Compliance
Standards mapping
SkillGrade maps its rubric to published security standards and regulation, so a grade can serve as independent supporting evidence in your AI governance program. It aligns with the following — it does not certify compliance with any of them.
| Standard / regulation | What we map to |
|---|---|
| EU AI Act | Art. 15 (accuracy, robustness & cybersecurity — names prompt injection, data poisoning, adversarial examples), Art. 25 (value chain), Art. 26 (deployer due diligence), Art. 50 (transparency). Enforceable since 2 Aug 2026. |
| OWASP Top 10 for LLM Applications (2025) | LLM01 Prompt Injection, LLM02 Sensitive Information Disclosure, LLM06 Excessive Agency, LLM07 System Prompt Leakage. |
| OWASP Agentic AI — Threats & Mitigations | Tool misuse, privilege compromise, excessive agency. |
| MITRE ATLAS | AML.T0051 (prompt injection), AML.T0057 (data leakage). |
| NIST AI RMF + Generative AI Profile (AI 600-1) | Measurement + trustworthiness, including explainability. |
| ISO/IEC 42001 Annex A · AICPA SOC 2 | Annex A controls · CC6.6 (third-party components). |
Traceable by design
How the grade is explainable
Every finding renders the control, the quoted evidence, the cited clause, and the exact rule that fired — so a grade is traceable and contestable, the property NIST calls Explainable & Interpretable and the EU AI Act (Art. 13 / Art. 86) frames as a right to explanation.
A SkillGrade rating does not certify legal compliance, replace a conformity assessment, or substitute for accredited certification.