The Governance OS for Autonomous AI.
What the AI SAFE² framework is.
AI SAFE² is a governance framework for autonomous AI systems, authored and published by Cyber Strategy Institute. Version 3.0 specifies 161 enforceable controls across five pillars, plus a ten-control Cross-Pillar Governance layer (CP.1–CP.10), and crosswalks every one of them to more than 32 regulatory and standards frameworks.
Where NIST AI RMF and ISO/IEC 42001 describe what good AI governance should achieve, AI SAFE² specifies the controls that produce it — and generates the evidence auditors ask for.
What version 3.0 actually contains
+
Five pillars carry the 161 controls. A sixth layer — Cross-Pillar Governance, CP.1 through CP.10 — governs the seams between them, where most real failures happen. Every control is mapped to more than 32 external frameworks, so implementing a control satisfies several obligations at once.
Who it is built for
+
Organizations that already have AI in production and cannot yet prove they govern it: CISOs answering board questions, compliance leaders facing an audit with no AI evidence, and the platform teams running agents against live systems today. If your agents can already act on production data, the framework applies to you now — not at your next planning cycle.
How agents are classified — Agent Capability Tiers
+
An Agent Capability Tier (ACT) classifies an AI agent by what it is actually capable of doing — not by how it is described in a design document. Control obligations scale to the tier, so a read-only assistant is not governed like an agent that can move money or change infrastructure.
For ACT-3 and ACT-4, CP.10 requires that human authority over consequential actions be cryptographically verified at the execution boundary — not assumed, and not recorded after the fact.
How you measure where you stand
+
The AI Sovereignty Maturity Score (AISM) places an organization on a five-step scale, so “are we governed?” becomes a number a board can track quarter over quarter.
- Framework
- AI SAFE² v3.0
- Author
- Cyber Strategy Institute
- Structure
- 161 controls · 5 pillars · CP.1–CP.10
- Mapped to
- 32+ frameworks
- Maturity scale
- AISM S0–S4
- Licence
- Published openly, citable with attribution
Five pillars. 161 controls. Zero ambiguity.
Controls that don't exist anywhere else.
The v3.0 Cross-Pillar Governance layer adds 10 controls that address the questions no other framework has answered yet.
Who authorized that sub-agent?
CP.9 enforces lineage control over agent spawning. Every sub-agent must inherit authorization from its parent chain and declare its own ACT tier. Unauthorized replication is prevented, not logged.
First-in-field · No equivalent in NIST, ISO, or OWASPHuman authority, enforced by architecture.
Human Execution Authority and Responsibility. CP.10 requires that for ACT-3 and ACT-4 systems, human authority is not assumed — it is cryptographically verified at the execution boundary before consequential actions complete.
First-in-field · ACT-3/ACT-4 deployment gateS0 to S4: Where does your organization stand?
The AI Sovereignty Maturity Score gives boards and CISOs a quantitative answer to "how well do we govern our AI?" S0 = no controls. S4 = deterministic enforcement at every execution boundary. Measurable. Auditable. Board-ready.
Integrated · Maps to all 32 compliance frameworks32 frameworks, mapped to the controls that satisfy them.
Common questions, straight answers.
What is the AI SAFE² framework?
+
AI SAFE² is a governance framework for autonomous AI systems, authored by Cyber Strategy Institute. Version 3.0 contains 161 controls across five pillars plus ten Cross-Pillar Governance controls (CP.1–CP.10), and maps to more than 32 regulatory frameworks including ISO/IEC 42001, NIST AI RMF, the EU AI Act, SOC 2 and CMMC 2.0. Its purpose is singular: move an organization from written policy to operational control of the AI actually running in its environment.
How is AI SAFE² different from NIST AI RMF or ISO/IEC 42001?
+
NIST AI RMF and ISO/IEC 42001 describe what good AI governance should achieve; AI SAFE² specifies the enforceable controls that produce it and crosswalks each one back to those standards, so the work you do here generates the evidence they ask for. It also covers two areas neither addresses: agent replication lineage (CP.9) and cryptographic verification of human authority at the execution boundary (CP.10, the HEAR Doctrine).
What is an Agent Capability Tier (ACT)?
+
An Agent Capability Tier (ACT) classifies an AI agent by what it is capable of doing, from ACT-1 (read-only, low consequence) through ACT-4 (autonomous, consequential, externally facing). Control obligations scale with the tier, and ACT-3 and ACT-4 systems must satisfy the HEAR Doctrine before a consequential action completes.
What is the HEAR Doctrine?
+
HEAR stands for Human Execution Authority and Responsibility. It requires that for ACT-3 and ACT-4 systems, human authority is cryptographically verified at the execution boundary rather than inferred from a workflow approval — closing the gap where an agent acts under authority nobody can prove was granted.
How do we know where our AI governance stands today?
+
The AI Sovereignty Maturity Score (AISM) places an organization on an S0–S4 scale, where S0 means no controls and S4 means deterministic enforcement at every execution boundary. Cyber Strategy Institute’s free assessment takes 8 minutes, requires no call, and returns an initial exposure score with your top three control gaps.
Is AI SAFE² free to use?
+
The framework is published openly and can be referenced and cited with attribution to Cyber Strategy Institute. The implementation toolkit — audit scorecard, roadmap, policy template and Risk Command Center guide — is available above, and developers can run the controls live via the AI SAFE² MCP server.
Where do we start?
+
Baseline first: the free AI governance assessment takes 8 minutes and no call is required. From there the toolkit turns your specific gaps into an implementation plan, and a Strategic Certainty Session produces a board-ready brief.
Download the AI SAFE² Implementation Toolkit
The complete v3.0 implementation package — audit scorecard, roadmap, enterprise policy template, Risk Command Center guide.
Download the Toolkit →Fork on GitHub
Apache 2.0. 161 controls. 6 production-ready packages. No gate. Build on it.
Fork on GitHub →Schedule an AI Governance Assessment
90 minutes with Vincent Sullivan. Board-ready risk visualization. Implementation roadmap. $2,500.
Book the Assessment →