Back to articles
Your AI Is "In Production." That Doesn't Mean It's Production-Ready.

Your AI Is "In Production." That Doesn't Mean It's Production-Ready.

A working draft framework that asks one hard question—can this AI safely operate in production?—and refuses to answer with a vanity percentage.

APRF exists to answer one gated question—can this AI safely operate in production?—without a vanity readiness percentage.

AI Production Readiness Framework

Related APRF controls

Most teams ship an LLM feature the same way they ship a landing page: merge the PR, watch the demo, celebrate.

Then reality shows up.

A prompt injection drains a customer's CRM. A coding agent commits secrets. A "support bot" hallucinates a refund policy into a lawsuit. A forgotten API key burns $82k overnight.

None of those failures look like "the model wasn't smart enough." They look like production systems without production gates.

The question most frameworks don't force you to answer

NIST AI RMF tells you how to *think* about risk. ISO/IEC 42001 tells you how to *manage* an AI system. SOC 2 tells auditors how to *trust your company*.

Useful. Necessary. Incomplete for the engineer on call.

The question that actually decides whether you sleep at night is simpler:

Can this AI application safely operate in production?

That's the question behind the AI Production Readiness Framework (APRF) — a vendor-neutral working draft published by StackRail.

It's not a certification. It's not a partner network. It's not a 0–100 "readiness score" you put in a board deck.

It's a gated methodology: mandatory checks either pass or they block you. Recommended controls never average into the gate.

What "gated" means (and why it matters)

If you've ever been sold an "AI maturity score," you already know the failure mode:

- Secrets hygiene is a disaster

- But your eval dashboard looks pretty

- Somehow you still get 87% ready

APRF forbids that trade.

Mandatory checks are pass/fail. Failures are blockers. Capability attainment is the minimum across pillars — not a mean. You never publish a single overall percentage.

If that sounds strict: good. Production is strict.

What's in the catalog (as of v0.10)

- 8 domains (security, safety, data, model lifecycle, agents, reliability, cost, governance)

- 27 pillars

- Core Profile: 40 gates for Tier‑2 customer-facing AI

- Regulated Profile: 61 gates for Tier‑3 / regulated systems

- Lenses for RAG, Agents, Voice, Coding agents

- Machine-readable spec + self-attestation JSON

- Crosswalks to NIST AI RMF, ISO 42001, OWASP LLM Top 10, SOC 2, AWS Well-Architected, SLSA — informative only, not certification

From chaotic AI tooling to gated production readiness
From chaotic AI tooling to gated production readiness

A concrete example

"We have an agent with tools." APRF doesn't congratulate you. It asks:

- Is there a charter and step budget?

- Are tools allowlisted and schema-validated?

- Are high-impact actions behind non-bypassable human approval?

- Can you kill the agent when it loops?

- Are spend ceilings in place so a runaway loop can't denial-of-wallet you?

If you can't demonstrate those with artifacts (configs, logs, drills), you don't get a soft yellow score. You get gate fail.

Try it in 15–30 minutes

We published a reference self-assessment (Core or Regulated, optional lenses). It's self-attestation — not certification — and you can download the full attestation JSON.

- Take the APRF assessment

- Read the framework

- Machine-readable spec

Who this is for

- Founders shipping AI before enterprise security asks hard questions

- Platform / MLOps teams tired of vibes-based "we're careful"

- Security folks who need AI controls that map to evidence, not prose

Who this is not for

Anyone looking for a badge that says "we're compliant with everything." APRF won't pretend. That's the point.

---

*APRF is a working draft. Publisher today: StackRail. Intended long-term steward: a neutral working group via public RFCs. Contribute: /aprf/rfc/.*

*Also published on Medium.*

Need help with production readiness? Get a free 30-minute audit.

Book Free 30-Min Production Audit

View our DevSecOps services

Assess against APRF Core

Run the Core Profile quiz — gated pass/fail blockers for AI production readiness, not a vanity score.