Score
Designs, builds, and applies frameworks, methods, and tools to identify, analyze, score, and report risks across technical, security, safety, regulatory, legal, ethical, and AI-specific contexts. Produces risk taxonomies, assessment methodologies, scoring models, vulnerability assessments, management frameworks, and reporting artifacts that support mitigation decisions, compliance, and ongoing monitoring.
This study addresses the growing global demand for risk-based AI regulation by systematically identifying, analyzing, and integrating the multifaceted risks of artificial intelligence across technical, ethical, and societal dimensions. Through a comprehensive literature review and framework analysis, it establishes the first systematic alignment between major international regulatory frameworks and AI risk typologies from academic research, thereby constructing a structured risk taxonomy. The work clarifies key dimensions and limitations of existing risk assessment methodologies, distills best practices, and identifies critical research gaps. By doing so, it provides a robust theoretical foundation and strategic guidance for the development of standardized, actionable AI risk management tools aligned with evolving regulatory expectations.
The widespread deployment of foundation models introduces multifaceted AI risks, yet existing taxonomies lack practical guidance for practitioners to identify context-specific risks in real-world usage scenarios. Method: We propose the first risk identification framework tailored to foundation model *use governance*, grounded in four design principles that shift AI risk identification from static classification toward dynamic, scenario-aware, and actionable analysis. Integrating AI risk taxonomy, use governance theory, and requirements-driven engineering—validated through a case-driven paradigm—we develop an extensible prototype. Contribution/Results: Evaluated across representative deployment use cases, the prototype effectively identifies critical risks—including privacy leakage and algorithmic bias—demonstrating significantly enhanced practicality and operational feasibility. This work advances AI safety governance by delivering both a methodological foundation and an implementable tool for risk-aware foundation model deployment.
State-of-the-art AI systems lack systematic risk management frameworks commensurate with those employed in high-consequence domains (e.g., aviation, nuclear energy). Method: We propose the first end-to-end risk governance framework tailored to frontier AI development lifecycles. It innovatively adapts classical risk governance mechanisms—including pre-deployment risk assessment, explicit safety thresholds, and structured red-teaming—to AI R&D workflows, mandating risk mitigation initiation prior to final model training. The framework comprises four integrated phases: risk identification, analysis and evaluation, mitigation and response, and governance and accountability. It synthesizes literature review, quantitative risk modeling, containment mechanisms, deployment controls, assurance verification, and organizational governance design. Contribution/Results: Empirical validation demonstrates significant improvements in risk coverage and response latency, alongside reduced probability of high-risk AI misalignment or loss of control—providing a practical, implementable roadmap for safe and responsible frontier AI development.
This study addresses the multidimensional risks—operational, security, and governance-related—that enterprises face when deploying large language models, noting that existing open-source tools are fragmented and fail to comprehensively cover authoritative risk taxonomies. To bridge this gap, the work proposes a structured mapping protocol that automatically aligns the capabilities of 21 prominent open-source tools with the 32 subcategories of the MIT AI Risk Framework, leveraging retrieval-augmented generation (RAG) and LLM-based parsing. The protocol’s validity is substantiated through source code and documentation analysis, majority voting, and inter-rater reliability assessment using Fleiss’ Kappa (κ = 0.509, F1 = 75.5%). Findings reveal a pronounced overconcentration of current tools on technical controls, with significant gaps in governance, legal, and market risk domains, thereby providing an empirical foundation for developing layered AI risk mitigation architectures.
Rapid deployment of AI systems in regulated domains exposes a critical gap between technical security and legal compliance, as algorithmic vulnerabilities (e.g., those cataloged in MITRE ATLAS) lack systematic mapping to quantifiable financial impacts—undermining evidence-based decisions on contingency reserves and cyber-insurance pricing. Method: We propose the first cross-domain AI threat vector classification framework that directly links technical threats to five business loss dimensions: confidentiality, integrity, availability, legal liability, and reputational harm. Leveraging structured ontology modeling, we integrate MITRE ATLAS, the EU AI Act, NIST AI Risk Management Framework, and ISO/IEC 42001 to define 53 actionable sub-threats. Contribution/Results: The framework achieves 100% coverage across 133 real-world AI incidents reported in 2025, demonstrating both conceptual completeness and audit readiness for regulatory and economic risk assessment.
