Public-release candidateBundle 1.0-rc.4Independent review pending
AI Trust Graph
Graph-based, evidence-driven assurance for connected AI systems.
AI Trust Graph is an open methodology that models connected AI environments as evidence-linked graphs of identities, agents, models, tools, data, infrastructure and providers — and the relationships between them — so that assurance conclusions stay bounded by what the evidence can actually support.
The problem
AI systems are no longer isolated models.
- Models connect to agents.
- Agents invoke tools.
- Tools operate through identities.
- Identities cross boundaries.
- Actions may reach consequential systems.
Risk can emerge through the relationships between them.
Relationships describe what may be possible; on their own they do not establish exploitation. A topological connection is not automatically an exploitable path.
Source: Artifact #1 — Manifesto
The reasoning chain
From what exists to what can be defended.
Objects create a system description. Relationships establish how the objects interact. Paths combine relationships under conditions. Authority and influence explain how consequences can be caused. Evidence and controls determine what can be concluded.
The Core Conceptual Model calls this chain the intellectual spine of the methodology
.
Objects
What exists?
Objects and system boundary.
Relationships
How is it connected?
Typed directional relationships.
Conditions
What must be true?
Preconditions and state.
Paths
What can happen next?
Reachability and path analysis.
Authority and Influence
Who or what can cause it?
Authority, influence and actionability.
Consequence
Why does it matter?
Target criticality and consequence.
Controls
What interrupts it?
Control breakpoint and resilience.
Evidence
Decision
What can we defend?
Evidence, confidence and accountable decision.
Source: stage names and order from the reasoning chain in Artifact #2 — Core Conceptual Model §0.10; questions and concepts from the same section’s theory map, whose final row covers both Evidence and Decision.
A separate lifecycle: the 13-phase Assessment Methodology
The reasoning chain belongs to the Core Conceptual Model. Assessment fieldwork is governed separately by Artifact #7, which defines the controlled fieldwork lifecycle and gates without redefining upstream semantics.
Source: Artifact #7 — Assessment Methodology; METHODOLOGY_MANIFEST §1
- Initiate
- Scope
- Discover
- Model
- Evidence
- Controls
- Paths
- Maturity
- Scoring
- Findings
- Decisions
- Report
- Reassess
Six domains
Six coordinated lenses over one graph.
The domains are coordinated assessment lenses over one graph. They are not separate products and should not maintain incompatible definitions, evidence grades or scoring assumptions. Each has twelve canonical controls and six maturity capabilities.
- D1ATG-DIS-001…012
Discovery and AIBOM
Establish measurable estate, ownership, dependencies and shadow AI.
Maturity capabilities
- D1.1 Discovery scope and source coverage
- D1.2 Canonical inventory and ownership
- D1.3 Shadow AI and unmanaged use
- D1.4 AIBOM and dependency lineage
- D1.5 Unknown, orphan and lifecycle management
- D1.6 Discovery evidence and assurance
- D2ATG-TRU-001…012
Trust and Privilege Paths
Model cloud and AI trust, identity inheritance and attacker-relevant paths.
Maturity capabilities
- D2.1 Trust relationship representation
- D2.2 Identity and privilege path analysis
- D2.3 Boundary and provider trust
- D2.4 Path identification and prioritization
- D2.5 Control breakpoint analysis
- D2.6 Trust graph quality and governance
- D3ATG-AUT-001…012
Authority Governance
Define and review effective access, inference, approval and action.
Maturity capabilities
- D3.1 Authority inventory and taxonomy
- D3.2 Delegation and identity context
- D3.3 Human approval and oversight
- D3.4 Authority amplification control
- D3.5 Revocation and containment
- D3.6 Authority decision governance
- D4ATG-VAL-001…012
AI Security Validation
Test architecture and controls against realistic scenarios.
Maturity capabilities
- D4.1 Validation strategy and scope
- D4.2 Threat modeling and path hypotheses
- D4.3 Rules of engagement and safety
- D4.4 Control effectiveness testing
- D4.5 Finding quality and closure
- D4.6 Validation assurance and independence
- D5ATG-GOV-001…012
AI Governance and Assurance
Connect ownership, risk tier, policy, obligations and evidence.
Maturity capabilities
- D5.1 Strategy, policy and risk appetite
- D5.2 Use-case intake and tiering
- D5.3 Decision rights and accountability
- D5.4 Applicability and obligations
- D5.5 Exceptions and risk acceptance
- D5.6 Assurance, reporting and literacy
- D6ATG-RES-001…012
Operational Resilience
Prepare for failure, compromise, containment and recovery.
Maturity capabilities
- D6.1 Observability and attribution
- D6.2 Detection and triage
- D6.3 Containment and kill mechanisms
- D6.4 Recovery, rollback and compensation
- D6.5 Incident reconstruction and evidence
- D6.6 Exercises, learning and resilience governance
Source: purposes from Artifact #2 §8.1; capabilities from Artifact #3 — Maturity Model; control IDs from Artifact #5 — Master Control Library.
Evidence-bounded conclusions
UNKNOWN stays UNKNOWN.
Insufficient evidence does not silently become a favourable — or an adverse — conclusion. UNKNOWN remains visible until sufficient evidence and accountable review resolve the material assertion.
- UNKNOWNis notSafe
- UNKNOWNis notFailed
- UNKNOWNis notZero risk
- UNKNOWNis notN/A
UNKNOWN is not Not Tested.
They are distinct non-numeric result states with different meanings.
