Formal verification proves what a system can do. Proof of Control proves what it did. Proof of Efficacy™ proves what survives when someone tries to break it. AI security has dozens of frameworks covering the first two. Almost nothing covers the third. Every other benchmark produces a document. Proof Benchmark produces a tamper-resistant, independently witnessed, publicly verifiable execution record - anchored to the NIST Randomness Beacon before a single test case runs. The result is either a ProofStamp or it isn't. There is no middle tier.
| Category | What it answers |
|---|---|
| Threats | What to worry about |
| Vulnerabilities | What can go wrong |
| Principles | What good looks like |
| Controls | What to enforce |
| Governance | What to build |
| Runtime enforcement | What to enforce at the action boundary |
| Evidence and verification | How you show any of the above actually happened |
| Adversarial efficacy | Whether it held when someone tried to break it |
| Framework | Owner | What It Does |
|---|---|---|
| MAESTRO | CSA / Ken Huang (Feb 2025) | 7-layer threat identification for agentic AI |
| AICM | CSA | 243 controls across 18 domains for AI systems |
| ATF | CSA | Operationalizes AICM for agents; Zero Trust framing |
| STAR for AI | CSAI Foundation | Catastrophic risk annex to CSA STAR; phases through Dec 2027 |
| OWASP LLM Top 10 | OWASP (Aug 2023, updated 2025) | Ranked list of LLM-specific vulnerabilities |
| OWASP Agentic Threats v1.0a | OWASP (Feb 2025) | 15 agentic threat categories |
| OWASP Multi-Agentic Threat Modeling Guide | OWASP (Apr 2025) | Structured threat modeling for multi-agent systems |
| OWASP Top 10 for Agentic Apps 2026 | OWASP (Dec 2025) | Top 10 agentic application risks, 100+ contributors |
| MITRE ATLAS | MITRE | Adversarial ML technique catalog, living knowledge base |
| NIST AI RMF 1.0 | NIST | Govern, map, measure, manage AI risk |
| NIST AI 600-1 | NIST | Risk management applied to generative AI |
| NIST AI 100-2 | NIST | Adversarial ML attacks and mitigations terminology |
| NIST CAISI Agent Standards Initiative | NIST (Feb 2026) | US government AI agent standards program |
| COSAiS | NIST | SP 800-53 control overlays for five AI use cases |
| Google SAIF / SAIF 2.0 | Embed security into AI model development; Agent Risk Map | |
| Cisco DefenseClaw | Cisco (Mar 2026) | Skills scanner, MCP scanner, AI BOM, sandboxing |
| Cisco AI Defense | Cisco | Runtime guardrails and red teaming for agentic workflows |
| Palo Alto AIRS 3 | Palo Alto Networks | Agent lifecycle security |
| CrowdStrike AI Runtime Protection | CrowdStrike | Runtime AI agent protection and shadow AI discovery |
| Microsoft Entra Agent ID | Microsoft | Agent identity within Microsoft enterprise perimeter |
| Anthropic Trustworthy Agents / Zero Trust for AI | Anthropic (Apr–May 2026) | Model-layer safety and zero trust principles for agents |
| AIUC-1 | AI Underwriting Consortium / Lovable (May 2026) | Six control families for coding agents |
| ASF | Jeff Sutherland | Agent Security Framework |
| MATRA | Academic | Model the attack surface of agentic AI systems |
| CoSAI | Linux Foundation | Coalition for Secure AI - working groups and guidance |
| C2PA | Content Provenance | Origin and edit history of media content |
| EU AI Act | European Commission (Aug 2026) | Risk-based requirements for AI systems in the EU |
| ISO/IEC 42001 | ISO | Certifiable AI management system; 12–18 month process |
| DORA | EU | Digital operational resilience for financial services |
| NIS2 | EU | Network and information security across critical sectors |
Every framework in this landscape tells an enterprise what their AI security posture should be.
Proof Benchmark tells them - and anyone who asks - what it actually is.
Submit a versioned build for evaluation against the Gauntlet. Pass or fail, results publish to ProofRegister - public, tamper-resistant, permanently on record. If scores meet PESA thresholds, a PROOFstamp is issued.