SETTING GLOBAL STANDARDS FOR TRUSTED AI CREDENTIALSAI Competence Framework v1.29 · current release
Explainer

Why security is a domain and not a lens

D8 exists as a domain because a lens applied across the other seven domains would have been invisible in every coverage map. The choice has real costs, stated here.

Security could have been treated as a property of every other domain: a security consideration inside data handling, another inside automation, another inside solution design. That is how a good deal of professional practice treats it, and it is defensible.

We made it a domain instead, and the argument is mechanical rather than philosophical. A lens does not appear in a coverage map. A provider mapping a course to D2 and D4 can honestly report full coverage of both while teaching nothing about adversarial conditions, because the security content sat inside statements whose subject was something else. Making D8 a domain forces the omission to be visible: it appears as an exclusion, with a rationale, or it does not appear at all.

What the choice costs

It duplicates. Handling untrusted content appears in D2 as an information-quality competence and in D8 as a security competence, and the two statements are close enough that an assessor may reasonably ask why both exist. We accept the duplication because the alternative is a gap that nobody can see.

It also invites the reading that security is somebody else’s domain — a specialism to be delegated rather than a competence held at L1 by everyone who touches an AI system. Every D8 L1 statement is deliberately written for a general audience for that reason: describing how content a system reads can alter its behaviour is not a security specialist’s competence, it is a condition of using the tools at all.

Where the boundary sits

D8 covers systems under adversarial conditions, and the containment of what those systems do to everything around them. It does not cover ordinary quality failure: an output that is simply wrong is D6. If the failure requires an adversary, or creates exposure through the system’s reach, it is D8.

Agent-specific security is not in D8. It is an extension, X-AGT, because the competence set only applies where agentic systems are in use, and pulling it into core would have made the core larger than most people need. That decision is explained separately.

What this article discusses

Framework material referenced

These links run one way. The article points at the specification; the specification does not cite the article as guidance.

D8Security
D8.L1.01Describe how content an AI system reads can alter its behaviour.
D8.L1.03State that AI output may be unsafe for a downstream system or person to act on.
D8.L1.05Describe why an AI system’s access to other systems is a security concern.

Discusses framework version 0.1 · the article itself carries no version

Revision history

No revision since publication

25.08.2026First published.

A notice is never edited. An article may be, and every substantive change appears above with the date it was made.

The author

Rasmus Dahl

Editorial lead, D8 Security

Leads the editorial group for D8 and drafted the twenty-five statements entered at version 0.1.

Argued during drafting against treating security as a lens applied across the other domains, and wrote the explainer stating that argument with its costs.

Declared interests, in full
Osei Assurance PartnersDeclared

Employed as lead assurance consultant in security practice. Osei Assurance Partners holds no listing on the register and delivers no credential against this framework.

AI Certification StandardsDeclared

Unpaid appointment to the editorial group. No economic interest.

Cite this article

Rasmus Dahl (2026) “Why security is a domain and not a lens”, Explainer, AI Certification Standards. Non-normative. Available at aicertificationstandards.org/articles/why-security-is-a-domain (accessed date).

Cite the article as an article. If you need to cite the competence itself, cite the statement: a credential specification or coverage map should reference statement identifiers, never this page.

Article last updated 25.08.2026 · page last reviewed 30.08.2026 · non-normative, not part of any framework version