Framework for AI security and governance

The CARE framework for AI security and governance

CARE is my four-phase framework for AI security and governance: Create, Adapt, Run, and Evolve. It governs AI that takes actions as well as AI that produces answers, with 87 controls in 16 categories, each scored on evidence instead of assertion. It runs as one program with RISE, my framework for AI strategy.

RISE and CARE cycle diagram. The outer ring shows the four RISE phases, Research, Implement, Sustain, and Evaluate, moving clockwise. The inner ring pairs each one with a CARE phase: Research with Create, Implement with Adapt, Sustain with Run, and Evaluate with Evolve.

What the CARE framework does

Finds every agent, including the ones nobody bought

Create starts with an inventory of every AI system and agent, an AI bill of materials, and a registry of every non-human identity and credential your AI uses. Citizen-built, SaaS-embedded, and MCP-connected agents get found and get an owner. You can't govern what you haven't found.

Grants autonomy on evidence

Four autonomy tiers, from T1 copilots to T4 multi-agent systems, each with a minimum maturity gate. Your scores show every tier as cleared, conditional, or not cleared. When a tier isn't cleared, you raise maturity or lower the tier.

Constrains behavior instead of describing intent

Approval gates enforced by the system instead of the prompt. A policy enforcement point outside the model on every tool call. Least-privilege tool profiles, sandboxed execution, per-agent identity with short-lived credentials, and a kill switch that gets drilled.

Holds up in front of an auditor

Policy and practice are scored separately. Self-attested practice is capped at Tier 2, because assertion isn't evidence. Overall maturity can't outrun the weakest phase or the governance category. Every control maps to the frameworks your auditors and regulators already use.

The four phases of the CARE framework

CARE has four phases, 16 categories, and 87 controls. Every control states what changes when agents are in scope, and 28 of them exist because agents exist. Each phase pairs with a RISE phase in the same position on the cycle.

  1. Create

    7 categories, 44 controlsPairs with RISE Research

    Build the foundations: policy and accountability, the AI and agent inventory, risk tiering and threat modeling, secure architecture, data and memory governance, ethics, and identity. Along the way, Create surfaces the needs and gaps the rest of the program has to answer.

    Categories

    • Policy, governance, and accountability
    • Asset inventory and attack surface
    • Risk assessment, tiering, and threat modeling
    • Secure architecture and development
    • Data, memory, and context governance
    • Ethics, bias, and transparency
    • Cybersecurity, privacy, and identity

    What it produces

    Written policies, an owned inventory of every AI system and agent, a risk tier for each one, and the needs and lessons learned that Adapt works from.

  2. Adapt

    4 categories, 18 controlsPairs with RISE Implement

    Adapt the program and its systems to the needs and lessons learned identified in Create. Moving systems into production is one part of that work, along with granting autonomy in stages, assuring tools and the supply chain, setting human oversight, and controlling change.

    Categories

    • Deployment, integration, and progressive autonomy
    • Tool, MCP, and supply chain assurance
    • Human oversight and boundaries
    • Change, release, and communication

    What it produces

    Controls fitted to your actual risks, systems that earn autonomy against logged evidence, and the status of every autonomy tier: cleared, conditional, or not cleared.

  3. Run

    3 categories, 16 controlsPairs with RISE Sustain

    Operate AI day to day with monitoring, enforcement before an agent acts, incident response and containment, and audit.

    Categories

    • Runtime monitoring, detection, and enforcement
    • AI incident response and containment
    • Audit, assurance, and training

    What it produces

    Telemetry that traces every agent action back to the person who authorized it, a drilled kill switch, and audit and red-team findings tracked to closure.

  4. Evolve

    2 categories, 9 controlsPairs with RISE Evaluate

    Improve the program from evidence, through metrics, management reviews that widen or narrow the permitted tiers, and clean retirement of systems.

    Categories

    • Continuous improvement, metrics, and feedback
    • Responsible decommissioning and knowledge transfer

    What it produces

    A management review decision on which autonomy tiers stay open, and retired agents that leave no orphaned identities, tokens, or connectors behind.

Autonomy tiers and maturity gates for agentic AI

How does CARE govern AI agents?

CARE doesn't put agents on a separate track. Every control states what changes when agents are in scope, and four autonomy tiers set the minimum maturity an organization needs before it runs agents at that level. RISE uses the same four tier definitions word for word.

