OSAFIS Relationship to Existing Frameworks
On this page
OSAFIS should interoperate with established AI security resources. Its proposed contribution is a contract-centred representation that connects a finding to analytical domains, actual system relationships and evidence. Whether that representation improves research or assessment practice is an empirical question. The existence of nine domains does not establish a coverage advantage, and an external resource need not adopt these domains to address a relevant threat.
This document distinguishes descriptions supported by external sources from OSAFIS mapping judgements. It records a source snapshot checked on 7 September 2026. Mappings below are provisional interpretations, not endorsements, certification crosswalks or proofs that the resources are equivalent.
Resources and their distinct purposes
NIST AI 100-2 E2025 provides adversarial machine-learning terminology organised around factors including learning methods, lifecycle stages and attacker goals, capabilities and knowledge. OSAFIS can retain these factors in a threat model while adding its proposed domain and contract assignments. The NIST publication does not validate the OSAFIS domain count or names. NIST adversarial machine learning taxonomy
NIST AI RMF supports voluntary management of risks associated with AI and considers effects on people, organisations and society. OSAFIS findings could supply evidence to a broader risk-management process, but completing a technical assessment does not demonstrate that all governance or trustworthiness responsibilities have been met. The NIST site reports work to revise AI RMF 1.0; citations should identify the version actually used. NIST AI Risk Management Framework
MITRE ATLAS is a knowledge base of adversarial tactics, techniques and case studies targeting AI. Its data also includes mitigations and typed relationships. OSAFIS must therefore not claim that external resources provide no account of relationships or propagation. Where a technique genuinely matches a case, an ATLAS identifier can accompany the local contract analysis, with the relevant ATLAS content and format versions. No comprehensive technique-level ATLAS crosswalk is asserted in this edition. MITRE ATLAS data repository
OWASP provides risk descriptions, attack scenarios and mitigation guidance for LLM and agentic applications. The 2025 LLM list remains useful as a versioned historical reference, while OWASP's resource page identifies an LLM 2026 edition dated 3 August 2026. The agentic 2026 guide is dated December 2025. The year in a guide title is not necessarily its publication year. OWASP LLM 2025 list, OWASP LLM 2026 resource, OWASP agentic 2026 resource
OWASP also publishes an industry framework crosswalk. Its existence is relevant to positioning: interoperability and cross-framework mapping are established activities, not exclusive OSAFIS capabilities. The OSAFIS-specific mapping task is to justify how a concrete failed contract relates to a particular external entry. OWASP framework crosswalk
CVSS v4.0 communicates vulnerability characteristics and severity through a defined scoring specification and vector. Where applicable, a report may retain a CVSS assessment with its version and vector alongside OSAFIS fields. OSAFIS does not provide a validated conversion from domain numbers, property counts or evidence descriptors into a CVSS score or a universal AI risk score. FIRST CVSS v4.0 specification
Rules for mapping
A mapping relates a specific definition or finding to a specific source edition. Similar wording is insufficient. The assessor identifies the external concept, explains the shared mechanism or obligation, records the limits of the match, and cites the source. A resource that covers a broad risk may intersect several OSAFIS domains, depending on where the particular system violates a contract.
Mapping relationships should use one of five descriptions: equivalent under stated scope, narrower, broader, partial overlap, or related context. Equivalence is a strong claim and requires matching conditions and exclusions. A provisional overlap is normally sufficient for a research cross-reference. Each mapping also records whether it is reviewed, proposed, disputed or not assessed. A missing mapping means only that no justified mapping is recorded; it does not establish a gap in the external resource.
Domain assignments in the following tables are conditional examples. They neither classify every instance of the external category nor list all possible domains. An entry point in a domain does not establish a violation there. L9 requires a collective contract and coupling mechanism in addition to any broad consequence.
