Printed from Production AI Institute public record

https://www.productionai.institute/insights/psf-compliance-explained

Production AI Institute · Public recordRecord
Production AI Institute
Briefing
Briefing

Today's public AI briefing: what changed, what went wrong, and what the evidence says.

Open Briefing →
Today's AI briefingThe daily record of what changed and broke.Public record explorerSearch every incident, entity, and source.
Check
Check

Inspect tools, incidents, and data-use disclosures against the public record.

Open Check →
Check an AI toolWhat a tool actually does with your data.Run exposure checkTest your own stack against the record.Data-use indexDisclosures across the major AI tools.Incident registryDocumented production AI failures.
The Lab
The Lab

Independent research instruments: model and agent scorecards, moral-reasoning evals, and ecosystem assessments.

Open The Lab →
The LabHow frontier models and agents actually perform.AI Morality CompassTest models on hard moral cases.Agent readinessIs the agent ecosystem production-ready?Ecosystem assessmentsIndependent reviews of the AI stack.Model & agent evalsOpen evaluations and their results.Research libraryEvidence-led analysis and briefings.
Learn
Learn

The open standard, the tools built on it, and the research that interprets the record.

Open Learn →
The FrameworkThe open production safety framework, explained.AI Adoption GuideFive stages from gated access to safe autonomy.Production AI Deployment GuideBuild a governed production system on Microsoft or AWS.Five-Year Automation RoadmapSequence enterprise capability, controls, and value.WorkflowOS · open sourceBuild governed AI workflows.Workflow libraryReady-made governed workflows.InsightsResearch articles on the record.
Act
Act

Turn uncertainty into public evidence: ask, disclose, build evidence, or correct.

Open Act →
Ask for disclosureRequest a public data-use answer.Submit a correctionFlag something wrong or missing on the record.Save a watchTell PAI what to keep current for you.
Method
Method

How the public record is made, governed, corrected, cited, and kept independent.

Open Method →
How records are madeSourcing, review, and correction.
Check an AI tool
Record
Record
Check an AI tool
Production AI public record - EditorialMethod →

Insights / PSF Compliance

STANDARD

PSF Compliance Explained

PSF compliance means an AI system has been assessed against the Production Safety Framework — the eight-domain standard for deploying AI in production environments. This guide explains what compliance requires, how it is assessed, and which practitioner certifications map to each domain.

Production AI Institute · 8 min read · Updated May 2026

What Is the PSF?

The Production Safety Framework (PSF) is a structured standard developed by Production AI Institute that defines the minimum controls required before an AI system can be considered production-ready. It was designed to fill the gap between ad-hoc deployment practices and the rigour that regulated industries, enterprise buyers, and procurement teams expect.

The PSF is organised into eight domains, each covering a distinct control surface. A PSF-compliant system has documented, tested controls in all eight. Partial compliance — covering some domains but not others — is documented in an assessment but does not meet the full standard.

The Eight PSF Domains

PSF-1Input Governance

Validation, sanitisation, prompt-injection defence, and intent classification at the system boundary. Every input path must be treated as a potential attack surface.

PSF-2Output Validation

Structured checks on model outputs before they reach users or downstream systems. Covers hallucination detection, format enforcement, and toxicity filtering.

PSF-3Data Protection

Controls on what data the AI system can access, retain, and transmit. Includes PII handling, data minimisation, and cross-tenant isolation.

PSF-4Observability

Logging, tracing, and monitoring sufficient to reconstruct what the system did and why. A system that cannot be observed cannot be trusted in production.

PSF-5Deployment Safety

Rollback capability, staged rollouts, environment parity, and release gating. Production AI systems need the same deployment rigour as any other production software.

PSF-6Human Oversight

Defined escalation paths, human-in-the-loop checkpoints, and override mechanisms. Autonomy without oversight is not production-ready.

PSF-7Security

Authentication, authorisation, secret management, and adversarial input handling. LLM-specific attack classes require controls beyond standard application security.

PSF-8Vendor Resilience

Dependency mapping, fallback providers, SLA monitoring, and continuity planning for third-party model and infrastructure dependencies.

How PSF Compliance Is Assessed

PSF compliance assessments follow a structured evidence-review process. For each domain, the assessor reviews documented controls, architecture diagrams, test results, and operational procedures. Self-attestation without supporting evidence does not satisfy the standard.

Production AI Institute offers the Deployment Safety Assessment (DSA) for organisations that want a formal third-party PSF review. The DSA produces a domain-by-domain scorecard, a gap analysis, and a remediation roadmap.

For practitioners who want to demonstrate individual PSF knowledge, the Certified LLM Operations Engineer (CLOE) and Certified AI Safety Specialist (CAIS) certifications cover the framework in depth.

Certifications That Demonstrate PSF Knowledge

Individual practitioners can demonstrate PSF competency through Production AI Institute certifications. Each certification maps to specific PSF domains:

CLOE — Certified LLM Operations Engineer

Covers: PSF-1, PSF-2, PSF-4, PSF-5

View cert
CAIS — Certified AI Safety Specialist

Covers: PSF-1, PSF-2, PSF-6, PSF-7

View cert
CAIG — Certified AI Governance Professional

Covers: PSF-3, PSF-6, PSF-8

View cert
CAAE — Certified Applied AI Engineer

Covers: PSF-1, PSF-2, PSF-4, PSF-5

View cert
CAIA — Certified AI Auditor

Covers: All eight domains (audit perspective)

View cert

PSF Compliance vs. Regulatory Compliance

PSF compliance is a technical and operational standard, not a legal one. It does not replace EU AI Act obligations, GDPR requirements, or sector-specific regulations. It does, however, provide documented evidence of controls that regulators and auditors commonly look for.

Organisations subject to the EU AI Act will find that PSF-compliant systems satisfy a substantial portion of the technical documentation requirements for high-risk AI systems. The PSF was designed with regulatory alignment in mind, though independent legal review is always required for compliance determinations. See our analysis: EU AI Act and Production AI.

Public record

This record is maintained by PAI and free to cite. If something is wrong or missing, tell us. Corrections and source suggestions keep the record honest.

Follow policy changes ->Save a watch ->Submit a correction
Records are free to cite. citation guidance.
PAI
Production AI Institute

The public record and operating memory for production AI: what changed, what broke, and what the evidence says.

WorkflowOS · open source (MIT)
Navigate
Briefing
OverviewToday's AI briefingPublic record explorer
Check
Check an AI toolRun exposure checkData-use indexIncident registry
The Lab
The LabAI Morality CompassAgent readinessEcosystem assessmentsModel & agent evalsResearch library
Learn
The FrameworkAI Adoption GuideProduction AI Deployment GuideFive-Year Automation RoadmapWorkflowOS · open sourceWorkflow libraryInsights
Act
Ask for disclosureSubmit a correctionSave a watch
Method & trust
How records are madeCorrectionsHow to citeContact
© 2026 Production AI Institute · CC BY 4.0
AboutPrivacyTermsSecurityGovernanceIndependence