1. ETSI
1.1. EN 304 223 - Securing Artificial Intelligence (SAI); Baseline Cyber Security Requirements for AI Models and Systems
1.1.1. Provision 5.4.2-1
1.1.2. Provision 5.4.2-2
1.1.3. Provision 5.4.2-3
1.1.4. Provision 5.4.2-4
1.2. TR 104 128 - Securing Artificial Intelligence (SAI); Guide to Cyber Security for AI Models and Systems
1.2.1. Provision 5.4.2-1
1.2.2. Provision 5.4.2-2
1.2.3. Provision 5.4.2-3
1.2.4. Provision 5.4.2-4
1.3. TR 104 048 - Securing Artificial Intelligence (SAI); Data Supply Chain Security
1.3.1. 6.1.2 Cybersecurity hygiene - 7
1.3.2. 6.5 Analysis - Logging
1.4. TR 104 222 - Securing Artificial Intelligence; Mitigation Strategy Report
1.4.1. 6.2.3 - 3
1.4.2. 6.3.3 - 1
1.4.3. 6.3.3 - 3
1.5. SAI 002 - Securing Artificial Intelligence (SAI); Data Supply Chain Security
1.5.1. 6.1.2 Cybersecurity hygiene - 7
1.5.2. 6.5 - Logging
2. NIST
2.1. AI RMF 1.0
2.1.1. MEASURE 2.4
2.1.2. MANAGE 3.1
2.1.3. MANAGE 3.2
2.1.4. MANAGE 4.1
2.2. SP 800-218A
2.2.1. PO.5.1
2.2.2. PO.5.3
2.2.3. RV.1.1
2.2.4. RV.2.1
2.3. AI 800-1
2.3.1. Practice 5.1: Implement safeguards proportionate to the model’s misuse risk - 1
2.3.2. Practice 6.1: Monitor for evidence of misuse - 1
2.3.3. Practice 6.1: Monitor for evidence of misuse - 2
2.3.4. Practice 6.1: Monitor for evidence of misuse - 5
2.3.5. Practice 6.1: Monitor for evidence of misuse - 6
2.4. IR 8596: Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile): NIST Community Profile
2.4.1. PR.PS-04
2.4.2. PR.PS-06
2.4.3. DE.CM-01
2.4.4. DE.CM-02
2.4.5. DE.CM-03
2.4.6. DE.CM-06
2.4.7. DE.CM-09
2.4.8. DE.AE-02
2.4.9. DE.AE-03
2.4.10. DE.AE-04
2.4.11. RS.AN-03
2.4.12. RS.AN-07
2.5. AI 100-2e2025: Adversarial Machine Learning A Taxonomy and Terminology of Attacks and Mitigations
2.5.1. 3.3.3 Direct Prompting Attacks - Interventions during deployment (5) - Detecting and terminating harmful interactions
2.5.2. 3.3.3 Direct Prompting Attacks - Interventions during deployment (5) - Monitoring and response
3. OWASP
3.1. OWASP Top 10 for Agentic Applications for 2026
3.1.1. ASI01: Agent Goal Hijack - 7
3.1.2. ASI02: Tool Misuse and Exploitation - 8
3.1.3. ASI03: Identity and Privilege Abuse - 9
3.1.4. ASI04: Agentic Supply Chain Vulnerabilities - 4
3.1.5. ASI04: Agentic Supply Chain Vulnerabilities - 6
3.1.6. ASI05: Unexpected Code Execution (RCE) - 7
3.1.7. ASI06: Memory & Context Poisoning - 2
3.1.8. ASI08: Cascading Failures - 8
3.1.9. ASI08: Cascading Failures - 10
3.1.10. ASI09: Human-Agent Trust Exploitation - 2
3.1.11. ASI09: Human-Agent Trust Exploitation - 3
3.1.12. ASI09: Human-Agent Trust Exploitation - 9
3.1.13. ASI10: Rogue Agents - 1
3.1.14. ASI10: Rogue Agents - 3
3.2. LLM Top 10
3.2.1. LLM03: Supply Chain - 7
3.2.2. LLM04: Data and Model Poisoning - 9
3.2.3. LLM05: Improper Data Handling - 7
3.2.4. LLM08: Vector and Embedding Weaknesses - 4
3.2.5. LLM09: Misinformation - 4
3.2.6. LLM10: Unbounded Consumption - 7
3.2.7. LLM10: Unbounded Consumption - 8
3.3. OWASP Model Context Protocol (MCP) Top 10
3.3.1. MCP01:2025 - Token Mismanagement and Secret Exposure - 4
3.3.2. MCP03:2025 - Tool Poisoning - 10
3.3.3. MCP07:2025 – Insufficient Authentication & Authorization - 6
3.3.4. MCP08:2025 – Lack of Audit and Telemetry - 1
3.3.5. MCP08:2025 – Lack of Audit and Telemetry - 2
3.3.6. MCP08:2025 – Lack of Audit and Telemetry - 3
3.3.7. MCP08:2025 – Lack of Audit and Telemetry - 4
3.3.8. MCP08:2025 – Lack of Audit and Telemetry - 5
3.3.9. MCP08:2025 – Lack of Audit and Telemetry - 6
3.3.10. MCP08:2025 – Lack of Audit and Telemetry - 7
3.3.11. MCP08:2025 – Lack of Audit and Telemetry - 8
3.3.12. MCP08:2025 – Lack of Audit and Telemetry - 9
3.3.13. MCP08:2025 – Lack of Audit and Telemetry - 10
3.3.14. MCP09:2025 – Shadow MCP Servers - 5