In response to escalating safety and rights risks posed by general-purpose artificial intelligence (GPAI), this paper proposes the first systematic reporting framework for GPAI incidents. Drawing on a systematic literature review and cross-case analysis of high-stakes domains—including aviation and healthcare—as well as regulatory practices in the U.S. and EU, the study identifies seven core dimensions: policy objectives, reporting entities, incident typologies, reporting modalities (mandatory vs. voluntary), near-miss inclusion, anonymity safeguards, and legal immunity provisions. It critically examines the trade-offs among safety learning, cross-organizational information sharing, and legal interoperability inherent in each mechanism. The resulting framework offers policymakers and researchers an actionable, theory-informed blueprint for designing GPAI incident reporting infrastructure—addressing a critical gap in GPAI risk governance and advancing the institutional foundations for responsible AI development and deployment.
This study addresses the regulatory blind spots confronting cutting-edge AI models during internal deployment, where existing external governance frameworks fall short in mitigating emerging risks. The work proposes the first standardized risk reporting framework tailored for internal AI use across multiple jurisdictions—specifically California, New York, and the European Union. Centered on two primary risk vectors, namely autonomous AI misbehavior and insider threats, the framework integrates threat modeling with legal compliance analysis through the lens of means, motive, and opportunity. It delivers a structured, actionable security assessment template that enhances pre-deployment risk identification and management transparency. Designed as a practical guide for high-capability AI developers, this approach significantly strengthens organizational readiness to anticipate and govern internal AI risks in alignment with diverse regulatory expectations.
Current AI risk mitigation frameworks suffer from fragmentation, terminological ambiguity, and coverage gaps, hindering coordinated multistakeholder governance. To address this, we introduce the first cross-framework taxonomy for AI risk mitigation, systematically synthesizing 831 mitigation measures from 13 prominent frameworks published between 2023 and 2025. Our methodology combines rapid evidence scanning, iterative clustering-based coding, and structured knowledge modeling to develop a four-dimensional classification—governance & oversight, technical safety, operational processes, and transparency & accountability—with 23 granular subcategories. We explicitly resolve semantic inconsistencies in key terms (e.g., “red-teaming,” “risk management”) and deliver a scalable, role-aligned taxonomy alongside a dynamic, open-source database. The resulting resource enables comparative framework analysis and gap identification, supporting national policymaking and AI safety organizations worldwide. All artifacts are publicly released to advance global AI governance infrastructure.
This study addresses the poor reproducibility, lack of auditability, and reliance on manual narratives in AI safety assessments by proposing a deterministic, auditable framework. The framework standardizes heterogeneous engineering evidence into control identifiers mapped to technical-level risks, generates executable assessment functions by compiling MITRE ATLAS rules, supports repeated evaluations via versioned policy objects, and incorporates formal verification to ensure logical consistency and semantic correctness. Experiments across five open-source projects demonstrate that the framework effectively quantifies risk variations before and after hardening interventions. Results confirm that strengthened controls reduce attack feasibility while precisely revealing residual risks arising from missing core safeguards.
While Artificial General Intelligence (AGI) presents transformative opportunities, its systemic safety risks lack mature, quantitative assessment methodologies. Method: This paper introduces the first quantitative risk modeling framework specifically designed for AGI, adapting high-consequence industry risk paradigms. It comprises six systematic steps: scenario definition, parameter decomposition, baseline quantification, metric identification, LLM capability gain mapping, and risk aggregation. Grounded in empirically validated metric–parameter relationships, the framework bridges qualitative judgment to auditable, verifiable quantitative claims (e.g., “X% probability of >$Y in annual economic loss”) and enables cross-domain unified evaluation (e.g., cyberattacks, biochemical threats). Contribution/Results: The framework is fully validated on an LLM-augmented cyberattack scenario, yielding statistically grounded risk quantifications. It provides regulators—such as those implementing the EU AI Act—with auditable, reproducible, and scalable risk assessments.
Traditional software risk management struggles to address the unique challenges posed by AI-native teams, particularly probabilistic outputs, autonomous multi-step actions, and silent evolution risks—especially high-consequence failures arising from mismatches between deterministic dependencies and probabilistic outputs at organizational boundaries. This work proposes a risk governance framework tailored for AI-native engineering teams, introducing an innovative seven-dimensional team profiling schema and six failure modes, including a newly identified “determinism-probabilism mismatch at dependency boundaries.” A contextualized synthetic assessment method is developed to align with standards such as NIST AI RMF and ISO/IEC 42001. The study reveals a significant decline in risk coverage when transitioning from conventional software to AI-native teams, with uncovered high-consequence failures predominantly occurring in AI-specific phases, rooted in the misuse of probabilistic outputs at system boundaries.