Mapping to the FINOS AI Governance Framework¶
Generated by scripts/check_air_mapping.py from docs/air/catalogue.yaml and docs/air/mapping.yaml.
Edit the YAML, not this file.
Every risk and every mitigation in the framework has exactly one entry, including the ones this project does not address. The script fails if an item is missing, if an entry names a knob or lint rule that does not exist in the code, or if the catalogue changes without the mapping.
Source¶
- Framework: https://github.com/finos/ai-governance-framework at commit
aabbffbe02a4(2026-09-09), CC-BY-4.0. Titles, ids, types and the mitigates relation only. Text belongs to FINOS. The site labels this release v2. - This is one reviewer's reading. Have someone who owns the framework at your organisation check it before it is published.
How to read the statuses¶
| Status | Meaning |
|---|---|
| implemented | This repo validates or computes it, with tests in this repo. |
| declared | This repo carries the setting in the signed bundle. Enforcement is in mediatore, mediatore-guest or the gateway. |
| partial | Some of the above, and the gap column says what is missing. |
| gap | In scope for a sandbox policy layer, and nothing exists yet. |
| out_of_scope | Not a sandbox policy concern, such as model quality, bias or training data. |
Two limits apply to everything below. Nothing in this repo has run on a cluster yet. And "enforced elsewhere" names where enforcement belongs, it does not claim those components do it today.
Summary¶
| implemented | declared | partial | gap | out_of_scope | |
|---|---|---|---|---|---|
| Risks (23) | 1 | 0 | 12 | 1 | 9 |
| Mitigations (23) | 1 | 2 | 12 | 2 | 6 |
Risks¶
| ID | Title | Status | In this repo | Note | Gap | Enforced elsewhere |
|---|---|---|---|---|---|---|
| AIR-RC-001 | Information Leaked To Hosted Model | partial | K4.1, K4.3, K4.4, K1.4 L007, L003 DataScope |
Egress allowlist decides which model endpoints the sandbox can reach, volume caps and output export bound what leaves. Nothing classifies the data sent to a model. | No data classification of prompt content. Audience classification is ROADMAP M4. | |
| AIR-SEC-002 | Information Leaked to Vector Store | out_of_scope | none | No vector store is part of the sandbox. | ||
| AIR-OP-004 | Hallucination and Inaccurate Outputs | out_of_scope | none | Model output quality. | ||
| AIR-OP-005 | Foundation Model Versioning | gap | K8.1 | K8.1 pins the image, and with it the agent CLI. The model an agent may call is not in the spec. | A model allowlist or pin could be a policy field rendered into managed settings. | |
| AIR-OP-006 | Non-Deterministic Behaviour | out_of_scope | none | Model behaviour. | ||
| AIR-OP-007 | Availability of Foundational Model | partial | K2.4, K4.3, K7.3 L009 Budgets, ceilings |
Tool call, wall clock and egress byte budgets and lease ceilings cap consumption. | No token or spend budget, so Denial of Wallet is only bounded by time and call count. | |
| AIR-SEC-008 | Tampering With the Foundational Model | partial | K8.1, K1.3 L008 |
Image source and tool pinning protect what runs in the sandbox. | Hosted model weights and provider tampering are outside this project. | |
| AIR-SEC-009 | Data Poisoning | out_of_scope | none | Training and fine-tuning data. | ||
| AIR-SEC-010 | Prompt Injection | partial | K1.1, K1.2, K1.3, K3.3, K4.1, K1.4 L003 |
L003 refuses the combination of sensitive data, untrusted content and an outbound channel, so a successful injection has no path out. Injection itself is not prevented. | Guard hook in mediatore-guest renders K3.3. | |
| AIR-OP-014 | Inadequate System Alignment | out_of_scope | none | RAG response alignment. | ||
| AIR-OP-016 | Bias and Discrimination | out_of_scope | none | Model fairness. | ||
| AIR-OP-017 | Lack of Explainability | partial | K8.3 | K8.3 sets how much is logged. | Reasoning capture is undefined. See AIR-DET-021 for the tiering that K8.3 steps should map to. | |
| AIR-OP-018 | Model Overreach / Expanded Use | partial | K7.2, K1.3 L011, L012, L013, L010 KnobGrant, SandboxProfile |
