{"resourceId":"rand-ai-vulnerability-framework","versions":[{"version":"legacy/2026-08-30/rand-ai-vulnerability-framework","resource":{"id":"rand-ai-vulnerability-framework","title":"New vulnerability framework treats many AI weaknesses as structural rather than patchable","organization":"RAND Corporation","sector":"AI security and risk management","geography":"International relevance","publishedAt":"July 30, 2026","sourceName":"A Structured Approach to Identifying and Characterizing AI Vulnerabilities","sourceLabel":"RAND research report RR-A4983-1","sourceUrl":"https://www.rand.org/pubs/research_reports/RRA4983-1.html","evidenceClass":"independent-research","outcomeClass":"cautionary","topics":["developers-agents","infrastructure","data-security","governance-procurement","operating-model"],"finding":"RAND decomposed generative AI architectures from training data through deployment interfaces and identified 31 vulnerability classes. Its highest aggregate risks clustered around training data and user-facing inference boundaries, including context windows and retrieval-augmented generation pipelines.","sledRelevance":"SLED security teams need to integrate AI into vulnerability management without pretending probabilistic model behavior maps neatly to conventional CVEs or patch cycles. The framework gives architects and buyers a component-level way to assign controls and residual risk.","evidence":"The researchers combined literature review, public incident and attack sources monitored from August 2025 through March 2026, architectural decomposition, and structured threat and impact metrics. They conclude that some weaknesses persist across model versions and can be reduced but not eliminated through conventional patching.","architectureImplications":"Threat-model training and fine-tuning data, provenance, embeddings, context, retrieval, prompts, output interfaces, and any connected tools separately. Add input validation, retrieval isolation, provenance checks, least privilege, output controls, anomaly detection, and stochastic adversarial testing as compensating controls.","governanceImplications":"Require component-level risk assessments and residual-risk acceptance; connect AI findings to existing vulnerability, change, incident, and supplier-management processes; and re-evaluate after model, data, retrieval, or tool changes.","securityPrivacyImplications":"Prioritize dataset provenance and controls at context and retrieval boundaries, where poisoned or injected content can affect confidentiality and integrity. Logging and monitoring must detect probabilistic exploitation and resource-exhaustion patterns, not only deterministic signatures.","caveats":"The taxonomy combines real-world and theoretical attack evidence and scores vulnerability classes rather than product-specific defects. It excludes bias harms, attacks that merely use AI, and external infrastructure or supply-chain vulnerabilities, and should be treated as an expandable baseline rather than a complete standard."}},{"version":"enrichment/2026-09-05T02:42:45.193Z/rand-ai-vulnerability-framework","resource":{"id":"rand-ai-vulnerability-framework","title":"New vulnerability framework treats many AI weaknesses as structural rather than patchable","organization":"RAND Corporation","sector":"AI security and risk management","geography":"International relevance","publishedAt":"July 30, 2026","publicationDate":"2026-07-30","eventDate":null,"sourceName":"A Structured Approach to Identifying and Characterizing AI Vulnerabilities","sourceLabel":"RAND research report RR-A4983-1","sourceUrl":"https://www.rand.org/pubs/research_reports/RRA4983-1.html","evidenceClass":"independent-research","outcomeClass":"cautionary","topics":["developers-agents","infrastructure","data-security","governance-procurement","operating-model"],"finding":"RAND decomposed generative AI architectures from training data through deployment interfaces and identified 31 vulnerability classes. Its highest aggregate risks clustered around training data and user-facing inference boundaries, including context windows and retrieval-augmented generation pipelines.","sledRelevance":"SLED security teams need to integrate AI into vulnerability management without pretending probabilistic model behavior maps neatly to conventional CVEs or patch cycles. The framework gives architects and buyers a component-level way to assign controls and residual risk.","evidence":"The researchers combined literature review, public incident and attack sources monitored from August 2025 through March 2026, architectural decomposition, and structured threat and impact metrics. They conclude that some weaknesses persist across model versions and can be reduced but not eliminated through conventional patching.","architectureImplications":"Threat-model training and fine-tuning data, provenance, embeddings, context, retrieval, prompts, output interfaces, and any connected tools separately. Add input validation, retrieval isolation, provenance checks, least privilege, output controls, anomaly detection, and stochastic adversarial testing as compensating controls.","governanceImplications":"Require component-level risk assessments and residual-risk acceptance; connect AI findings to existing vulnerability, change, incident, and supplier-management processes; and re-evaluate after model, data, retrieval, or tool changes.","securityPrivacyImplications":"Prioritize dataset provenance and controls at context and retrieval boundaries, where poisoned or injected content can affect confidentiality and integrity. Logging and monitoring must detect probabilistic exploitation and resource-exhaustion patterns, not only deterministic signatures.","caveats":"The taxonomy combines real-world and theoretical attack evidence and scores vulnerability classes rather than product-specific defects. It excludes bias harms, attacks that merely use AI, and external infrastructure or supply-chain vulnerabilities, and should be treated as an expandable baseline rather than a complete standard.","streamIds":["state-government","local-government","campus-operations"],"roles":{"sales":"Interpretation — Problem and stakeholders: CISOs, architects, procurement, and risk owners may use ordinary patch tracking for weaknesses arising in data or probabilistic inference. Discovery: Who owns retrieval, context, training-data provenance, outputs, and connected tools, and which weaknesses remain after model updates? Value hypothesis: Component-level assessment could clarify compensating controls and residual-risk decisions. Potential engagement: Threat-model one AI workflow and connect findings to existing vulnerability management. Evidence boundary: RAND's 31 classes combine observed and theoretical evidence; they are not 31 verified defects in the customer's product. The framework excludes some harm categories and external infrastructure risks. Using it does not certify completeness, safety, compliance, or resistance to all forms of attack.","engineering":"Interpretation — Fit: Apply the taxonomy to sensitive context, retrieval, and tool-enabled systems. Architecture: Map data provenance, embeddings, retrieval boundaries, prompts, output interfaces, and privileges separately rather than treating the model as the whole system. Prerequisites: Component inventory, representative hostile inputs, and configuration and log access. Constraints: Probabilistic behavior requires repeated testing; conventional patches may only reduce exposure. Security: Validate least privilege, retrieval isolation, input/output controls, provenance, and resource-exhaustion protection alongside model safeguards. Proposed validation: Exercise poisoning and injection repeatedly, record exploit conditions and control effectiveness, and rerun after model, corpus, or tool changes. Interpret findings as product-specific evidence rather than inheriting the report's class-level risk scores.","delivery":"Interpretation — Work and dependencies: Add AI components and tests to existing vulnerability, change, incident, and supplier processes. Ownership: Platform and data owners implement controls; security tests them; service owners accept documented residual risk. Skills and adoption: Train operations staff to investigate intermittent failures and preserve reproducible evidence without exposing sensitive prompts. Governance checkpoints: Review control coverage before launch and after data, retrieval, model, or permission changes. Proposed acceptance: Material components have owners, repeatable tests, compensating controls, monitoring, and a recorded response to unresolved findings. Risks: A taxonomy checklist may miss product-specific paths, and stochastic noise can obscure exposure. Keep conventional infrastructure security and excluded harm assessments covered through their existing processes rather than assuming this framework replaces them."},"retrievedAt":null,"enrichedAt":"2026-09-05T02:42:45.193Z","enrichmentBasis":"archived evidence"}}]}