The framework
- A Technical Report from ISO/IEC JTC 1/SC 42, published January 2024 and applicable across sectors rather than tied to one.
- It covers three distinct situations, and they are not interchangeable: AI used inside a safety-related function, non-AI safety functions used to constrain AI-controlled equipment, and AI used to design or develop a safety function.
- A TR is informative. It carries no clauses you can be certified against, so nothing here is a conformity route - it is vocabulary and method that a safety argument can cite.
- Related: ISO/IEC 23894:2023 (AI risk management) and ISO/IEC 42001:2023 (AI management system). TR 5469 is the functional-safety-facing one of the three.
Where a red-team result fits
Verification & validation of an AI element
AI — Functional safety and AI systems (verification & validation evidence) - an adversarial-robustness rate with a matched benign control is V&V evidence about the element, produced repeatably. It is one input to the AI-safety lifecycle, not a determination within it.
Evidence produced
- An attack-success rate per EAI risk with a 95% interval and a benign false-positive control, as V&V evidence for the AI element.
- The benign control is the part a functional-safety reviewer will ask for first: a rate with no baseline cannot separate an induced failure from a noisy detector.
- Retained, digest-bound run artifacts (report.json#/by_attack and report.json#/benign_fpr) so the evidence can be re-checked rather than taken on trust.
Dates (verified 26 Jul 2026)
- Published
- January 2024ISO/IEC JTC 1/SC 42; verified 10 Aug 2026
Not legal advice; verify the live EUR-Lex/ISO text at launch before relying on these dates.
What it is - and isn’t
- adversarial-only - Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.
- evidence-not-certification - The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
- behavioural-not-worst-case - Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.
Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.
Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.
Clause references are indicative; a wrong clause citation is worse than a missing one.
Turn this into filed evidence.
Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.