Skip to content

Framework Alignment

This page maps implemented Legate control themes to common frameworks for auditors and GRC reviewers. It is evidence mapping, not a certification, conformity assessment, “MCP certified,” “AIUC-1 certified,” or “EU AI Act compliant” claim for Legate alone.

Forward with Access Model and Disclosure Boundary. Deeper evidence packages are available through BlockSkunk / Agelite diligence - not as an exhaustive dump in this portal.

Frameworks

Legate’s public connect contract maps control themes to:

  • MCP Authorization (2026-07-28) / OWASP MCP Top 10 themes
  • NIST CSF 2.0
  • ISO/IEC 27001:2022
  • ISO/IEC 42001:2023
  • SOC 2 (Security / Confidentiality) trust-criteria themes
  • NIST AI RMF (tool-plane slice: Govern / Map / Measure / Manage)
  • AIUC-1 operational control IDs (tool-plane slice)
  • EU AI Act articles that AIUC-1 crosswalks for that tool-plane slice

Control themes

Control themeWhat it means at the interfaceFrameworks (high level)
Audience-bound tokensShort-lived Bearer; audience/resource bound to Legate URIMCP Auth, NIST CSF PR.AA, ISO 27001 A.5/A.8, ISO 42001 A.6, SOC 2 CC6
Least privilegeScopes → packs; deny-by-default writesMCP / OWASP privilege, PR.AA, A.8, A.6, CC6
Write consentExplicit consent claim required for write toolsMCP authz, PR.AA, A.8, ISO 42001 A.9*, AIUC-1 C009, EU AI Act Art. 14 (tool plane), CC6
Input validationTool args validated against published schemasOWASP injection, PR.DS, A.8, CC6
Tool-call guardingProduction tool plane runs OdinGard Cerberus (existence - not scoring models)OWASP tool poisoning themes, PR.DS / DE.CM, A.8, AIUC-1 D003, CC7
Audit / telemetryDigests for actor / tool / args / status - no secrets in logsDE.CM, A.8 logging, A.6, AIUC-1 E015, EU AI Act Art. 12 / 19, CC7
Rate limitingAbuse / denial resistance on /mcpPR.IR, A.8, CC6
Output hygieneRedaction + size capsPR.DS, A.8, AIUC-1 A-series hygiene themes, CC6
Fail-closed authProduction remote requires configured OIDC + resource URIPR.AA, A.8, AIUC-1 B008 themes, EU AI Act Art. 15 (cyber), CC6
Client vs tool planeSampling / generative UX is client-side; Legate is tool planeNIST CSF GV.OC, ISO 42001 A.6, EU AI Act Art. 50 (client/deployer)

*Human oversight for model sampling is an MCP client obligation. Legate enforces tool-plane write consent only.

NIST AI RMF (tool-plane)

AI RMF functionHow Legate contributes
GOVERNDocumented role boundary: resource server vs LLM host; themes on this page
MAPTool packs + scopes as capability inventory
MEASUREAudit digests; rate-limit / deny signals for operators
MANAGEFail-closed auth, pack deny, write-consent gate

Org-wide AI risk programs (policies, impact assessments) live outside this product docs set.

AIUC-1 / EU AI Act (tool-plane)

Public crosswalk: AIUC-1 × EU AI Act. Legate maps as a component (tool plane), not as a stand-alone high-risk AI system conformity package.

AIUC-1 theme (IDs)EU AI Act articlesWhat Legate contributes at the interface
E015 Log AI system activityArt. 12, Art. 19Append-only tool-call digests (actor / tool / args digest / status) - no secrets
C009 Real-time feedback and interventionArt. 14Write tools require explicit consent claim; signing stays outside the agent
D003 Restrict unsafe tool callsArt. 72 themesScopes → packs; deny-by-default writes; tool-call guarding (existence)
B008 Protect deployment environmentArt. 15Fail-closed remote auth; audience-bound tokens; rate limits; internal publish posture
A-series hygiene (credentials / leakage)Art. 15 (cyber)Redaction + no bearer tokens in logs
E016 / E017 disclosure themesArt. 13, Art. 50Connect docs + this page + Disclosure Boundary; “interacting with AI” notice is primarily client / deployer
E013 / C001 QMS and risk taxonomyArt. 9, Art. 17, Art. 27Packs/scopes as capability inventory only - org AIMS and deployer FRIA stay outside Legate

Out of scope

  • FedRAMP High / full NIST SP 800-53 SSP
  • Legate as an OAuth authorization server
  • Third-party AI conformity assessment for Legate alone
  • AIUC-1 certification or “EU AI Act compliant” claims for Legate alone
  • Art. 10 training-data duties for models Legate does not train
  • Art. 27 fundamental-rights impact assessment (deployer)
  • CE marking / EU database registration
  • Guard / scoring engines, policy source files, or mandate business rules - see Disclosure Boundary

Was this page clear?