Standford text

How Stanford built its AI Security Framework on AIUC-1

Amy Steagall, CISO and Bhavya Gupta, ISO (Stanford University)

Stanford's Information Security Office (ISO) needed a way to secure a fast-growing adoption of AI across research, teaching, healthcare, and administration without becoming the bottleneck that pushes deployment underground. The result is the Stanford AI Security Framework (AISF), a risk-based, shared-responsibility model that integrates AIUC-1, ISO 42001, the NIST AI RMF, the EU AI Act, and OWASP AIVSS. AIUC-1 supplies the framework's operational core: a way to classify and tier AI use cases by what an agent can actually do, not just what data it touches.

Stanford’s unique environment

Few organizations have a risk surface as varied as a research university. Stanford spans research, teaching, clinical care, supported by administrative staff and spans public research outputs to protected health information, admissions files, financial aid records, and HR data. AI adoption is accelerating across all of these areas at once, which only increases the amount of data generated. Faculty, students, and researchers expect access to the latest tools, and Stanford is committed to providing them.

At the same time, the systems being adopted increasingly access sensitive institutional data and act on it directly, creating regulatory, financial, and reputational exposure. A growing share of this AI isn't procured as "AI" at all: it arrives as new features inside SaaS products the university licensed years ago.

"The genie is out of the bottle, AI has a critical role to play in our research and education now, and in the future. My goal was to make the easy path the safest path focusing our deepest reviews on the systems that really need it."

Amy Steagall
CISO, Stanford University

Starting with foundations

Rather than invent a framework from scratch, the team built on established standards and assigned each one a clear job:

  • AIUC-1 provides the operational use-case classification and tiering methodology that ties these standards together.
  • ISO 42001 provides the management-system structure for organizational governance. The NIST AI RMF contributes to lifecycle-oriented risk identification.
  • The EU AI Act informs regulatory risk classification and transparency obligations, such as disclosing to people when they are interacting with an AI system.
  • OWASP AIVSS provides vulnerability and security scoring guidance.

The framework we developed also extends a core Stanford principle: shared responsibility. The AI deployer is the first-line accountable party. For self-service deployments, completing the deployment checklist is a meaningful, auditable act of self-certification, not a rubber stamp. Clearly defined roles, including the CIO, CISO, data owners, service or business owners, the University Privacy Office, and ISO, mean every system has an owner from inception through decommissioning.

Importantly, the AISF is positioned as a framework, not a mandate. It gives the Stanford community the tools, principles, and criteria to make informed decisions, while allowing local units to retain authority over their functional areas of oversight.

The role of AIUC-1

Traditional data classification approaches ask one question: how sensitive is the data? For AI agents, that isn’t enough. Two agents reading the same dataset can pose very different risks if one only summarizes and the other modifies records, sends messages, or triggers transactions.

AIUC-1 gave Stanford three things it needed:

Controls built for agentic AI. AIUC-1 is designed specifically around what agents do: call tools, take actions, and operate with varying autonomy. Its controls are technically grounded, covering risks like prompt injection, unauthorized agent actions, and unsafe tool calls.

A standard that keeps pace. AIUC-1 is updated quarterly as capabilities, threats, and legislation evolve, and it is crosswalked to frameworks Stanford already uses, including ISO 42001, NIST AI RMF, and the EU AI Act. This approach let the team adopt current best practices and keeps the framework nimble when the landscape shifts.

Risk tiering based on consequence, not just data. Drawing on AIUC-1's methodology, the AISF tiers systems by consequence severity, weighing data sensitivity, autonomy, tool access, and reversibility:

  • A Low Risk system is informational, touches no sensitive data, initiates no tool calls, and is easily reversible.
  • A Moderate Risk system analyzes internal data and uses tools in a limited way within defined workflows.
  • A High Risk system handles sensitive or regulated data and executes tool calls affecting systems of record, such as financial, HR, or student records, with the potential for irreversible action.

This tier is then crossed with an Agent Deployment Category (defined by Stanford) describing where the agent acts and who is exposed to it:

Agent Deployment Categories

This dual-axis model reflects a key insight: two systems at the same risk tier can carry markedly different governance burdens depending on whether they augment one person, automate a workflow, or reach the outside world. When agents call other agents, the composed system inherits the controls of the highest category in the chain.

"Data classification told us what an agent could see. AIUC-1 helped us ask what it could do, and that's where the real risk in agentic systems lives."

Bhavya Gupta
Information Security Officer, Stanford University

Deploying a shared-responsibility framework for all

Stanford treats the AISF as a living document. It is reviewed on an annual cycle and updated as regulations change, as audit findings and operational lessons accumulate, and as the AI landscape evolves. Open questions the team is already tracking include agent-to-agent identity, cross-tenant identity for third-party agents, and emerging standards for agent authorization.

The framework is also finding an audience beyond Stanford. The ISO team has shared the AISF with the Ivy+ CISO network, where peer institutions are actively embracing the framework’s principles into their own environments. Stanford welcomes practitioner feedback to help the framework mature.

"We built this to work at Stanford, but the problem isn't unique to us. Every institution is trying to say yes to AI without losing sight of what its agents can do."

Bhavya Gupta
Information Security Officer, Stanford University

Amy Steagall and Bhavya Gupta are members of the AIUC-1 Consortium, where they bring Stanford's real-world experience of governing AI across a complex institution to shaping the standard itself.

Read the full framework: Stanford AI Security Framework (AISF)

Amy Steagall-Hess is the CISO at Stanford University. She previously spent 25 years in the United States Air Force, culminating in a leadership role at Joint Force Headquarters-Cyber, NSA Texas, where she led teams conducting offensive and defensive cyber operations. She’s an executive member of the AIUC-1 Consortium.

Bhavya Gupta is an Information Security Officer at Stanford University. In addition, she co-leads two OWASP Foundation projects - the AI Vulnerability Scoring System project and the Agentic Skills Top 10. She’s a member of the AIUC-1 Consortium.