Scope is a reviewed profile, widening it is a time-boxed, approved, one-step KnobGrant. This bounds how far a sandbox policy can drift, not how a business team uses the output. | How the output is used in the business is outside the policy. | |
| AIR-OP-019 | Data Quality and Drift | out_of_scope | none | Model data freshness. | ||
| AIR-OP-020 | Reputational Risk | out_of_scope | none | Consequence of other risks. Containment reduces it indirectly. | ||
| AIR-RC-022 | Regulatory Compliance and Oversight | partial | K8.3, K8.2 L013 signed bundle, KnobGrant, gitops-only admission |
Every policy version is signed, numbered and traceable to a grant with named approvers, K8.3 has a Compliance approver role. | No retention period or records-class field, so the record-keeping obligations the framework names are not expressed. | |
| AIR-RC-023 | Intellectual Property (IP) and Copyright | out_of_scope | none | Copyright in model output. Egress and export controls only help with trade secret leakage. | ||
| AIR-SEC-024 | Agent Action Authorization Bypass | implemented | K5.1, K5.2, K5.3, K5.4, K5.5, K3.2, K2.1, K7.4 L005, L006, L007, L008, L009, L011, L012, L013 ceilings, status.maxExposure, KnobGrant |
Policy side: deny by default, read-only tokens, no wildcard audiences, expiring relaxations, computed maximum exposure. Enforcement is in mediatore, guest and gateway. | mediatore, mediatore-guest, gateway. Not verified here. | |
| AIR-SEC-025 | Tool Chain Manipulation and Injection | partial | K1.3, K3.3, K2.1 L008 |
Tools are pinned by digest and the guard strictness is carried in the bundle. | Parameter and call-sequence rules are not modelled. | |
| AIR-SEC-026 | MCP Server Supply Chain Compromise | partial | K1.3 L008 |
MCP servers must be pinned by manifest digest. | No vetting workflow or evidence of review is recorded. | |
| AIR-SEC-027 | Agent State Persistence Poisoning | partial | K6.1, K1.2 | Tenancy tier and project instruction loading. One VM per lease that is destroyed afterwards is a banlieue and mediatore rule. | Nothing in the spec says whether a workspace may persist between leases. | |
| AIR-OP-028 | Multi-Agent Trust Boundary Violations | partial | K6.1, K5.6 | One identity and one VM per subject, carried as settings. | banlieue, mediatore | |
| AIR-SEC-029 | Agent-Mediated Credential Discovery and Harvesting | partial | K3.1, K5.1, K5.2, K5.3, K5.4 L005, L006 |
Short, read-only, audience-bound tokens and credential delivery mode. | No detection of credential discovery behaviour. | mediatore-guest delivers credentials. |
Which framework mitigations address each risk¶
The framework declares this relation. It is listed so a risk marked implemented or partial can be checked against the controls the framework expects for it.
| Risk | Framework mitigations |
|---|---|
| AIR-RC-001 | AIR-DET-001, AIR-PREV-002, AIR-DET-004, AIR-PREV-006, AIR-PREV-007, AIR-PREV-012, AIR-DET-015, AIR-PREV-020 |
| AIR-SEC-002 | AIR-PREV-006, AIR-PREV-014, AIR-DET-016 |
| AIR-OP-004 | AIR-PREV-005, AIR-PREV-006, AIR-DET-013, AIR-DET-015 |
| AIR-OP-005 | AIR-DET-004, AIR-PREV-005, AIR-PREV-010, AIR-DET-011, AIR-DET-015 |
| AIR-OP-006 | AIR-DET-004, AIR-PREV-005, AIR-PREV-010, AIR-DET-011, AIR-DET-015 |
| AIR-OP-007 | AIR-PREV-003, AIR-DET-004, AIR-PREV-008, AIR-DET-009, AIR-PREV-017 |
| AIR-SEC-008 | AIR-PREV-007, AIR-PREV-012, AIR-PREV-020 |
| AIR-SEC-009 | AIR-PREV-002, AIR-PREV-006, AIR-PREV-012 |
| AIR-SEC-010 | AIR-PREV-003, AIR-PREV-017, AIR-PREV-019 |
| AIR-OP-014 | AIR-DET-004, AIR-PREV-005, AIR-DET-011, AIR-DET-015 |
| AIR-OP-016 | AIR-PREV-005, AIR-PREV-006, AIR-DET-011, AIR-DET-015 |
| AIR-OP-017 | AIR-DET-013 |
| AIR-OP-018 | AIR-PREV-003, AIR-DET-004, AIR-DET-011, AIR-PREV-017, AIR-PREV-018 |
| AIR-OP-019 | AIR-DET-004, AIR-PREV-006, AIR-DET-015 |
| AIR-OP-020 | AIR-PREV-003, AIR-PREV-007, AIR-DET-011, AIR-DET-013, AIR-PREV-017 |
| AIR-RC-022 | AIR-PREV-005, AIR-PREV-006, AIR-PREV-007, AIR-DET-013, AIR-PREV-014, AIR-DET-016, AIR-DET-021 |