T1
Assistants and copilots where a human executes every actionMinimum overall maturity (0 to 5): 2.0
T2
Platform and citizen-built agents that call tools inside a governed platformMinimum overall maturity (0 to 5): 3.0
T3
Custom and code-executing agents with MCP, external communication, or production accessMinimum overall maturity (0 to 5): 3.5
T4
Multi-agent and cross-boundary systemsMinimum overall maturity (0 to 5): 4.0

How CARE and RISE work together

RISE, my framework for AI strategy, decides what your organization will do with AI and how much autonomy it grants. CARE decides how those systems get governed and secured. They run as one cycle, and each phase hands something specific to its partner.

  • Create pairs with Research

    Create takes the risk appetite, the accountable executive, and the use-case portfolio from Research, writes the policies, and returns the tier gates the portfolio has to clear.

  • Adapt pairs with Implement

    Adapt takes what Create learned and Implement's staged roadmap, fits controls and systems to both, and returns the status of each autonomy tier.

  • Run pairs with Sustain

    Run operates against the KPI thresholds Sustain sets and returns audit results, runtime indicators, and incident summaries.

  • Evolve pairs with Evaluate

    Evolve takes Evaluate's realized-value record and proposed tier changes, and returns the management review decision on which tiers stay open.

The shared rule: when a use case needs a tier your organization hasn't cleared, you have two moves. Raise maturity or lower the tier.

Why AI governance has to constrain behavior

In July 2025, during a declared code freeze, a Replit coding agent wiped a live production database and then reported that rollback was impossible, which wasn't true. It could recite the freeze instruction. What it lacked was an approval gate the system enforced, separation between writing code and running it, and a tested kill switch.

87controls in 16 categories, with 28 that exist because AI agents exist.
3,619mapping rows across 24 frameworks and laws, each direct row carrying a verbatim excerpt from its source.
Dec 2, 2027is when EU AI Act rules for Annex III high-risk systems now apply, after the 2026 AI Omnibus. Article 50 transparency rules apply from August 2, 2026.Source: European Commission, 2026

What a CARE assessment delivers

I run CARE as an assessment of your AI security and governance program. You leave with scores you can defend and a plan to move them.

  • An intake of your AI estate, including how your agents are built, connected, and owned.
  • Policy and practice scores on all 87 controls, with the evidence status behind every score.
  • Six-month, twelve-month, and goal targets for every control.
  • A dashboard with phase and category maturity, agentic readiness, your autonomy tier posture, and a risk heat map.
  • A mapping from every control to the frameworks your auditors and regulators already use.

CARE framework FAQ

What is the CARE framework for AI security and governance?
CARE is a four-phase framework for governing and securing AI: Create, Adapt, Run, and Evolve. It has 87 controls in 16 categories, scores policy and practice separately, caps self-attested scores, and sets a minimum maturity gate for each of four autonomy tiers, from copilots to multi-agent systems.
What does CARE stand for?
Create, Adapt, Run, Evolve. Create builds the foundations and surfaces the needs and gaps. Adapt adjusts the program and its systems to what Create learned, including how systems reach production. Run operates and monitors them. Evolve improves the program from evidence.
Is this the same as the CARE Principles for Indigenous Data Governance?
No. The CARE Principles for Indigenous Data Governance (Collective Benefit, Authority to Control, Responsibility, Ethics) set out Indigenous Peoples' rights and interests in data. The CARE framework on this page is a security and governance framework for the AI systems and agents inside an organization. The two share an acronym and nothing else.
Does CARE map to ISO/IEC 42001, the NIST AI RMF, and the EU AI Act?
Yes. Every CARE control maps to the frameworks and laws an auditor is likely to raise, including ISO/IEC 42001, the NIST AI RMF, NIST CSF 2.0, the EU AI Act, the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, and MITRE ATLAS. The mapping covers 24 frameworks and laws, so a team already running ISO/IEC 27001 or the NIST CSF extends what it has.
What are the CARE autonomy tiers?
T1 covers assistants and copilots where a human executes every action. T2 covers platform and citizen-built agents that call tools inside a governed platform. T3 covers custom and code-executing agents with MCP, external communication, or production access. T4 covers multi-agent and cross-boundary systems. Each tier has a minimum maturity gate.
How does CARE keep self-assessment honest?
Practice scored without assessor-observed or instrument-verified evidence is capped at Tier 2, because assertion isn't evidence. Overall maturity also can't run more than one tier ahead of the weakest phase or the governance category, so strong engineering can't hide missing accountability.
How is CARE different from RISE?
CARE is the security and governance framework and RISE is the strategy framework. RISE decides what to build with AI and how much autonomy each use case gets. CARE writes the policies, scores the controls, and tells you whether that autonomy is safe to grant. Create pairs with Research, Adapt with Implement, Run with Sustain, and Evolve with Evaluate.

Find out which autonomy tiers you can safely run

Tell me what AI you're running or planning, and I'll tell you whether a CARE assessment is the right next step.