STALE MEASUREMENTNewest real-model measurement: 26 days old, measured with v0.32.0; 7 releases have shipped since, past this project’s own 7-day window. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart

STALE CLOCKThe regulatory entries on this page were last checked against their primary sources on 39 days before this build’s anchor of , past this project’s own 30-day window. Every date here was true when it was read and has not been re-read since. Verify against the primary source before relying on it. The clock, with every source

EVIDENCE, MAPPED · lead hook: EU MACHINERY REG · 20 JAN 2027

Your result, crosswalked to the rules that are arriving.

A Provael report maps each finding to the frameworks buyers and regulators cite. Dates verified against EUR-Lex and ISO on 26 Jul 2026 - always confirm the current legal text.

Evidence, not certification.Independent · not affiliated with ISO, the EU, NIST, IEC, OWASP or MITRE
Evidence, not certification

Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.

Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

Framework crosswalk

Framework crosswalk · each framework links to its detail page
FrameworkWhat Provael maps to itTiming
EU AI Act · Article 15Accuracy, robustness & cybersecurity evidence for high-risk AI.Applies 2 Aug 2028 (Annex I, product-embedded)
· was 2 Aug 2027; deferred by the adopted AI Digital Omnibus
EU Machinery Regulation 2023/1230lead hookRobustness evidence for AI-driven machinery safety functions.Applies 20 Jan 2027
IEC 61508 · functional safetyAdversarial-robustness input to a systematic-capability argument.In force · maintained series
ISO 13849-1/-2 · safety-related parts of control systemsAdversarial fault cases for the Part 2 validation argument.In force · maintained series
ISO 25785-1 · dynamically stable robotsAnticipatory: balance and fall hazards, measured before the standard lands.Committee Draft (ISO/CD)
· not published; no fixed date
ISO 10218-1/-2:2025Cybersecurity clauses for industrial robots & integration.Published 5 Feb 2025
NIST AI RMFMeasure & Manage functions for AI risk.Referenced by auditors
ISO/IEC TR 5469:2024AI functional safety: adversarial V&V evidence for an AI element in a safety function.Published Jan 2024 · technical report, not certifiable
ISO/IEC 23894:2023AI risk management: the EAI taxonomy as risk context, measured rates as assessment input.Published 6 Feb 2023 · guidance, not certifiable
ISO/IEC 42001:2023AI management system: red-teaming as an operational control.Published Dec 2023
IEC 62443Industrial security levels for automation & control systems.Referenced by auditors
EU Cyber Resilience Act 2024/2847Software security posture: SBOM, vulnerability handling, secure-by-default, support period.Reporting 11 Sep 2026 · full 11 Dec 2027

How to read every row

Each mapping carries the same three caveats. Read them before you cite a clause.

adversarial-only

Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.

evidence-not-certification

The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.

behavioural-not-worst-case

Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.

What an assessment emits

Every output is an open, tool-ingestible format - the evidence you file, not a certificate.

Evidence outputs · open formats, ingestible by standard GRC and code-scanning tools
OutputFormatWhat it isStandard
SARIF reportSARIF 2.1.0Findings that drop straight into GitHub code scanning; each is tagged with its EAIxx ruleId.OASIS SARIF 2.1.0 · GitHub code scanning
OSCAL assessment-resultsOSCAL JSONMachine-readable assessment results for GRC / ATO tooling.NIST OSCAL
ML-BOMCycloneDX ML-BOM 1.6A machine-learning bill of materials for the policy under test; ingests into OWASP Dependency-Track.CycloneDX 1.6 · maps to EU AI Act Art. 11 / Annex IV
AVID recordAVID recordAn AI Vulnerability Database record. Submission is gated and manual - never auto-submitted.avidml.org
AttestationDSSE-style envelope · assurance profilesA signed statement over the run: SHA-256 always, plus an optional Ed25519 signature that verifies offline. With --profile it embeds a standards-aligned assurance view - ISO 10218-2:2025 cyber-risk evidence routed to IEC 62443 SL2, an insurer summary (per-family ASR + 95% Wilson CI + benign-FPR + the honest which-families-transfer table), or a third-party cert-readiness cross-reference. Evidence, not certification.DSSE-style · SHA-256 + optional Ed25519 · ISO 10218-2 / IEC 62443 / insurer profiles
ScorecardOne-page PDF / HTMLA PASS/FAIL summary against your ASR threshold, an EAI heatmap, and per-attack 95% confidence intervals.Provael scorecard
certify dossierOSCAL + print-to-PDF HTMLThe conformity-assessment evidence dossier for an ML-based safety component, built by the provael certify command.OSCAL assessment-results + self-contained HTML
Redacted sample evidence pack
SARIF 2.1.0 + summary · the artifact an assessment delivers · redacted for public use
Machine-readable crosswalks

Take the artifact, not just the page

Each file below maps the Embodied AI Security Top 10 onto an external benchmark or framework, as JSON you can diff and file. Every one is authored by Provael alone: naming a benchmark or a standards body here is not an affiliation, an endorsement or a certification, and none is implied in either direction.

A crosswalk states how categories line up. It does not state that the numbers are comparable — and where two projects measure different things, the artifact records the incomparability rather than joining them.

  • MITRE ATLAS

    JSON ↓ 9 KB

    mapping_statusproposed — authored by Provael, not reviewed or endorsed by MITRE

    Maps Embodied AI Security Top 10 entries onto ATLAS techniques with coverage counts. A mapping, not an ATLAS listing: MITRE has neither reviewed nor accepted it.

  • ForesightSafety-VLA

    JSON ↓ 14 KB

    mapping_statusproposed — authored by Provael, not reviewed or endorsed by the ForesightSafety-VLA authors

    Per-category coverage and the disagreement between the two frames, computed rather than asserted. Provael derives its counterparts to their cost metrics from a per-step boolean, not a continuous cost integrated over their simulator — comparable in shape, not in number.

    Counterpart: arXiv:2606.27079

  • RoboJailBench

    JSON ↓ 13 KB

    mapping_statusnot declared in this artifact — the posture is stated on its crosswalk card ↗ and is not supplied here, because inventing one is the overclaim the field exists to prevent

    Bidirectional taxonomy mapping with coverage counts. A `covered` row means a Provael family measures that harm class in simulation with a benign-FPR control — a sim proxy, mostly stub-validated. Read the transfer status with any number, never the number alone.

    Counterpart: arXiv:2605.19328

  • SafeVLA-Bench

    JSON ↓ 4 KB

    mapping_statusproposed — taxonomy comparability only; NO metric comparison is emitted, and the blocker that prevents one is recorded in the artifact

    The category mapping ships and the numeric comparison deliberately does not. The artifact carries the blocker that prevents joining the numbers, so a consumer can see why rather than assume it was an oversight.

    Counterpart: arXiv:2606.00773

  • VLA-Arena

    JSON ↓ 6 KB

    mapping_statusproposed — authored by Provael, not reviewed or endorsed by the VLA-Arena authors

    Records which Provael families map onto their safety suites and, explicitly, which do not. The two are not comparable and the artifact says why — the reason is posture, not units.

    Counterpart: arXiv:2512.22539

1 of 5 artifacts declare no mapping_status field of their own; those are marked above rather than given one. Artifacts are copied verbatim from results/crosswalk/ in the product repository, which stays the source of truth. XPolicyLab is deliberately absent: it has a crosswalk card whose own status is cited, not crosswalked and it ships no artifact, so listing it here would present a planned integration as a delivered one.

Need this mapped to your system?

Book an Embodied-AI Red-Team Assessment and receive an evidence pack you can file, with the crosswalk filled in for your policy.