| AIR-RC-023 | AIR-PREV-006, AIR-PREV-007 |
| AIR-SEC-024 | AIR-DET-004, AIR-PREV-018, AIR-PREV-019, AIR-DET-021, AIR-PREV-022, AIR-PREV-023 |
| AIR-SEC-025 | AIR-DET-004, AIR-PREV-019, AIR-DET-021 |
| AIR-SEC-026 | AIR-DET-004, AIR-PREV-020, AIR-PREV-023 |
| AIR-SEC-027 | AIR-DET-004, AIR-PREV-022 |
| AIR-OP-028 | AIR-DET-004, AIR-PREV-022 |
| AIR-SEC-029 | AIR-DET-004, AIR-PREV-023 |
Mitigations¶
| ID | Title | Status | In this repo | Note | Gap | Enforced elsewhere |
|---|---|---|---|---|---|---|
| AIR-DET-001 | AI Data Leakage Prevention and Detection | partial | K4.3, K4.4, K1.4 L009 |
Volume caps bound exfiltration. TLS inspection is the only content inspection hook, and its loosest step is R1. | No data loss detection rules. | |
| AIR-PREV-002 | Data Filtering From External Knowledge Bases | out_of_scope | none | Knowledge base ingestion. | ||
| AIR-PREV-003 | User/App/Model Firewalling/Filtering | declared | K4.1, K4.2, K4.4 L007 |
Allowlist entries are validated here, filtering is done by the gateway. | gateway | |
| AIR-DET-004 | AI System Observability | partial | status conditions, KnobGrant status | Controller status shows version, digest, exposure and lint conditions. | No metrics endpoint or events until ROADMAP M2. Decision audit is mediatore's. | |
| AIR-PREV-005 | System Acceptance Testing | gap | none | Knob prerequisites are not proven by control tests. Grants record approvals, not test results. | ||
| AIR-PREV-006 | Data Quality & Classification/Sensitivity | partial | DataScope | Two data scopes, LabOnly and Internal. | Audience classification is ROADMAP M4. | |
| AIR-PREV-007 | Legal and Contractual Frameworks for AI Systems | out_of_scope | none | Contracts and legal review. | ||
| AIR-PREV-008 | Quality of Service (QoS) and DDoS Prevention for AI Systems | partial | K7.3 L009 |
Lease concurrency and duration ceilings. | Rate limiting at the gateway. | |
| AIR-DET-009 | AI System Alerting and Denial of Wallet (DoW) / Spend Monitoring | partial | L009 Budgets |
Budgets cap use. | No spend or token dimension, no alerting until ROADMAP M2. | |
| AIR-PREV-010 | AI Model Version Pinning | gap | none | See AIR-OP-005. A model pin is not a policy field. | ||
| AIR-DET-011 | Human Feedback Loop for AI Systems | out_of_scope | none | K3.2 is approval of actions, not a feedback loop on output quality. | ||
| AIR-PREV-012 | Role-Based Access Control for AI Data | partial | K7.2, K5.2, K5.3 L005, L006, L010 |
Subjects, eligibility and audience scoping. | Scoping stops at the audience and token. Access control inside the downstream data store is that system's. | |
| AIR-DET-013 | Providing Citations and Source Traceability for AI-Generated Information | out_of_scope | none | Output citation. | ||
| AIR-PREV-014 | Encryption of AI Data at Rest | out_of_scope | none | Disk encryption is a VM concern. | banlieue installMode Deferred with vTPM and LUKS, see the banlieue design. | |
| AIR-DET-015 | Using Large Language Models for Automated Evaluation (LLM-as-a-Judge) | out_of_scope | none | Model evaluation. | ||
| AIR-DET-016 | Preserving Source Data Access Controls in AI Systems | partial | K5.6 | Identity type is carried. Token delegation chain is mediatore's. | mediatore | |
| AIR-PREV-017 | AI Firewall Implementation and Management | declared | K4.1, K4.4 L007 |
Same as AIR-PREV-003. | gateway | |
| AIR-PREV-018 | Agent Authority Least Privilege Framework | implemented | K5.1, K5.2, K5.3, K5.5, K7.3, K7.4, K3.2 L005, L006, L009, L011, L012, L013 SandboxProfile, SandboxPolicy, KnobGrant, ceilings, status.maxExposure |
Role and privilege definition is the profile and policy, dynamic privilege is the expiring grant with renewal re-evaluation, approval workflow is K3.2 and grant approvals, exposure is computed. Enforcement at the API and tool layer is downstream. | Agent behaviour monitoring is not modelled. | mediatore, mediatore-guest, gateway. Not verified here. |
| AIR-PREV-019 | Tool Chain Validation and Sanitization | partial | K1.3, K3.3 L008 |
