PAI tracks the frameworks, runtimes, model providers, safety tools, observability platforms, and workflow layers that teams actually use, then maps them against PSF evidence requirements.
A living map of the AI stack against PSF evidence.
The map separates published assessments, Lab scorecards, coverage mapping, and watchlist entries so practitioners can see what has evidence today and what is being tracked next.
Logos mark public ecosystem entries used for independent coverage mapping. Inclusion is editorial, not commercial.
24public entries
17published assessments
2Lab scorecards
2mapped entries
3watchlist
AB
Cloud AI platformPublished assessment
Amazon Bedrock
AWS · Managed model platform · May 2026
Managed platform strengths help with security, identity, and deployment control. Application-level safety evidence still has to be designed and tested.
Independent PSF assessment of a public managed platform.
Strong human proxy pattern and sandboxed code execution options. The research-to-production path still needs deployment, monitoring, and incident evidence.
Strong managed authorization story for tool access. Production systems still need oversight, business-rule gating, and action-level audit evidence above the tool layer.
Useful role-based orchestration for fast prototypes. Multi-agent execution amplifies missing boundaries, so production use needs a serious companion control layer.
Independent PSF assessment of a public framework.
D1D2D3D4D5D6D7D8
Strengths
Role clarityFast workflow assemblyMulti-agent task decomposition
A real agent runtime for developer workflows. Strong operational promise, with important gaps around filesystem, repository, and external action controls.
Independent PSF assessment of a public SDK.
D1D2D3D4D5D6D7D8
Strengths
Developer workflow fitMCP integration pathTraceable agent work
Gaps
Filesystem scopeRepository write boundariesSensitive data controls
Excellent for optimized structured pipelines. Production teams need surrounding deployment controls, security boundaries, and evidence for data handling.
Strong ecosystem and graph control primitives. Needs companion policy, data protection, and security evidence before teams call a deployment production-ready.
Independent PSF assessment of a public framework.
D1D2D3D4D5D6D7D8
Strengths
LangGraph control flowLangSmith observability pathBroad integration ecosystem
Gaps
Native PII controlsDefault tool permission boundariesFormal security model
Core D4 tooling for traces, evals, and investigation. Coverage is strongest when trace retention, incident triggers, and evaluation thresholds are written down.
Independent PSF comparison of public observability tools.
Strong retrieval and data connector story. Production readiness depends on data classification, retrieval auditability, and output validation around the application.
Valuable workflow automation layer for AI-enabled operations. The PSF question is not whether workflows run, but whether actions, data, and review gates are governed.
Independent PSF assessment of a public automation platform.
Assessed as a modern agent runtime with strong tool execution patterns, but production safety still depends on explicit controls around boundaries, data, and review.
Public assessment, no affiliation or endorsement implied.
Vector stores affect data protection, auditability, and vendor resilience. Managed compliance and self-hosting tradeoffs should be explicit before deployment.
Independent PSF comparison of public infrastructure options.
D1D2D3D4D5D6D7D8
Strengths
Retrieval infrastructure maturityManaged and self-host optionsOperational ecosystem
Gaps
Document-level access policyPII removal pathMigration test evidence
Evidence artifacts: Embedding Data Register, Access Control Map, Vector Store Exit Test
Strong schema-first model for structured extraction and validation. It is deliberately a library, so deployment and oversight remain application responsibilities.
Mapped for voice AI evidence needs, including consent, provenance, misuse controls, and incident response. This is coverage mapping, not a product certification.
Public ecosystem mapping, no affiliation or endorsement implied.