Skip to content
§ Prospectus · HI-AAF v. 1.3 · MMXXVI

A standard for the AI agents you trust with your business.

The standard and the practice for proving your agents behave — in production. Human Intelligence publishes HI-AAF, assesses agents against it, and keeps trained human reviewers in the loop — not just automated checks — so the evidence stays current after deployment.

Mapped to NIST AI RMF · ISO/IEC 42001 · OWASP LLM Top 10 · MITRE ATLAS · SOC 2 · EU AI Act · DFARS / CMMC

Established 2025
Seattle
Singapore
Edition v.1.3
§ II · Insight

Security is not the same as trust.

An AI agent can be secure — patched, scanned, network-isolated — and still be untrustworthy. Trust is a question of behavior under uncertainty: does the agent do the right thing when the situation drifts from its training?

Does it know when to escalate? Whose identity does it act under, and with whose permissions? Security frameworks were written for code, not for systems that make judgments.

Trust requires a different standard — one written for behavior, not for binaries; one that does not end at deployment but persists through every interaction the agent has with a real customer: a claim approved, a refund issued, a record changed.

Compliance frameworks have always followed the technologies they govern. SOC 2 followed cloud. HI-AAF follows agents.

§ III · The Framework

The Agent Assurance Framework, in 9 domains.

One control language for how your agents behave. Each control is cross-mapped to NIST AI RMF, ISO/IEC 42001, OWASP, MITRE ATLAS, SOC 2, the EU AI Act, and DFARS / CMMC — one assessment produces evidence you can reuse against whichever framework you already report to.

See the full crosswalk
Table III.1 · HI-AAF Domains · v.1.398 controls · 9 domains · 5-level maturity
GOV12 controls

Governance & Accountability

Ownership, policy, and risk-management discipline for every agent in production.

SPC9 controls

Agent Specification & Pre-Deployment Assurance

Behavior, capabilities, and constraints validated before deployment and on material change.

IAM8 controls

Identity, Access & Authorization

Scoped identity, least-privilege credentials, and clean attribution for every agent action.

INP10 controls

Input & Prompt Security

Defense against direct and indirect prompt injection, including through memory and retrieval.

ACT9 controls

Action & Tool Use Controls

Tool allowlists, blast-radius limits, and pre-execution review for irreversible actions.

DAT13 controls

Data Protection & Privacy

Classification, isolation, and lifecycle of data across prompts, memory, and retrieval.

OUT16 controls

Output Integrity & Supply Chain

Groundedness, safety, fairness, and provenance of outputs — and trust in upstream providers.

MON12 controls

Continuous Monitoring & Human Oversight

Per-step logging, drift detection, and a qualified human review queue with documented SLAs.

MAS9 controls

Multi-Agent Systems

Cross-agent identity, authorization, blast radius, and propagation of suspend across the chain.

§ IV · Practice

Five engagements that take you from un-assessed to certified.

Art. 6.01

Workshop

A facilitated two-day session that frames the agent's intended behavior, its operating envelope, and the questions the assessment must answer.

Art. 6.02

Readiness Review

A structured pre-assessment against the nine domains, returning a written readiness opinion and the work required to meet the Standard.

Art. 6.03

Assessment

The formal evaluation of an AI agent against HI-AAF, conducted by Human Intelligence assessors and concluding in a published Letter of Assessment.

Art. 6.04

Maintenance

Continuous review of the agent's behavior in production, with quarterly findings and a documented record of corrective action.

Art. 6.05

Certification

Written assessment that an AI agent meets the Standard, reviewed annually and issued by Human Intelligence.

§ V · Operate

Compliance is not a one-time act.

Beneath every certification under HI-AAF sits a human review layer — a trained, accountable group of reviewers whose work is to keep the Standard a living thing rather than a one-time stamp. They watch what the agent does after the assessors leave.

Reviewers receive escalations from certified agents, judge them against the controls written into the Standard, and return findings that flow back into the agent's operating record. Where behavior drifts, they intervene. Where the Standard itself proves thin, they say so.

This is the discipline that distinguishes assurance from inspection: people working steadily, in the open. It is what we mean when we call our own organization Human Intelligence.

§ VI · Engage

To request an assessment, or to read the draft Standard.

Offices
Seattle, United States
Singapore
Correspondence
hello@humanintel.net
Press & standards
By written request only.
Notice

HI-AAF v1.3 is an independent framework published by Human Intelligence. It is not affiliated with NIST, ISO, AICPA, or any government or accreditation body. The framework is offered openly for review during the current draft cycle.

End of prospectus. — Human Intelligence, MMXXVI.