- What is the CARE framework for AI security and governance?
- CARE is a four-phase framework for governing and securing AI: Create, Adapt, Run, and Evolve. It has 87 controls in 16 categories, scores policy and practice separately, caps self-attested scores, and sets a minimum maturity gate for each of four autonomy tiers, from copilots to multi-agent systems.
- What does CARE stand for?
- Create, Adapt, Run, Evolve. Create builds the foundations and surfaces the needs and gaps. Adapt adjusts the program and its systems to what Create learned, including how systems reach production. Run operates and monitors them. Evolve improves the program from evidence.
- Is this the same as the CARE Principles for Indigenous Data Governance?
- No. The CARE Principles for Indigenous Data Governance (Collective Benefit, Authority to Control, Responsibility, Ethics) set out Indigenous Peoples' rights and interests in data. The CARE framework on this page is a security and governance framework for the AI systems and agents inside an organization. The two share an acronym and nothing else.
- Does CARE map to ISO/IEC 42001, the NIST AI RMF, and the EU AI Act?
- Yes. Every CARE control maps to the frameworks and laws an auditor is likely to raise, including ISO/IEC 42001, the NIST AI RMF, NIST CSF 2.0, the EU AI Act, the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, and MITRE ATLAS. The mapping covers 24 frameworks and laws, so a team already running ISO/IEC 27001 or the NIST CSF extends what it has.
- What are the CARE autonomy tiers?
- T1 covers assistants and copilots where a human executes every action. T2 covers platform and citizen-built agents that call tools inside a governed platform. T3 covers custom and code-executing agents with MCP, external communication, or production access. T4 covers multi-agent and cross-boundary systems. Each tier has a minimum maturity gate.
- How does CARE keep self-assessment honest?
- Practice scored without assessor-observed or instrument-verified evidence is capped at Tier 2, because assertion isn't evidence. Overall maturity also can't run more than one tier ahead of the weakest phase or the governance category, so strong engineering can't hide missing accountability.
- How is CARE different from RISE?
- CARE is the security and governance framework and RISE is the strategy framework. RISE decides what to build with AI and how much autonomy each use case gets. CARE writes the policies, scores the controls, and tells you whether that autonomy is safe to grant. Create pairs with Research, Adapt with Implement, Run with Sustain, and Evolve with Evaluate.