ASK defines the architectural properties — enforcement, mediation, governance, and trust — so you can build agent systems that are secure, auditable, and compliant. Open, vendor-neutral, and aligned with the regulatory frameworks that matter.
"Agents are principals to be governed, not tools to be configured."
Most AI security guidance is aspirational. ASK is operational — specific enough for an engineer to implement, an auditor to verify, and a regulator to accept.
ASK doesn't say "ensure appropriate oversight." It defines concrete properties — enforcement outside the agent boundary, complete mediation, immutable audit trails. Things you can implement, test, and verify. Any stack, any platform.
Every action is traced. Every trust relationship is documented. Every constraint state is reconstructible. ASK maps directly to EU AI Act, NIST AI RMF, SOC 2, HIPAA, and GDPR — the evidence is structural, not bolted on.
Agents built on ASK have governance that scales from a laptop to an enterprise fleet. The same invariants apply at every level — which means you can ship agent-powered products into environments with real security requirements.
Five claims, and the invariants that make each one true. Every invariant is binary — it holds or it doesn't — and every one has a test. When someone asks "how do I know this is safe?", the answer is a result, not a promise.
The agent cannot reach the machinery that governs it, and that machinery keeps working when things break.
What the agent did, what it was allowed to do at the time, and what left the boundary. Recorded by something the agent cannot write to.
An agent holds what an operator gave it, bounded in how it may be used, and cannot enlarge that holding from the inside.
Every trust relationship is declared. What arrives unverified gets the lowest tier, and data never becomes instruction.
Halt, containment, and governance stay in human hands — and the load of exercising them stays inside human capacity.
Fifteen of 38 invariants. Alongside them sit 14 principles — the judgment calls the framework names rather than pretends to automate. Every invariant carries a verification test: read the full set.
An agent decomposes into four layers: the model that reasons, the context assembled in front of it, the runtime that runs the loop, and the workspace it executes in. ASK defines who owns each one and what must hold at every boundary between them — because that is where enforcement goes.
Reasoning happens at the Model — an inference endpoint outside the workspace, owned by a vendor and treated as untrusted. The framework governs what reaches it and what its output is allowed to cause. Two things are replaceable: the workspace (reimage without losing state) and the role (load different constraints). Nothing else is portable. Inside, the critical security boundary is between Constraints (operator-owned, read-only) and Identity (agent-owned, writable). An agent that can write to its own constraints can rewrite its own rules — the architecture makes this structurally impossible.
You don't give a new hire the keys to production on day one. Agents are the same. ASK defines a trust spectrum so operators can set boundaries and users can set their own comfort level — and agents can earn more autonomy through observed behavior, not just configuration.
Human confirms every action. The new hire with a senior looking over their shoulder.
Human reviews batches. Agent proceeds on clear cases, flags the rest. Trusted but verified.
Agent operates independently within defined bounds. Escalates exceptions only. The experienced team member.
Humans set goals, agent manages scope. Highest trust, earned through track record.
Trust elevation always requires human approval. Trust reduction can be automatic. No agent — and no human — can self-promote.
ASK works as context for any AI coding assistant. Point your tool at the framework and start getting security review on every design decision.
Install the ASK plugin. Gives you /ask for security review, plus skills for threat analysis and secure architecture design.
Add the ASK marketplace and install the plugin. Same skills — review, threat analysis, and design.
Install from the Command Palette, or add the marketplace to your settings for browse-and-install.
Clone the ASK repo and install the plugin into your project.
Clone the ASK repo into your project. Cursor, Windsurf, Cline, and other tools that read project context will pick up the framework automatically.
Regulators converged on asking for evidence rather than policy documents: audit trails the system cannot tamper with, human override that demonstrably works, access control you can show. ASK maps each obligation to the invariants that satisfy it and the test that evidences it — so an auditor gets a result, not a claim.
Also covered: California SB 53, AB 2013 and the CPPA rules, the Council of Europe convention, Korea, Singapore, DORA, NYDFS, ISO/IEC 42001, AIUC-1, and NIST COSAiS — alongside a plain statement of what ASK does not provide, including conformity assessment, privacy determinations, and bias testing. Working on AI compliance in a regulated industry? Contributions to the mappings are welcome.
ASK is a complete framework — not just principles. Each document serves a different audience and use case.
Invariants, cognitive model, trust spectrum, principal hierarchy, policy model, and agent lifecycle. Start here.
Risks organized by attack surface — runtime, network, ingress, agent state, multi-agent, governance. Cross-referenced to MITRE ATLAS technique IDs.
A test for every invariant, each stating what to do and what must happen. Where a property has a part no test can reach, that part is named rather than implied.
Implementation guidance for novel threats — XPIA kill chain, MCP tampering, delegation poisoning, identity corruption, behavioral drift, and oversight fatigue.
Invariant-by-invariant mappings to EU AI Act, NIST AI RMF, SOC 2, HIPAA, GDPR, and SEC AI Guidance. Honest about gaps.
Known gaps and open questions. ASK documents what it doesn't yet cover — because honest gap reporting builds more trust than overclaiming.