STALE MEASUREMENTNewest real-model measurement: 26 days old, measured with v0.32.0; 7 releases have shipped since, past this project’s own 7-day window. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart

STALE CLOCKThe regulatory entries on this page were last checked against their primary sources on 39 days before this build’s anchor of , past this project’s own 30-day window. Every date here was true when it was read and has not been re-read since. Verify against the primary source before relying on it. The clock, with every source

NIST AI 100-1 · Generative AI Profile (NIST AI 600-1)

NIST AI RMF

The NIST AI Risk Management Framework is a voluntary, widely-adopted structure for identifying and managing AI risk across four functions: Govern, Map, Measure, Manage. Provael produces evidence for the Measure and Manage functions.

Voluntary framework; widely referenced by auditors and procurement.Evidence, not certification.
What it is

The framework

  • NIST AI 100-1 defines the core AI RMF; the Generative AI Profile (NIST AI 600-1) extends it.
  • It is voluntary but frequently cited in US procurement and by third-party auditors as a maturity yardstick.
  • The Measure function is about analysing, assessing and tracking AI risks with repeatable metrics.
  • NIST AI 100-2e2025 provides the adversarial-ML taxonomy Provael names its attacks against (privacy attacks map to NISTAML.03).
The hook

Where a red-team result fits

Measure 2.7

The AI RMF subcategory “AI system security and resilience - as identified in the MAP function - are evaluated and documented” asks for exactly this evidence - Provael positions the measured ASR, its 95% CI and the benign-FPR control as the evaluation, and the SARIF + signed attestation bundle as the documentation.

Measure

Quantify AI risks and trustworthiness characteristics with repeatable, documented methods - an ASR with a CI and a benign control fits directly.

Manage

Prioritise and act on measured risks; a CI red-team gate operationalises the Manage function in the development loop.

What Provael maps to it

Evidence produced

  • Measure: an attack-success rate with a benign control and confidence interval, tracked over time.
  • Manage: a CI gate that acts on the measurement and blocks regressions.
  • Documentation and reproducible traces supporting the Govern function’s evidence trail.
Timing

Dates (verified 26 Jul 2026)

AI RMF 1.0 released
January 2023
Generative AI Profile
July 2024
How to read this mapping

What it is - and isn’t

  • adversarial-only - Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.
  • evidence-not-certification - The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
  • behavioural-not-worst-case - Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.
Evidence, not certification

Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.

Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

Clause references are indicative; a wrong clause citation is worse than a missing one.

Turn this into filed evidence.

Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.