Catalogue of Tools & Metrics for Trustworthy AI

These tools and metrics are designed to help AI actors develop and use trustworthy AI systems and applications that respect human rights and are fair, transparent, explainable, robust, secure and safe.

Pegasus



Pegasus is an open-source compliance framework for AI security validation. It evaluates security evidence against formal requirements drawn from standards, regulations, and best-practice frameworks, including ISO/IEC 42001, the EU AI Act, NIST AI RMF, OWASP LLM Top 10, OWASP ASVS, PCI DSS, SOC 2, and SLSA. The framework uses Rego-based policies and certification profiles to assess whether collected evidence satisfies specified controls and requirements. Pegasus includes a policy engine, evidence store, certification evaluation capabilities, and benchmarking tools, enabling organisations to translate security findings into compliance assessments and assurance artefacts.

Key capabilities:

  • Automated policy-based compliance evaluation with pass/fail/warn/skip results
  • Multi-standard certification scoring with configurable pass thresholds
  • Dual-agent cross-review architecture (security + compliance) with confidence scoring
  • Content-addressable evidence store (SHA-256) for tamper-evident audit trails
  • 22 MITRE ATLAS/ATT&CK technique mappings for AI and infrastructure threats
  • Extensible policy library with community contributions welcome

Use Cases

There is no use cases for this tool yet.

Would you like to submit a use case for this tool?

If you have used this tool, we would love to know more about your experience.

Add use case
Partnership on AI

Disclaimer: The tools and metrics featured herein are solely those of the originating authors and are not vetted or endorsed by the OECD or its member countries. The Organisation cannot be held responsible for possible issues resulting from the posting of links to third parties' tools and metrics on this catalogue. More on the methodology can be found at https://oecd.ai/catalogue/faq.