Lighthouse AdvisorySLED AI Adoption Intelligence
← Back to results

From the SLED-wide archive edition of August 30, 2026

Independent researchCautionaryRecent

New vulnerability framework treats many AI weaknesses as structural rather than patchable

RAND Corporation · AI security and risk management · International relevance

Publisher
A Structured Approach to Identifying and Characterizing AI Vulnerabilities
Original publication
July 30, 2026
Source retrieved
Not recorded in the historical archive
Read original source

What happened

RAND decomposed generative AI architectures from training data through deployment interfaces and identified 31 vulnerability classes. Its highest aggregate risks clustered around training data and user-facing inference boundaries, including context windows and retrieval-augmented generation pipelines.

Why it matters

SLED security teams need to integrate AI into vulnerability management without pretending probabilistic model behavior maps neatly to conventional CVEs or patch cycles. The framework gives architects and buyers a component-level way to assign controls and residual risk.

Evidence and measured results

The researchers combined literature review, public incident and attack sources monitored from August 2025 through March 2026, architectural decomposition, and structured threat and impact metrics. They conclude that some weaknesses persist across model versions and can be reduced but not eliminated through conventional patching.

Limitations and uncertainty

The taxonomy combines real-world and theoretical attack evidence and scores vulnerability classes rather than product-specific defects. It excludes bias harms, attacks that merely use AI, and external infrastructure or supply-chain vulnerabilities, and should be treated as an expandable baseline rather than a complete standard.

Put this evidence to work

Lighthouse Advisory interpretation, grounded in this source as summarized in the preserved archive. Enriched 2026-09-05; this does not change the original publication date. Labels below come from the analysis itself.

Sales

Role takeaway

Problem and stakeholders: CISOs, architects, procurement, and risk owners may use ordinary patch tracking for weaknesses arising in data or probabilistic inference.

Discovery
Who owns retrieval, context, training-data provenance, outputs, and connected tools, and which weaknesses remain after model updates?
Value hypothesis
Component-level assessment could clarify compensating controls and residual-risk decisions.
Potential engagement
Threat-model one AI workflow and connect findings to existing vulnerability management.
Evidence boundary
RAND's 31 classes combine observed and theoretical evidence; they are not 31 verified defects in the customer's product. The framework excludes some harm categories and external infrastructure risks. Using it does not certify completeness, safety, compliance, or resistance to all forms of attack.

Pre-sales engineering

Role takeaway
Fit
Apply the taxonomy to sensitive context, retrieval, and tool-enabled systems.
Architecture
Map data provenance, embeddings, retrieval boundaries, prompts, output interfaces, and privileges separately rather than treating the model as the whole system.
Prerequisites
Component inventory, representative hostile inputs, and configuration and log access.
Constraints
Probabilistic behavior requires repeated testing; conventional patches may only reduce exposure.
Security
Validate least privilege, retrieval isolation, input/output controls, provenance, and resource-exhaustion protection alongside model safeguards.
Proposed validation
Exercise poisoning and injection repeatedly, record exploit conditions and control effectiveness, and rerun after model, corpus, or tool changes. Interpret findings as product-specific evidence rather than inheriting the report's class-level risk scores.

Delivery

Role takeaway

Work and dependencies: Add AI components and tests to existing vulnerability, change, incident, and supplier processes.

Ownership
Platform and data owners implement controls; security tests them; service owners accept documented residual risk.
Skills and adoption
Train operations staff to investigate intermittent failures and preserve reproducible evidence without exposing sensitive prompts.
Governance checkpoints
Review control coverage before launch and after data, retrieval, model, or permission changes.
Proposed acceptance
Material components have owners, repeatable tests, compensating controls, monitoring, and a recorded response to unresolved findings.
Risks
A taxonomy checklist may miss product-specific paths, and stochastic noise can obscure exposure. Keep conventional infrastructure security and excluded harm assessments covered through their existing processes rather than assuming this framework replaces them.

Implementation considerations

Lighthouse Advisory interpretation across the operating dimensions a public-sector buyer must settle before this evidence becomes a design. Each note answers the question under its heading for this specific source.

Architecture and integration

What must connect, and where does the AI sit in the workflow?

Threat-model training and fine-tuning data, provenance, embeddings, context, retrieval, prompts, output interfaces, and any connected tools separately. Add input validation, retrieval isolation, provenance checks, least privilege, output controls, anomaly detection, and stochastic adversarial testing as compensating controls.

Governance

Who approves, reviews and stays accountable for outcomes?

Require component-level risk assessments and residual-risk acceptance; connect AI findings to existing vulnerability, change, incident, and supplier-management processes; and re-evaluate after model, data, retrieval, or tool changes.

Security and privacy

What data, permissions and controls need testing?

Prioritize dataset provenance and controls at context and retrieval boundaries, where poisoned or injected content can affect confidentiality and integrity. Logging and monitoring must detect probabilistic exploitation and resource-exhaustion patterns, not only deterministic signatures.

The preserved archive analysis covered architecture, governance and security. Not assessed for this record: accessibility and workforce, procurement, operating model.

Publication history

  1. 2026-08-30SLED-wide archive · Issue 035 resources
Read preserved resource versions (JSON)

Stable resource ID: rand-ai-vulnerability-framework