The PSF defines the domains of practice a production AI deployment must address to be considered safe, responsible, and professionally maintainable. It is model-agnostic, cloud-agnostic, and applies to any organisation deploying AI in a production environment - regardless of which models, platforms, or vendors they use.
The Framework defines what teams implement across a production AI system. PAI-8 defines what organisations govern, evidence, audit, and report. The two standards are parallel layers of the same operating model.
Read the PAI-8 standard →The standard is text. WorkflowOS is the working artifact — design workflows, run PSF analysis, simulate runs, and export evidence. Free on the web, or fork the MIT-licensed source and self-host for clients.
Use it to interpret the public record, review your own deployment, and name the controls in your documentation.
Interpret the record
Public records on incidents, disclosures, and policy changes are mapped to the PSF domains they implicate.
Open record explorer →Review a deployment
Run the readiness check to separate implemented controls from assumed ones before an incident does it for you.
Run readiness check →Map your vendors
Map vendors and tools to PSF domains to find the controls that remain your responsibility.
Map a vendor →Cite the standard
The framework is open and citable in policies, reviews, and research. Version history is published.
How to cite →Major cloud platforms document how to configure their own products. What they do not provide is a common safety standard for the moments when the underlying model changes, a vendor's service goes down, or a use case involves personal data the system was not designed to handle.
Production AI deployment is a discipline - not a vendor configuration exercise. The same principles of input governance, output validation, data protection, observability, deployment safety, human oversight, security, and vendor resilience apply whether you are running GPT-4o through OpenAI's API, Claude through AWS Bedrock, Llama on your own infrastructure, or Qwen through a European hosting provider.
The Production Safety Framework was developed to fill this gap. It describes the eight domains of practice that any serious production AI deployment should address, in terms that are independent of any specific vendor, platform, or model family.
The framework is published openly and free to reference. It gives deployment reviews, Lab scorecards, incident analysis, and procurement teams a shared language that is independent of any vendor's product.
Each domain contains practical control areas that can be used in deployment reviews, evidence checks, incident analysis, and Lab assessments.
Every input reaching an AI model must be validated, sanitised, and treated as untrusted.
Raw model output is never trusted. Every output is validated before it acts on any system.
Personal and sensitive data is protected throughout the AI pipeline, not just at rest.
You cannot manage what you cannot measure. Every AI system in production must be observable.
Every model change is a risk. Production AI deployments require the same rigour as critical software.
Automation does not mean unaccountable. High-stakes AI decisions require human checkpoints.
AI systems introduce new attack surfaces. Standard security practices must extend to cover them.
A production AI system that only works with one vendor is a liability, not an asset.
The Production Safety Framework is published under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. You may freely share, adapt, and build on the framework for any purpose, including commercial use, provided you attribute the Production AI Institute.
If you are referencing the PSF in a job description, procurement document, research paper, or internal policy, see our citation guidance for the recommended attribution format.
Tool policy changes, new incident records, disclosure signals, and practical next steps. Public evidence, plain English, no hype.