Skip to content

Enterprise AI Framework 0.3.0: compliance mappings, AI security, and a reference implementation

Release 0.3.0 rebuilds the compliance mappings and the security section against current sources, and it adds a reference implementation for the delivery model. This post lists what changed and what readers should do about it.

Summary

Every compliance mapping now cites article, clause, or category identifiers, states the date its facts were checked, and lists its sources. The security pages name threats with OWASP and MITRE ATLAS identifiers. Two new security pages cover the AI supply chain and incident response. The Delivery section gains a reference implementation, and the site has new navigation and zoomable diagrams.

What changed

Area Change
EU AI Act The timeline reflects Regulation (EU) 2026/1744, the Digital Omnibus on AI. High-risk obligations now apply from 2027-12-02 for Annex III systems and from 2028-08-02 for Annex I systems.
NIST AI RMF All 19 categories, the seven trustworthiness characteristics, and the 12 risks in the Generative AI Profile
ISO/IEC 42001 Clauses 4 to 10 and all 38 Annex A controls
FedRAMP The Consolidated Rules for 2026, Key Security Indicators, and the SP 800-53 control families
Security A threat catalog with OWASP LLM Top 10 2026, OWASP Agentic, and MITRE ATLAS identifiers, plus AI supply chain and AI incident response pages
Delivery A reference implementation page and a starter standards library
Site Section tabs, breadcrumbs, page metadata, and diagrams that open in a zoomable viewer

Impact and migration

  • Teams that planned EU AI Act high-risk work for 2026-08-02 should move those plans to the amended dates.
  • Headings changed on every compliance and security page, so update deep links to old headings.
  • Teams that record OWASP LLM identifiers should record the edition too. The threat model has a crosswalk from the 2025 identifiers to the 2026 ones.

Evidence and references