3.3.15. MCP09:2025 – Shadow MCP Servers - 8
3.3.16. MCP09:2025 – Shadow MCP Servers - 11
4. MITRE
4.1. ATLAS Framework
4.1.1. AML.M0024 - AI Telemetry Logging
4.2. SAFE-AI
4.2.1. Zero-day exploits
5. Multi Agency
5.1. Guidelines for secure AI system development
5.1.1. Monitor your system’s behaviour
5.1.2. Monitor your system’s inputs
6. Personal Data Protection Commission Singapore (PDPC)
6.1. Model Artificial Intelligence Governance Framework Second Edition
6.1.1. 1. Clear roles and responsibilities for the ethical deployment of AI - c) (ii)
6.1.2. 2. Risk management and internal controls - b) (ii)
6.1.3. Repeatability - b)
6.1.4. Repeatability - e)
7. Google
7.1. Secure AI Framework
7.1.1. Agent Observability
7.1.2. Vulnerability Management
7.1.3. Threat Detection
8. CoSAI
8.1. Establish Risks and Controls for the AI Supply Chain
8.1.1. 3.2.1 Supply Chain Security for Data - Vector Space Attacks
8.1.2. 3.2.2 Model - Data Drift
8.1.3. 3.2.4 Infrastructure - Feedback Loop Exploitation
8.2. AI Incident Response Framework
8.2.1. 3.2. Monitoring and Telemetry
8.2.2. 3.3.1. Preparation Phase - Monitoring Infrastructure
8.2.3. 3.3.2. Detection and Analysis Phase - Detection Mechanisms - Automated Monitoring
8.2.4. 3.3.2. Detection and Analysis Phase - Initial Triage - Incident Verification
8.2.5. 3.3.3. Containment, Eradication, and Recovery Phase - Recovery Procedures - Enhanced Monitoring
8.3. Model Context Protocol (MCP) Security
8.3.1. 3.2.10 Logging
9. Microsoft
9.1. Cloud Adoption Framework - Secure AI
9.1.1. Detect AI security threats 1 - Deploy automated AI risk detection across your environment
9.1.2. Detect AI security threats 3 - Implement platform-specific monitoring strategies
9.2. Responsible AI Standard
9.2.1. RS1.8
9.2.2. RS3.2
10. IBM
10.1. IBM Framework for Securing Generative AI
10.1.1. Establish governance
11. Cloud Security Alliance (CSA)
11.1. AI Controls Matrix
11.1.1. AIS-03
11.1.2. CCC-07
11.1.3. CEK-16
11.1.4. CEK-21
11.1.5. DCS-10
11.1.6. IAM-12
11.1.7. IAM-13
11.1.8. I&S-02
11.1.9. I&S-06
11.1.10. LOG-01
11.1.11. LOG-03
11.1.12. LOG-05
11.1.13. LOG-07
11.1.14. LOG-10
11.1.15. LOG-11
11.1.16. LOG-12
11.1.17. LOG-13
11.1.18. LOG-14
11.1.19. LOG-15
11.1.20. MDS-10
11.1.21. SEF-05
11.1.22. TVM-10
12. OpenAI
12.1. Preparedness Framework
12.1.1. Safeguards Against Malicious Users - Usage Monitoring
12.2. Safety Best Practices
12.2.1. Implement safety identifiers
13. CISA
13.1. Principles for the Secure Integration of Artificial Intelligence in Operational Technology
13.1.1. 4.1.3 - Implement anomaly detection and behavioral analytics
13.1.2. 4.1.5 - Continuously validate and refine AI models in simulated environments before deployment
14. NCSC/NSA/CISA etc
14.1. AI Data Security
14.1.1. 4.3 Input and Output Monitoring
15. SANS
15.1. Critical AI Security Guidelines
15.1.1. 5 Monitoring
15.1.2. 7.1 Capture Audit Trails Across the Stack
15.1.3. 7.2 Monitor for Indicators of Model Tampering
15.1.4. 7.3 Employ Detection on Prompt and Output Layers
16. OECD
16.1. Due Diligence Guidance for Responsible AI
16.1.1. Step 4 - Track implementation and results of due diligence activities
17. IMDA
17.1. Model AI Governance Framework for Agentic AI
17.1.1. 2.2.2 Design for meaningful human oversight - 3
17.1.2. 2.3.3 When deploying, continuously monitor and test - Continuous testing and monitoring - 1
17.1.3. 2.3.3 When deploying, continuously monitor and test - Continuous testing and monitoring - 2
18. SDAIA (Saudi Arabia)
18.1. AI Ethics Principles
18.1.1. Principle 2 – Privacy & Security - Deploy and Monitor - 1
18.1.2. Principle 5 – Reliability & Safety - Deploy and Monitor - 1
18.1.3. Principle 5 – Reliability & Safety - Deploy and Monitor - 2
