Release announcement · September 12, 2026
EAIMS 1.1.0 is now available. This release extends the Enterprise AI Maturity Standard with Adversarial & Agentic Governance: an additional set of requirements for assessing how organizations govern AI systems exposed to misuse, adversarial threats, privileged access, and autonomous actions.
As AI systems gain the ability to use tools and act across business processes, maturity assessment must address more than adoption. It must examine what systems are authorized to do, how their actions are attributed, what evidence is retained, and how harmful behavior can be contained.
AI maturity is not maximum automation. It is the ability to create value with appropriate autonomy, verifiable controls, and clear human accountability.
In this announcement
- What is EAIMS?
- What is new in version 1.1.0?
- What this means in practice
- Continuity and migration
- Release and validation status
- Explore the release and contribute
What is EAIMS?
EAIMS — Enterprise AI Maturity Standard is an open, vendor-neutral, evidence-grounded framework with an executable reference implementation for assessing and improving enterprise AI maturity. It connects organizational capability with business value, accountability, bounded autonomy, and operational risk.
The established EAIMS 1.0 foundation includes 8 dimensions, 30 capabilities, 5 maturity levels, and 150 capability-specific maturity anchors. Version 1.1.0 builds on that foundation with an additive governance overlay.
What is new in version 1.1.0?
1. Nine new adversarial and agentic requirements
The release introduces nine normative ADV requirements addressing the following areas:
- Adversarial exposure: assessing how an AI system may be targeted or misused.
- Blast radius: examining the potential reach and consequences of harmful actions.
- Agent credentials: governing the credentials through which agents access systems and perform actions.
- Privilege attribution: establishing traceability for the authority used by an agent.
- Adversarial evaluation: evaluating behavior under adversarial conditions.
- Runtime abuse evidence: retaining evidence relevant to misuse during operation.
- Containment: addressing the ability to constrain harmful behavior.
- Threat-intelligence disposition: documenting how relevant threat information is evaluated and addressed.
- Synthetic identity and representation: addressing risks associated with AI-generated identities and representations.
2. Extended gates for autonomous and agentic systems
Version 1.1.0 extends the G3 Autonomous / Agentic gate family with G3-13 through G3-17. These additions bring the new governance concerns into the framework’s gate structure, supported by applicability, evidence, and gate-effect guidance.
3. Stronger governance of material dependencies
The release strengthens MSP-005 and MSP-008, addressing dependency concentration, fallback and exit arrangements, and traceability across composite dependencies. This helps focus assessment on the external models, services, and interconnected components on which an AI system depends.
4. Additional implementation and assessment guidance
New supporting guidance covers applicability, evidence expectations, assessor interpretation, threat-intelligence handling, migration, crosswalks, and critical-I4 considerations. These resources help readers apply the overlay within the wider EAIMS assessment framework.
What this means in practice
Consider an enterprise AI agent that can access customer records, use external tools, and initiate operational actions. A useful maturity assessment should ask:
- What actions and privileges are within its authorized scope?
- How far could an error or malicious instruction propagate?
- Can its use of credentials and authority be traced?
- What evidence would reveal misuse during operation?
- How would harmful activity be contained?
- What happens if a critical external dependency changes or fails?
EAIMS 1.1.0 provides a more explicit governance basis for examining these questions. For organizational leaders, architects, governance teams, and assessors, the practical focus is on connecting claims about AI readiness to evidence about authority, exposure, dependencies, and control.
Continuity and migration
Historical EAIMS 1.0.x assessments retain their original meaning and are not retroactively regraded. The 1.1 overlay is additive, and frozen 1.0 reference outputs are checked through executable regression.
Organizations adopting the new release should review the overlay’s applicability and evidence guidance alongside the migration documentation. Readers returning from the 0.2.1 research baseline should also consult the earlier migration guide to understand the transition to the 1.0 framework.
Release and validation status
EAIMS 1.1.0 is published as a final, maintainer-frozen release. It is field-informed; independent third-party assessor validation and formal multi-organization empirical validation remain post-release activities.
EAIMS does not itself confer certification, regulatory conformity, legal compliance, or safety assurance. Its documentation and specification content are available under CC BY 4.0; code, tests, workflows, and JSON Schemas are available under Apache-2.0, subject to the repository’s licensing boundaries.
Explore the release and contribute
Start with the release notes, review the governance overlay, and explore the assessment guide:
- EAIMS GitHub repository
- Version 1.1.0 release notes
- Adversarial & Agentic Governance guide
- V1 assessment guide
- Contribution guidelines
Help improve the next iteration. We welcome practical feedback from AI practitioners, researchers, enterprise leaders, and independent assessors. Review the requirements, challenge their assumptions, and share implementation findings through GitHub issues. If EAIMS is useful to your work, star the repository and share it with your network.
Elias Naserkhaki
Founder and Initial Author, EAIMS
Founding Steward, eaims.org