Why security is a domain and not a lens
D8 exists as a domain because a lens applied across the other seven domains would have been invisible in every coverage map. The choice has real costs, stated here.
Security could have been treated as a property of every other domain: a security consideration inside data handling, another inside automation, another inside solution design. That is how a good deal of professional practice treats it, and it is defensible.
We made it a domain instead, and the argument is mechanical rather than philosophical. A lens does not appear in a coverage map. A provider mapping a course to D2 and D4 can honestly report full coverage of both while teaching nothing about adversarial conditions, because the security content sat inside statements whose subject was something else. Making D8 a domain forces the omission to be visible: it appears as an exclusion, with a rationale, or it does not appear at all.
What the choice costs
It duplicates. Handling untrusted content appears in D2 as an information-quality competence and in D8 as a security competence, and the two statements are close enough that an assessor may reasonably ask why both exist. We accept the duplication because the alternative is a gap that nobody can see.
It also invites the reading that security is somebody else’s domain — a specialism to be delegated rather than a competence held at L1 by everyone who touches an AI system. Every D8 L1 statement is deliberately written for a general audience for that reason: describing how content a system reads can alter its behaviour is not a security specialist’s competence, it is a condition of using the tools at all.
Where the boundary sits
D8 covers systems under adversarial conditions, and the containment of what those systems do to everything around them. It does not cover ordinary quality failure: an output that is simply wrong is D6. If the failure requires an adversary, or creates exposure through the system’s reach, it is D8.
Agent-specific security is not in D8. It is an extension, X-AGT, because the competence set only applies where agentic systems are in use, and pulling it into core would have made the core larger than most people need. That decision is explained separately.
Framework material referenced
These links run one way. The article points at the specification; the specification does not cite the article as guidance.
Discusses framework version 0.1 · the article itself carries no version
No revision since publication
A notice is never edited. An article may be, and every substantive change appears above with the date it was made.