18.1.4. Principle 7 – Accountability & Responsibility - Deploy and Monitor - 1
18.1.5. Principle 7 – Accountability & Responsibility - Deploy and Monitor - 2
19. Cyber Security Council (UAE)
19.1. National Cyber Security Policy for Artificial Intelligence
19.1.1. 2.5.2
19.1.2. 2.6.1
19.1.3. 2.6.3
19.1.4. 3.2.6 Network Security for AI/ML Infrastructure - 7
19.1.5. 3.5.2 Defending Against AI/ML Attacks - 1
19.1.6. 3.5.2 Defending Against AI/ML Attacks - 4
19.1.7. 3.6.1 AI/ML Security Analytics - 1
19.1.8. 3.6.1 AI/ML Security Analytics - 2
19.1.9. 3.6.1 AI/ML Security Analytics - 3
19.1.10. 3.6.1 AI/ML Security Analytics - 4
19.1.11. 3.6.1 AI/ML Security Analytics - 5
19.1.12. 3.6.3 Digital Forensics for AI/ML Security Incidents - 1
20. Smart Dubai (UAE)
20.1. AI Ethics Principles & Guidelines
20.1.1. 1.2.2.7
20.1.2. 1.3.1.3
21. Central Bank of the UAE
21.1. Guidance Note on the Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions in the U.A.E
21.1.1. 6. Continuous Monitoring and Review - a
21.1.2. 6. Continuous Monitoring and Review - b
22. Qatar Central Bank
22.1. Artificial Intelligence Guidelines
22.1.1. 7.9
22.1.2. 12.7
22.1.3. 13.6.4
22.1.4. 13.7.2
22.1.5. 15.15
22.1.6. 17.2
22.1.7. 17.9
22.1.8. 19.1
22.1.9. 19.2
22.1.10. 19.3
22.1.11. 19.3.1
23. MIC/METI (Japan)
23.1. AI Guidelines for Business
23.1.1. Transparency - 1 (a)
23.1.2. Transparency - 1 (b)
24. METI (Japan)
24.1. Governance Guidelines for Implementation of AI Principles
24.1.1. Action Target 4-2
25. EU
25.1. EU AI Act
25.1.1. 12.1 Record Keeping
25.1.2. 12.2 Record Keeping
25.1.3. 12.3 Record Keeping
25.1.4. 19.1 Automatically Generated Logs
25.1.5. 19.2 Automatically Generated Logs
25.1.6. 26.1 Obligations of deployers of high-risk AI systems
25.1.7. 26.6 Obligations of deployers of high-risk AI systems
25.1.8. 72.1 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
25.1.9. 72.2 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
25.1.10. 72.3 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
25.1.11. 72.4 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
26. ISO/IEC
26.1. DIS 27090
26.1.1. 7.5
26.2. DIS 24970
26.2.1. 5.1
26.2.2. 5.2
26.2.3. 5.3
26.2.4. 5.4
26.2.5. 5.5
26.2.6. 6.4
26.2.7. 7.2
26.2.8. 7.3
26.2.9. 8
26.2.10. 9
27. CEN/CENELEC
27.1. prEN 40000-1-2: Cybersecurity requirements for products with digital elements - Part 1-2: Principles for cyber resilience
27.1.1. 7.7
27.1.2. 7.9
28. Databricks
28.1. The Databricks AI Security Framework
28.1.1. DASF 14: Audit actions performed on datasets
28.1.2. DASF 19: Manage end-to-end machine learning lifecycle
28.1.3. DASF 20: Track ML training runs
28.1.4. DASF 21: Monitor data and AI system from a single pane of glass
28.1.5. DASF 32: Govern and monitor access of AI model and model serving endpoints
28.1.6. DASF 35: Track model performance
28.1.7. DASF 36: Set up monitoring alerts
28.1.8. DASF 37: Set up inference tables for monitoring and debugging models
28.1.9. DASF 55: Monitor audit logs
28.1.10. DASF 65: Implement end-to-end AI traceability
29. World Economic Forum
29.1. Presidio AI Framework: Towards Safe Generative AI Models
29.1.1. Model drift monitoring and watermarking
30. ENISA
30.1. Multilayer Framework for Good Cybersecurity Practices for AI
30.1.1. Evasion
30.1.2. From the lab to the market 4
30.1.3. From the lab to the market 6
30.1.4. Networking 7
30.1.5. Infrastructure 1
30.1.6. Regulation 1
31. ICO
31.1. Guidance on the AI Auditing Framework - Draft guidance for consultation
31.1.1. What steps should we take to manage the risks of privacy attacks on AI models? - 2
31.1.2. Detective Controls - 1
31.1.3. Detective Controls - 3
32. ISO
32.1. 42001:2023 - Information technology — Artificial intelligence — Management system
32.1.1. 4.4
32.1.2. 9.1