rai-standards

Consolidates NIST AI RMF, AI STRIDE, and EU AI Act references for responsible AI planning.

1.4k|284|Updated Nov 2, 2025
One-click install
npx skills add https://github.com/microsoft/hve-core --skill rai-standards
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: rai-standards
Source: https://github.com/microsoft/hve-core/tree/main/.github/skills/rai/rai-standards
Command: npx skills add https://github.com/microsoft/hve-core --skill rai-standards

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Teams running Responsible AI reviews need consistent, authoritative standards content without scattering NIST AI RMF subcategories, threat-modeling overlays, and EU AI Act obligations across multiple documents.

Core Features & Use Cases

  • NIST AI RMF 1.0 Reference Set: Provides Govern, Map, Measure, and Manage function subcategories as structured reference tables.
  • AI STRIDE Threat-Modeling Overlay: Extends STRIDE analysis with AI-specific concerns like data poisoning, model tampering, and inference exfiltration, using a dual threat-ID convention.
  • EU AI Act Risk Tiers: Paraphrased overview of risk tiers and high-risk obligation themes with links to authoritative legal text.
  • Use Case: During a Phase 4 Security Model Analysis, load the AI STRIDE overlay to merge RAI-specific threats into the Security Planner's output while preserving both RAI-managed and cross-referenced threat IDs.

Quick Start

Ask the RAI Planner to map your AI system's risks against the NIST AI RMF Govern and Measure functions using this standards reference.

Frequently Asked Questions about rai-standards

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the NIST AI RMF and how is it used in AI risk planning?

NIST AI RMF 1.0 is a U.S. Government framework organizing AI risk management into Govern, Map, Measure, and Manage functions. This skill provides each function's subcategories as reference tables that the RAI Planner maps to workflow phases.

How do I apply STRIDE threat modeling to AI systems?

Apply the AI STRIDE overlay, which extends standard STRIDE categories with AI-specific concerns like data poisoning, model tampering, and inference exfiltration. Treat training, inference, and monitoring boundaries as trust boundaries and use the dual threat-ID convention.

What are the EU AI Act risk tiers?

The EU AI Act defines four tiers: unacceptable risk (prohibited), high risk (strong governance obligations), limited risk (transparency obligations), and minimal risk (little additional burden). High-risk systems require risk management, data governance, human oversight, and recordkeeping.

Can I add a custom framework like ISO 42001 alongside NIST AI RMF?

Yes. Keep the default NIST AI RMF mapping as the baseline and layer the customer framework on top with explicit attribution. The open-standards catalog links ISO/IEC 42001, 23894, and 42005 for this extension pattern.

Does this skill provide authoritative EU AI Act legal text?

No. The EU AI Act content is a paraphrased summary with attribution, not verbatim legal text. For authoritative clause lookups and jurisdiction-specific interpretation, delegate to the rpi-research skill and consult the EUR-Lex regulation page.