Skip to main content

By Sector / Foundation Models

Foundation Model Governance

General-purpose LLM platforms scored against cross-cutting US AI governance frameworks. Foundation models score lower than sector-vertical vendors because sector-specific obligations (Section 1557, SR 11-7, ABA Op 512) are downstream deployer responsibilities, scored N/A here.

Edition: 2026-Q2Vendors: 5Sector-weighted composite
By Stefan Efros, CEO & Founder, EFROSReviewed by Daniel Agrici, Chief Security Officer, EFROS
Reviewed by CSO ·

Why this sector view

Foundation model selection is the most cross-cutting AI decision US enterprises make — the choice cascades through every downstream productivity, vertical, and custom application. The composite uses baseline (unamplified) weights since foundation models are general-purpose; the sector-specific scoring axes are scored N/A and excluded from the composite denominator.

Primary frameworks anchored

  • NIST AI RMF 1.0 + GAI Profile (NIST AI 600-1)
  • Colorado AI Act SB 24-205
  • NYC Local Law 144, CA AB 2013, IL HB 3773, TN ELVIS Act, UT SB 149
  • EO 14110 + OMB M-24-10 (federal procurement)
  • ISO/IEC 42001 (international AI MS)
Foundation Models vendor scoring — composite descending
#VendorScoreGradeBAAOpt-outUS ResSOC 2ISO 42001NIST AICO AI§1557SR 11-7ABA 512SubprocTC
1Anthropic Claude58CPartialYesPartialYesNoPartialNoN/AN/AN/AYes4/5
2Google Gemini for Workspace58CPartialPartialYesYesNoPartialNoN/AN/AN/AYes4/5
3OpenAI ChatGPT & API53DPartialPartialPartialYesNoPartialNoN/AN/AN/AYes4/5
4Meta Llama25FNoYesYesNoNoNoNoN/AN/AN/ANo2/5
5Perplexity AI19FNoPartialNoPartialNoNoNoN/AN/AN/APartial2/5

Buyer's guide for this sector

For foundation model selection, the highest-leverage scoring axes are BAA tier coverage (enterprise vs consumer gap is the #1 shadow-AI source), training opt-out default, US data residency configuration, and trust-center maturity. Sector overlays are deployer responsibility — but the foundation vendor's posture on cross-cutting axes determines how much governance work the deploying organization inherits.

Operationalize the scoring

NIST AI RMF Implementation Guide

The Index tells you which vendors clear the bar. The companion resource tells you how to turn that selection into a deployable governance program with documented evidence.

NIST AI RMF Implementation Guide →

Scoring as of 2026-05-13 from public information (vendor trust portals, BAAs, SOC report cover pages, model cards, vendor documentation). Posture changes frequently — re-verify with the vendor's trust center before contract. Methodology: read the full methodology.

Turn the scoring into a deployable program

The Index tells you the posture. These engagements turn the posture into operational evidence.