Tool selection is limited to pinned tools. | Parameter validation and sequence validation rules are not in the spec. | |
| AIR-PREV-020 | MCP Server Security Governance | partial | K1.3, K4.1 L008 |
Pre-approved servers pinned by digest, with egress through the gateway. That resembles the framework's pre-approved tier, it has not been checked against that tier's requirements. | No vetting, onboarding or incident response content. | |
| AIR-DET-021 | Agent Decision Audit and Explainability | partial | K8.3 signed bundle version |
The policy version is stamped into tokens so decisions can be traced to a policy. | K8.3 steps are not mapped to the framework's retention tiers, and reasoning capture is undefined. | Audit events come from mediatore and the guest hook. |
| AIR-PREV-022 | Multi-Agent Isolation and Segmentation | partial | K6.1, K5.6 | Tenancy tier and identity type are carried. | banlieue VM per identity, mediatore attestation. | |
| AIR-PREV-023 | Agentic System Credential Protection Framework | partial | K3.1, K5.1, K5.2, K5.3, K5.4 L005, L006 |
Just-in-time, short-lived, scoped credentials are policy. Delivery and environment isolation are downstream. | No behavioural detection. | mediatore-guest |
Open gaps¶
- AIR-RC-001 Information Leaked To Hosted Model: No data classification of prompt content. Audience classification is ROADMAP M4.
- AIR-OP-005 Foundation Model Versioning: A model allowlist or pin could be a policy field rendered into managed settings.
- AIR-OP-007 Availability of Foundational Model: No token or spend budget, so Denial of Wallet is only bounded by time and call count.
- AIR-SEC-008 Tampering With the Foundational Model: Hosted model weights and provider tampering are outside this project.
- AIR-OP-017 Lack of Explainability: Reasoning capture is undefined. See AIR-DET-021 for the tiering that K8.3 steps should map to.
- AIR-OP-018 Model Overreach / Expanded Use: How the output is used in the business is outside the policy.
- AIR-RC-022 Regulatory Compliance and Oversight: No retention period or records-class field, so the record-keeping obligations the framework names are not expressed.
- AIR-SEC-025 Tool Chain Manipulation and Injection: Parameter and call-sequence rules are not modelled.
- AIR-SEC-026 MCP Server Supply Chain Compromise: No vetting workflow or evidence of review is recorded.
- AIR-SEC-027 Agent State Persistence Poisoning: Nothing in the spec says whether a workspace may persist between leases.
- AIR-SEC-029 Agent-Mediated Credential Discovery and Harvesting: No detection of credential discovery behaviour.
- AIR-DET-001 AI Data Leakage Prevention and Detection: No data loss detection rules.
- AIR-DET-004 AI System Observability: No metrics endpoint or events until ROADMAP M2. Decision audit is mediatore's.
- AIR-PREV-005 System Acceptance Testing: Knob prerequisites are not proven by control tests. Grants record approvals, not test results.
- AIR-PREV-006 Data Quality & Classification/Sensitivity: Audience classification is ROADMAP M4.
- AIR-DET-009 AI System Alerting and Denial of Wallet (DoW) / Spend Monitoring: No spend or token dimension, no alerting until ROADMAP M2.
- AIR-PREV-010 AI Model Version Pinning: See AIR-OP-005. A model pin is not a policy field.
- AIR-PREV-012 Role-Based Access Control for AI Data: Scoping stops at the audience and token. Access control inside the downstream data store is that system's.
- AIR-PREV-018 Agent Authority Least Privilege Framework: Agent behaviour monitoring is not modelled.
- AIR-PREV-019 Tool Chain Validation and Sanitization: Parameter validation and sequence validation rules are not in the spec.
- AIR-PREV-020 MCP Server Security Governance: No vetting, onboarding or incident response content.
- AIR-DET-021 Agent Decision Audit and Explainability: K8.3 steps are not mapped to the framework's retention tiers, and reasoning capture is undefined.
- AIR-PREV-023 Agentic System Credential Protection Framework: No behavioural detection.