- UNKNOWN
The material state remains unresolved because evidence is absent, insufficient or materially conflicting.
Numeric treatment No numeric value.
Reporting treatment Included in uncertainty and evidence-gap counts.
- Not Tested
Testing required for a stronger conclusion was not performed.
Numeric treatment No numeric value for effectiveness.
Reporting treatment May retain a design score if separately supported.
Neither may be silently converted into a fabricated effectiveness result. Evidence grade E0 (no evidence) can support either, according to context: The only defensible conclusion is UNKNOWN or Not Tested.
Source: meanings from Artifact #6 — Evidence Model §0.5, §1.1; numeric and reporting treatment from Artifact #4 — Scoring Framework §0.5.
UNKNOWN is not zero, weak, safe or effective.
Distinct non-numeric result states
- Not Assessed
- UNKNOWN
- Inconclusive
- Not Tested
- Not Applicable
Each state has its own numeric and reporting treatment. They must never be silently collapsed into one another, into a score, or into a pass/fail. AI Trust Graph deliberately produces no single overall trust score.
Source: Artifact #4 §0.5
Control breakpoints
Where can a material path be interrupted?
A control breakpoint is a node, relationship or boundary where an effective control can materially stop, constrain, detect or contain a path. Alternate and residual paths must still be checked.
- Human
- Agent
- Identity
- Tool
- API
- Sensitive action
Stop. Progression past the breakpoint is blocked.
Constrain. Progression continues only within narrower scope or conditions.
Detect. Progression is observed and raises a signal for response.
Contain. Downstream effect is isolated or limited.
Path validation state
- Candidate
- Topological
- Plausible
- Validated
- Exploitable
- Controlled
- Invalidated
Path role
- Primary
- Alternate
- Residual
Validation state and role are orthogonal dimensions and are not collapsed into one state machine.
Source: Artifact #2 §1.8, §6.3, §6.6
Evidence model
Six grades of evidentiary support.
A grade measures how strongly a source supports a precisely stated assertion — not desirability, safety or compliance. A high grade can confirm an adverse state.
- E0
No evidence
No source is available or the supplied item cannot be linked to the assertion.
The only defensible conclusion is UNKNOWN or Not Tested. E0 is not evidence that the control is absent.
- E1
Inference or uncorroborated signal
A hypothesis is derived from incomplete, indirect, automated or unverified information.
Can prioritize investigation and create candidate graph assertions, but cannot establish implementation or operating effectiveness.
- E2
Attestation
An accountable person states that a condition or practice exists.
Supports claimed practice and context; needs corroboration for material technical claims.
- E3
Approved documentary evidence
A governed document records approved design, policy, architecture, procedure, contract or decision.
Can support design intent and governance state. It does not alone prove actual configuration, runtime behavior or sustained operation.
- E4
Corroborated technical evidence
Technical evidence from authoritative sources is supported by an independent source, consistent observation or reproducible inspection.
Can support implementation or operation within observed scope when current, relevant and representative.
- E5
Direct technical and representative evidence
Current direct technical evidence is combined with a representative test or operating record that demonstrates the claimed behavior under stated conditions.
May support verified effectiveness or adaptive operation, but only for the tested scope, period and conditions.
Grade is not sufficiency. Meeting the grade minimum is necessary but not sufficient; relevance, scope, currentness, representativeness, conflict status and an approved reviewer decision still govern.
Grade is its own quantity. Evidence grade is never added to control effectiveness, severity, maturity or risk as if they were the same quantity.
Source: Artifact #6 — Evidence Model §1.1–§1.8. The full sufficiency rules are deliberately not summarized here — read them at source.
The structure that carries the model
- Domains
- 6
- Canonical controls
- 72
- Maturity capabilities
- 36
- Maturity levels
- M1–M5
- Evidence grades
- E0–E5
Maturity is cumulative, evidence-gated and not an average of control scores.
Canonical source
Read the methodology itself.
This website explains; the artifacts on GitHub decide. Listed in the recommended reading order from the Methodology Manifest.
- Artifact #1v1.0ManifestoPurpose, principles and boundaries of the methodology
- Artifact #2v3.0.0Core Conceptual ModelThe graph model: nodes, edges, trust, authority, boundaries, paths
- Artifact #12v3.0.0Ontology SpecificationCanonical entity types, relationship predicates, states and enumerations
- Artifact #3v1.0Maturity ModelThe M1–M5 scale, 36 capabilities, critical gates
- Artifact #4v3.0.0Scoring FrameworkControl scoring, DCA/VCR/WCA, the PEI formula
- Artifact #5v2.0.0Master Control LibraryAll 72 canonical controls
- Artifact #6v2.0.0Evidence ModelE0–E5 grading, quality dimensions, evidence lifecycle
- Artifact #7v1.1.0Assessment MethodologyThe 13-phase assessment lifecycle and specialized methods
- Artifact #8v1.0Assessor HandbookAssessor competency levels (A1–A5), field guidance per control
- Artifact #9v1.1.0Reporting StandardThe mandatory report package and claim-integrity rules
- Artifact #10v2.0.0Reference Assessment RepositorySynthetic worked calibration cases and adversarial vectors
- Artifact #11v1.0Governance & Certification ModelStewardship, change control, certification readiness
Public review
This methodology is meant to be challenged.
- Challenge the assumptions.
- Examine the graph semantics.
- Inspect the evidence rules.
- Report inconsistencies.
- Contribute through GitHub.