The Open Standards
Published by AI Security Intelligence

The measurement layer
for AI risk.

Three open specifications that measure AI risk with discipline: AIRS, AIER, and VSS. Live readings, publicly versioned, downloadable and citable.

ASI ▸ Standards Readout

20 Jul 2026 · 23:45 UTC
AIRS AI Readiness Score Carrier underwriting readiness · F206
39 MEAN · 0–100 SCALE
AIER™ AI Exposure Rating Entities under observation
1,368 ENTITIES · JUL 2026
VSS Vulnerability Scoring Standard AI incidents · empirically scored
317 INCIDENTS · JUL 2026
The Triad

Three peers. Three specifications. One measurement layer.

Each standard measures a different layer of the same risk. Cut from the same institutional grain, published on the same open cadence, cited in the same room.

Dossier · AIRS · v1.1

The readiness score for AI underwriting.

AIRS asks a single question, at scale: how prepared is this organization to underwrite the AI systems it operates? The answer is a number between 0 and 100, computed against 60+ evidence signals, updated monthly across our F206 portfolio.

39 Mean AIRS
F206 · Jul 2026
AIRS ▸ Spec & Readings Rev 20260714
Spec Version
v1.1
Released May 2026
Signals Evaluated
60+
Across 5 domains
F206 Coverage
100%
Updated monthly
Mean Score
39/ 100
σ = 4.9
Top Quintile
≥ 42
Underwriteable at standard terms
Tier Mapping
T1 – T5
Insurance Ready → Uninsurable
What AIRS Measures
  • Governance maturity across board, executive, and operator layers
  • Model inventory completeness and monitoring coverage
  • Third-party model provenance and vendor risk posture
  • Incident response readiness and disclosure discipline
  • Regulatory alignment against NIST AI RMF and EU AI Act
Aligned with NAIC Model Bulletin NIST AI RMF EU AI Act ISO/IEC 42001
Dossier · AIER™ · v1.0

The exposure reading, entity by entity.

AIER measures the AI exposure a single organization carries — not their readiness to underwrite, but the shape and magnitude of what could go wrong. Held in confidence. Delivered by reveal token. Underwrites carrier accumulation intelligence across a portfolio.

1,368 Entities under observation
Jul 2026
AIER ▸ Spec & Readings Rev 20260714
Spec Version
v1.0
Released 14 Jul 2026
Trademark
Serial 99877324
USPTO · registered
Entities Under Observation
1,368
Reveal-token gated
Tier Range
T1 – T5
Five-band exposure scale
Signal Substrate
30
Signals per reading
Delivery
Email · Token
Single-use reveal
What AIER Measures
  • Blast radius — how many downstream parties an incident touches
  • Model provenance concentration and vendor tail risk
  • Data lineage exposure across training and inference
  • Regulatory jurisdiction footprint and disclosure obligations
  • Correlated exposure with other carriers in the cohort lens
Standards Body AI Security Intelligence USPTO 99877324
Dossier · VSS · v1.2

The catalog of what can actually go wrong.

VSS is an AI-tagged catalog of every published vulnerability that touches an AI system — prompt injection, data poisoning, model theft, jailbreaks, supply-chain compromise. Empirically derived. Continuously scored. The raw material AIRS and AIER both draw from.

317 Incidents scored
Jul 2026
VSS ▸ Spec & Catalog Rev 20260714
Spec Version
v1.2
Released 18 Feb 2026
Total Incidents Scored
317
Cumulative
New This Month
+12
Rolling 30 days
Signature Classes
17
Prompt · Data · Model · Chain
Ingestion Cadence
Daily
Continuous refresh
Machine-Readable
JSON · STIX
Feed available
What VSS Catalogs
  • Prompt-layer vulnerabilities — injection, jailbreak, indirect prompt
  • Data-layer compromise — poisoning, membership inference, extraction
  • Model-layer weakness — theft, evasion, backdoor, adversarial
  • Supply-chain exposure — dependency, weights, provider posture
  • Deployment-layer misconfiguration — access, isolation, egress
Taxonomy Language MITRE ATLAS OWASP LLM AVID
How They Interlock

One risk, measured at three layers.

AIRS scores how prepared an insurer is to underwrite AI risk. AIER measures the exposure any single entity carries. VSS catalogs the vulnerabilities that create that exposure. Read together, they are the measurement layer the AI economy runs on.

LAYER 1 · READINESS How ready? LAYER 2 · EXPOSURE How exposed? LAYER 3 · VULNERABILITY What can break? AIRS · READINESS SCORE Readiness 39 · /100 AIER™ · EXPOSURE READING 1,368 entities VSS · INCIDENTS SCORED 317 incidents INFORMS → AIRS underwriting READS FROM → VSS scored
Layer 1 · AIRS

The reading room.

AIRS is what a carrier looks at first — a portfolio-wide readiness score that answers whether an entity can be underwritten at all.

Layer 2 · AIER™

The confidential reading.

AIER is the per-entity exposure companion to AIRS. Portfolio → readiness (AIRS). Entity → exposure (AIER). Delivered by reveal token.

Layer 3 · VSS

The raw material.

VSS is the empirical scoring standard for every AI incident AIRS and AIER both draw from. Five actuarial dimensions. The floor the other two stand on.

The Publication Cadence

Open standards, open process.

Every specification runs the same four-step process, published in the open and versioned in a live ledger. No black-box updates. No silent revisions.

01

Threat Model

Establish what the standard measures, why, and against what harms.

02

Draft Spec

Publish a versioned draft with signals, methodology, and evidence weights.

03

Versioned Release

Cut a numbered release. Diff from prior version published alongside.

04

Live Ledger

Readings published against the released spec, timestamped, cite-able.

The Open Standards

Read the specifications.

AIRS, AIER, and VSS are published open. Downloadable and citable. Cite them in your filings. Build against them.