Enterprise AI Framework 0.3.0: compliance mappings, AI security, and a reference implementation¶
Release 0.3.0 rebuilds the compliance mappings and the security section against current sources, and it adds a reference implementation for the delivery model. This post lists what changed and what readers should do about it.
Summary¶
Every compliance mapping now cites article, clause, or category identifiers, states the date its facts were checked, and lists its sources. The security pages name threats with OWASP and MITRE ATLAS identifiers. Two new security pages cover the AI supply chain and incident response. The Delivery section gains a reference implementation, and the site has new navigation and zoomable diagrams.
What changed¶
| Area | Change |
|---|---|
| EU AI Act | The timeline reflects Regulation (EU) 2026/1744, the Digital Omnibus on AI. High-risk obligations now apply from 2027-12-02 for Annex III systems and from 2028-08-02 for Annex I systems. |
| NIST AI RMF | All 19 categories, the seven trustworthiness characteristics, and the 12 risks in the Generative AI Profile |
| ISO/IEC 42001 | Clauses 4 to 10 and all 38 Annex A controls |
| FedRAMP | The Consolidated Rules for 2026, Key Security Indicators, and the SP 800-53 control families |
| Security | A threat catalog with OWASP LLM Top 10 2026, OWASP Agentic, and MITRE ATLAS identifiers, plus AI supply chain and AI incident response pages |
| Delivery | A reference implementation page and a starter standards library |
| Site | Section tabs, breadcrumbs, page metadata, and diagrams that open in a zoomable viewer |
Impact and migration¶
- Teams that planned EU AI Act high-risk work for 2026-08-02 should move those plans to the amended dates.
- Headings changed on every compliance and security page, so update deep links to old headings.
- Teams that record OWASP LLM identifiers should record the edition too. The threat model has a crosswalk from the 2025 identifiers to the 2026 ones.