Taxonomy-Driven Analysis of Open-Source AI Risk Mitigation Tools

📅 2026-08-07
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the multidimensional risks—operational, security, and governance-related—that enterprises face when deploying large language models, noting that existing open-source tools are fragmented and fail to comprehensively cover authoritative risk taxonomies. To bridge this gap, the work proposes a structured mapping protocol that automatically aligns the capabilities of 21 prominent open-source tools with the 32 subcategories of the MIT AI Risk Framework, leveraging retrieval-augmented generation (RAG) and LLM-based parsing. The protocol’s validity is substantiated through source code and documentation analysis, majority voting, and inter-rater reliability assessment using Fleiss’ Kappa (κ = 0.509, F1 = 75.5%). Findings reveal a pronounced overconcentration of current tools on technical controls, with significant gaps in governance, legal, and market risk domains, thereby providing an empirical foundation for developing layered AI risk mitigation architectures.
📝 Abstract
Rapid adoption of large language models (LLMs) in enterprise settings has introduced operational, security, and governance risks. As generative AI applications move from pilot to production, manual harm identification and mitigation are becoming difficult to scale. Although many tools support model evaluation, adversarial testing, runtime guardrails, and observability, the tooling landscape remains fragmented. Tools are typically designed for specific engineering tasks and described in technical terms that do not align with governance frameworks or risk taxonomies, making it difficult to determine which tools address which risks and where critical gaps remain. This paper proposes a structured protocol to automate AI risk mitigation through a taxonomy-driven analysis of open-source LLM evaluation and security tools. We map the capabilities of 21 prominent open-source tools to the 32 subcategories of the extended MIT AI Risk Mitigation and Response Taxonomy. An LLM-assisted retrieval-augmented generation pipeline analyzes source code and documentation to extract capabilities for each taxonomy category. Reliability assessment yielded moderate agreement (Fleiss' Kappa = 0.509) among three independent reviewers. The analysis reveals a highly skewed landscape in which tools cluster around technical and operational controls, while governance, legal and regulatory, and financial and market controls remain largely unaddressed. This motivates a layered risk-mitigation architecture combining tool-based controls with organizational and regulatory processes. The mapping protocol achieved an F1 score of 75.5% after majority voting. Overall, the study provides a practical mapping between enterprise AI risk categories and open-source mitigation capabilities, identifies where human oversight remains necessary, and presents a taxonomy-driven framework applicable to open-source and proprietary solutions.
Problem

Research questions and friction points this paper is trying to address.

AI risk mitigation
large language models
risk taxonomy
open-source tools
governance
Innovation

Methods, ideas, or system contributions that make the work stand out.

taxonomy-driven analysis
retrieval-augmented generation
AI risk mitigation
open-source LLM tools
structured mapping protocol
🔎 Similar Papers
2024-08-14AGI - Artificial General Intelligence - Robotics - Safety & AlignmentCitations: 27
A
Afreen Alam
Department of Administrative Sciences, Metropolitan College, Boston University, Boston, MA 02215, USA
E
Evgenija Popchanovska
Faculty of Computer Science and Engineering, Ss. Cyril and Methodius University, Skopje 1000, North Macedonia
A
Ana Gjorgjevikj
Faculty of Computer Science and Engineering, Ss. Cyril and Methodius University, Skopje 1000, North Macedonia
M
Maryan Rizinski
Department of Computer Science, Metropolitan College, Boston University, Boston, MA 02215, USA
L
Lubomir T. Chitkushev
Department of Computer Science, Metropolitan College, Boston University, Boston, MA 02215, USA
Irena Vodenska
Irena Vodenska
Boston University
Environmental Social and Governance (ESG) investingDisinformation in the era of climate crisisNews Sentiments and Systemic R
Dimitar Trajanov
Dimitar Trajanov
Prof.@ Ss. Cyril and Methodius University in Skopje & Visiting Research Prof.@ Boston University, US
Data scienceAI AgentsNLPSemantic webOpen data