commission carries those requirements across by delegated acts amending Machinery Regulation Annex III, applicable by 2 August 2028.
How to read every row
Each mapping carries the same three caveats. Read them before you cite a clause.
Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.
The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.
Every date cited on this page is published as a dated, source-linked record at /regulatory-clock (and as JSON), with an explicit statement per instrument of what a Provael run does and does not establish.
Clause references are indicative; a wrong clause citation is worse than a missing one.
Provael is built and maintained by one person. That is a real dependency for anything you rely on, so it is stated here rather than left to the About page: the tool is Apache-2.0 and forkable, every result is reproducible from a committed recipe, and no evidence you already hold stops being valid if this project does. What a single maintainer cannot offer is a service level, and none is published for that reason.
What an assessment emits
Every output is an open, tool-ingestible format - the evidence you file, not a certificate.
| Output | Format | What it is | Standard |
|---|---|---|---|
| SARIF report | SARIF 2.1.0 | Findings that drop straight into GitHub code scanning; each is tagged with its EAIxx ruleId. | OASIS SARIF 2.1.0 · GitHub code scanning |
| OSCAL assessment-results | OSCAL JSON | Machine-readable assessment results for GRC / ATO tooling. | NIST OSCAL |
| ML-BOM | CycloneDX ML-BOM 1.6 | A machine-learning bill of materials for the policy under test; ingests into OWASP Dependency-Track. | CycloneDX 1.6 · maps to EU AI Act Art. 11 / Annex IV |
| AVID record | AVID record | An AI Vulnerability Database record. Submission is gated and manual - never auto-submitted. | avidml.org |
| Attestation | DSSE-style envelope · assurance profiles | A signed statement over the run: SHA-256 always, plus an optional Ed25519 signature that verifies offline. With --profile it embeds a standards-aligned assurance view - ISO 10218-2:2025 cyber-risk evidence routed to IEC 62443 SL2, an insurer summary (per-family ASR + 95% Wilson CI + benign-FPR + the honest which-families-transfer table), or a third-party cert-readiness cross-reference. Evidence, not certification. | DSSE-style · SHA-256 + optional Ed25519 · ISO 10218-2 / IEC 62443 / insurer profiles |
| Scorecard | One-page PDF / HTML | A PASS/FAIL summary against your ASR threshold, an EAI heatmap, and per-attack 95% confidence intervals. | Provael scorecard |
| certify dossier | OSCAL + print-to-PDF HTML | The conformity-assessment evidence dossier for an ML-based safety component, built by the provael certify command. | OSCAL assessment-results + self-contained HTML |
Take the artifact, not just the page
Each file below maps the Embodied AI Security Top 10 onto an external benchmark or framework, as JSON you can diff and file. Every one is authored by Provael alone: naming a benchmark or a standards body here is not an affiliation, an endorsement or a certification, and none is implied in either direction.
A crosswalk states how categories line up. It does not state that the numbers are comparable — and where two projects measure different things, the artifact records the incomparability rather than joining them.
MITRE ATLAS
JSON ↓ 9 KBmapping_statusproposed — authored by Provael, not reviewed or endorsed by MITRE
Maps Embodied AI Security Top 10 entries onto ATLAS techniques with coverage counts. A mapping, not an ATLAS listing: MITRE has neither reviewed nor accepted it.
ForesightSafety-VLA
JSON ↓ 14 KBmapping_statusproposed — authored by Provael, not reviewed or endorsed by the ForesightSafety-VLA authors
Per-category coverage and the disagreement between the two frames, computed rather than asserted. Provael derives its counterparts to their cost metrics from a per-step boolean, not a continuous cost integrated over their simulator — comparable in shape, not in number.
Counterpart: arXiv:2606.27079
RoboJailBench
JSON ↓ 13 KBmapping_statusnot declared in this artifact — the posture is stated on its crosswalk card ↗ and is not supplied here, because inventing one is the overclaim the field exists to prevent
Bidirectional taxonomy mapping with coverage counts. A `covered` row means a Provael family measures that harm class in simulation with a benign-FPR control — a sim proxy, mostly stub-validated. Read the transfer status with any number, never the number alone.
Counterpart: arXiv:2605.19328
SafeVLA-Bench
JSON ↓ 4 KBmapping_statusproposed — taxonomy comparability only; NO metric comparison is emitted, and the blocker that prevents one is recorded in the artifact
The category mapping ships and the numeric comparison deliberately does not. The artifact carries the blocker that prevents joining the numbers, so a consumer can see why rather than assume it was an oversight.
Counterpart: arXiv:2606.00773
VLA-Arena
JSON ↓ 6 KBmapping_statusproposed — authored by Provael, not reviewed or endorsed by the VLA-Arena authors
Records which Provael families map onto their safety suites and, explicitly, which do not. The two are not comparable and the artifact says why — the reason is posture, not units.
Counterpart: arXiv:2512.22539
1 of 5 artifacts declare no mapping_status field of their own; those are marked above rather than given one. Artifacts are copied verbatim from results/crosswalk/ in the product repository, which stays the source of truth. XPolicyLab is deliberately absent: it has a crosswalk card whose own status is cited, not crosswalked and it ships no artifact, so listing it here would present a planned integration as a delivered one.
Need this mapped to your system?
Book an Embodied-AI Red-Team Assessment and receive an evidence pack you can file, with the crosswalk filled in for your policy.