rai-standards

Référence consolidée des normes d'IA responsable : NIST AI RMF 1.0, couche de modélisation des menaces AI STRIDE, niveaux de risque de l'EU AI Act, et un catalogue de normes ouvertes avec…

npx skills add https://github.com/microsoft/hve-core --skill rai-standards

RAI Standards Skill

This skill is the reusable standards package for the RAI Planner. It consolidates the embedded NIST AI RMF content, the AI STRIDE threat-modeling overlay, and a paraphrased EU AI Act reference so the phase playbook can stay focused on workflow and orchestration.

Attribution and licensing posture

  • NIST AI RMF 1.0 is a U.S. Government document and is reproduced here as public-domain reference material with attribution. Public-domain material carries no license obligation, so it adds no term to the package license expression.
  • EU AI Act content in this skill is paraphrased and attributed rather than quoted verbatim, consistent with the open legal-text posture used in the repository. The paraphrase is this repository's own expression.
  • The AI STRIDE overlay is Microsoft-authored reference material for threat-modeling reuse in the RAI workflow.

Every file in this package is therefore governed by the repository-original license. The table records the source each file draws on.

PathLicenseOrigin
references/nist-ai-rmf-govern.mdCC-BY-4.0Adapted from NIST AI RMF 1.0 (public domain)
references/nist-ai-rmf-map.mdCC-BY-4.0Adapted from NIST AI RMF 1.0 (public domain)
references/nist-ai-rmf-measure.mdCC-BY-4.0Adapted from NIST AI RMF 1.0 (public domain)
references/nist-ai-rmf-manage.mdCC-BY-4.0Adapted from NIST AI RMF 1.0 (public domain)
references/eu-ai-act.mdCC-BY-4.0Paraphrase of EU AI Act 2024/1689, not reproduced
references/ai-stride-overlay.mdCC-BY-4.0Repository-original
SKILL.md and remaining package contentCC-BY-4.0Repository-original

Framework index

NIST AI RMF trustworthiness characteristics

KeyCharacteristicDescription
validReliableValid and ReliableBase characteristic for correctness, robustness, and stability
safeSafeSafety and harm prevention under normal and adversarial conditions
secureResilientSecure and ResilientResistance to attack, misuse, and failure
accountableTransparentAccountable and TransparentGovernance, auditability, and decision provenance
explainableInterpretableExplainable and InterpretableUnderstandability of model behavior and outputs
privacyEnhancedPrivacy-EnhancedProtection of personal data and confidentiality
fairBiasManagedFair with Harmful Bias ManagedBias detection, mitigation, and equitable outcomes

Phase-to-framework mapping

RAI phasePrimary standards packageNotes
Phase 1 ScopingNIST AI RMF Govern + MapContext, purpose, stakeholders, and policy framing
Phase 2 Risk ClassificationNIST AI RMF GovernGovernance culture, DEI&A, and stakeholder engagement
Phase 3 Standards MappingNIST AI RMF Govern + MeasureCore standards mapping and TEVV alignment
Phase 4 Security Model AnalysisAI STRIDE overlay + MeasureThreat modeling and overlap with security analysis
Phase 5 Impact AssessmentNIST AI RMF ManageRisk prioritization, mitigation, and monitoring
Phase 6 Review and HandoffNIST AI RMF Manage + EU AI ActRegulatory review, incident response, and evidence handoff

Customer extension pattern

The default framework remains NIST AI RMF 1.0. When a customer supplies an additional framework, preserve the default NIST mapping as a baseline and layer the custom framework on top with explicit attribution. This keeps the planner interoperable while allowing organizations to add ISO, sector, or regional references without rewriting the core playbook.

Open-standards catalog

Use the links below as the reference catalog for open standards and governance resources. Do not reproduce normative text verbatim when the license posture does not allow it.

Plus de skills de microsoft

oss-growth
microsoft
Persona de growth hacker OSS
agent-framework-azure-ai-py
microsoft
Créez des agents Azure AI Foundry à l’aide du SDK Python Microsoft Agent Framework (agent-framework-azure-ai). À utiliser lors de la création d’agents persistants avec AzureAIAgentsProvider, de l’utilisation d’outils hébergés (interpréteur de code, recherche de fichiers, recherche web), de l’intégration de serveurs MCP, de la gestion de fils de conversation ou de l’implémentation de réponses en streaming. Couvre les outils de fonction, les sorties structurées et les agents multi-outils.
development
airunway-aks-setup
microsoft
Configurez AI Runway sur AKS — du cluster nu au modèle en cours d'exécution. Couvre la vérification du cluster, l'installation du contrôleur, l'évaluation GPU, la configuration du fournisseur et le premier déploiement. QUAND : « configurer AI Runway », « intégrer un cluster AKS », « installer AI Runway », « configuration airunway », « déployer un modèle sur AKS », « inférence GPU sur AKS », « configuration KAITO sur AKS », « exécuter LLM sur AKS », « vLLM sur AKS », « configurer le service de modèles sur AKS », « contrôleur AI Runway ».
devops
appinsights-instrumentation
microsoft
Conseils pour instrumenter les applications web avec Azure Application Insights. Fournit des modèles de télémétrie, la configuration du SDK et des références de configuration. QUAND : comment instrumenter une application, SDK App Insights, modèles de télémétrie, qu'est-ce qu'App Insights, conseils sur Application Insights, exemples d'instrumentation, bonnes pratiques APM.
devops
applicationinsights-web-ts
microsoft
Instrumentez les applications navigateur/web avec le SDK JavaScript Application Insights (@microsoft/applicationinsights-web). Utilisez-le pour la surveillance des utilisateurs réels (RUM) — vues de page, clics, dépendances AJAX/fetch, exceptions, événements personnalisés et traces d’agents GenAI côté navigateur corrélées aux traces OpenTelemetry backend. Couvre le script de chargement du SDK et la configuration npm, les extensions de framework (React, React Native, Angular), Click Analytics, les initialiseurs de télémétrie et les conventions sémantiques OTel GenAI pour les spans d’agents/outils/modèles émises depuis le navigateur.
devops
azure-ai-anomalydetector-java
microsoft
Créez des applications de détection d'anomalies avec le SDK Azure AI Anomaly Detector pour Java. Utilisez-le lors de l'implémentation de la détection d'anomalies univariées/multivariées, de l'analyse de séries temporelles ou de la surveillance basée sur l'IA.
development
azure-ai-language-conversations-py
microsoft
Implémentez la compréhension du langage conversationnel (CLU) à l’aide du SDK Python azure-ai-language-conversations. Utilisez-le lorsque vous travaillez avec ConversationAnalysisClient pour analyser l’intention et les entités d’une conversation, créer des fonctionnalités de NLP ou intégrer la compréhension du langage dans des applications.
development
azure-ai-ml-py
microsoft
SDK v2 d’Azure Machine Learning pour Python. Utiliser pour les espaces de travail ML, les tâches, les modèles, les jeux de données, le calcul et les pipelines. Déclencheurs : « azure-ai-ml », « MLClient », « espace de travail », « registre de modèles », « tâches d’entraînement », « jeux de données ».
development