A developer/deployer has an affirmative defense if it discovers and cures a violation through internal testing/red-teaming and is otherwise in compliance with the latest NIST AI Risk Management Framework, ISO/IEC 42001, or another nationally/internationally recognised framework (or an AG-designated framework).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.