The framework
- NIST AI 100-1 defines the core AI RMF; the Generative AI Profile (NIST AI 600-1) extends it.
- It is voluntary but frequently cited in US procurement and by third-party auditors as a maturity yardstick.
- The Measure function is about analysing, assessing and tracking AI risks with repeatable metrics.
- NIST AI 100-2e2025 provides the adversarial-ML taxonomy Provael names its attacks against (privacy attacks map to NISTAML.03).
Where a red-team result fits
Measure 2.7
The AI RMF subcategory “AI system security and resilience - as identified in the MAP function - are evaluated and documented” asks for exactly this evidence - Provael positions the measured ASR, its 95% CI and the benign-FPR control as the evaluation, and the SARIF + signed attestation bundle as the documentation.
Measure
Quantify AI risks and trustworthiness characteristics with repeatable, documented methods - an ASR with a CI and a benign control fits directly.
Manage
Prioritise and act on measured risks; a CI red-team gate operationalises the Manage function in the development loop.
Evidence produced
- Measure: an attack-success rate with a benign control and confidence interval, tracked over time.
- Manage: a CI gate that acts on the measurement and blocks regressions.
- Documentation and reproducible traces supporting the Govern function’s evidence trail.
Dates (verified 26 Jul 2026)
- AI RMF 1.0 released
- January 2023
- Generative AI Profile
- July 2024
Not legal advice; verify the live EUR-Lex/ISO text at launch before relying on these dates.
Primary references
What it is - and isn’t
- adversarial-only - Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.
- evidence-not-certification - The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
- behavioural-not-worst-case - Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.
Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.
Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.
Clause references are indicative; a wrong clause citation is worse than a missing one.
Turn this into filed evidence.
Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.