Historical LLM 2025 mapping
The following table deliberately uses the 2025 identifiers. It must not be read as a category-level mapping of the 2026 guide. The table's domain assignments and contract descriptions are OSAFIS interpretations; the source establishes the existence and scope of the external categories. OWASP LLM 2025 list
| External ID | Possible domains | Contract question for a concrete case |
|---|---|---|
| LLM01:2025 | L5 and possibly L6 or L7 | Did lower-trust content obtain instructional authority or change the authorised task |
| LLM02:2025 | L1 L2 L3 L6 or L7 | Which component disclosed protected information, to whom, and across which boundary |
| LLM03:2025 | L1 L2 or L3 with D3 | Which supplied artifact or dependency escaped its provenance or integrity controls |
| LLM04:2025 | L3 and L1 | Did corrupted information affect learning, or did an unauthorised model change persist |
| LLM05:2025 | L2 or L7 | Did a consumer interpret model output as executable authority without the required validation |
| LLM06:2025 | L7 with D1 | Could available capabilities exceed the task, resource or approval scope |
| LLM07:2025 | L1 L2 or L5 | Was a protected secret disclosed, and was secrecy incorrectly used as an enforcement boundary |
| LLM08:2025 | L3 and possibly L2 or L6 | Were retrieval isolation, provenance or state ownership violated |
| LLM09:2025 | L3 L5 or L8 | Which evidence, interpretation or presentation obligation failed; was the result a security issue or a quality error |
| LLM10:2025 | L1 L2 L7 or L9 | Which computation, quota, action budget or collective stability contract failed |
The source treatment of prompt injection includes cross-modal cases. Accordingly, OSAFIS should not claim that image-borne attacks are absent from OWASP simply because an external list does not contain an entry called perception. Within OSAFIS, an image can be observed correctly while its text is improperly promoted to instruction in L5. An inaccurate estimate of the environment would instead require evidence for L4. OWASP prompt injection guidance
Agentic 2026 mapping
The identifiers in this table refer to the December 2025 publication of the agentic 2026 guide. The proposed domain relationships require case-level review. They do not imply that OWASP has accepted the OSAFIS model. OWASP agentic guide
| External ID | Possible domains | Contract question for a concrete case |
|---|---|---|
| ASI01 | L5 and possibly L7 | Did external influence replace the authorised objective or corrupt its operational plan |
| ASI02 | L7 and possibly L2 | Were tool choice, parameters, sequencing or permitted effects improperly constrained |
| ASI03 | L2 L6 or L7 with D1 | Was identity, scope or delegated authority incorrectly inherited or applied |
| ASI04 | L1 L2 L3 or L7 with D3 | Which supplied agent, tool, model or descriptor failed its supply or adoption contract |
| ASI05 | L2 or L7 | Which execution boundary admitted unintended code or an unapproved command |
| ASI06 | L6 or L5 | Was retained state corrupted, or was transient context selected or interpreted improperly |
| ASI07 | L2 L5 or L7 | Did transport authenticity, message authority or actual delegation fail |
| ASI08 | L9 where justified | Which coupling or containment defect amplified the failure beyond local behaviour |
| ASI09 | L8 with D1 | Did the interaction undermine informed authorisation or justified human reliance |
| ASI10 | Case dependent | Which observable contract was violated; what evidence distinguishes malicious influence from autonomous malfunction |
A worked mapping decision
Consider an illustrative, unexecuted case in which a retrieval assistant reads a document containing a request to change the user's task. The document is an entry point associated with L3. Its retrieval may satisfy the data-access contract, so L3 is not automatically a failed domain. If the interpreter treats the document as an authorised instruction, the hypothesised failure is L5 and P04 Instruction Integrity. If the objective changes, P09 Objective Integrity may also apply, provided the assessment independently specifies that obligation.
A provisional external mapping to LLM01:2025 is reasonable for the instruction manipulation. An agentic goal-redirection scenario may also overlap ASI01 in the specified 2026 guide. The two links describe related scopes; they do not create two independent vulnerabilities. The report should state the adversary's ability to place the document, the source of legitimate authority, the observable task change, and any untested downstream action. This example demonstrates the proposed mapping procedure, not a validated result.
Coverage and novelty claims
An external resource's scope must be assessed from its definitions, supporting guidance and examples. Comparing organisations such as OWASP, MITRE and NIST as though each had one fixed checklist produces misleading conclusions. A binary coverage matrix is particularly weak when a check mark means only that a topic is mentioned and a blank means only that a preferred name is absent.
A useful comparison selects a bounded case set, a defined task and a fixed version of each resource. It evaluates outcomes such as consistent contract identification, propagation reconstruction, missed obligations and analyst effort. Reviewers should disclose training differences and access to supporting material. This design can support a limited finding about utility. It cannot establish that OSAFIS covers every AI threat or is the first framework of its kind.
The current crosswalk is a scoped mapping proposal. Detailed migration of the LLM 2026 categories, a technique-level ATLAS mapping and a control-level standards mapping require separate source review. The resource-level references above acknowledge their relevance without representing unperformed work as complete. No certification or legal compliance conclusion follows from this document.
Maintenance
Each mapping record preserves the external publisher, title, identifier, edition, source URL, access date, local contract, mapping relationship, rationale, reviewer status and limitations. Revisions should identify whether the external definition changed or the local interpretation changed. Older mappings remain available for historical findings. Updating a website date without reviewing the source is not a mapping revision.
The release process should check referenced sources and any announced replacement edition, then update affected mapping records under Versioning and Identifiers. External content rights remain with their owners. OSAFIS links and interprets these resources without implying endorsement or copying their full guidance into the specification.