From the SLED-wide archive edition of August 30, 2026
New vulnerability framework treats many AI weaknesses as structural rather than patchable
RAND Corporation · AI security and risk management · International relevance
- Publisher
- A Structured Approach to Identifying and Characterizing AI Vulnerabilities
- Original publication
- July 30, 2026
- Source retrieved
- Not recorded in the historical archive
What happened
RAND decomposed generative AI architectures from training data through deployment interfaces and identified 31 vulnerability classes. Its highest aggregate risks clustered around training data and user-facing inference boundaries, including context windows and retrieval-augmented generation pipelines.
Why it matters
SLED security teams need to integrate AI into vulnerability management without pretending probabilistic model behavior maps neatly to conventional CVEs or patch cycles. The framework gives architects and buyers a component-level way to assign controls and residual risk.
Evidence and measured results
The researchers combined literature review, public incident and attack sources monitored from August 2025 through March 2026, architectural decomposition, and structured threat and impact metrics. They conclude that some weaknesses persist across model versions and can be reduced but not eliminated through conventional patching.
Limitations and uncertainty
The taxonomy combines real-world and theoretical attack evidence and scores vulnerability classes rather than product-specific defects. It excludes bias harms, attacks that merely use AI, and external infrastructure or supply-chain vulnerabilities, and should be treated as an expandable baseline rather than a complete standard.
Put this evidence to work
Lighthouse Advisory interpretation, grounded in this source as summarized in the preserved archive. Enriched 2026-09-05; this does not change the original publication date. Labels below come from the analysis itself.
Sales
Role takeaway
Problem and stakeholders: CISOs, architects, procurement, and risk owners may use ordinary patch tracking for weaknesses arising in data or probabilistic inference.
- Discovery
- Who owns retrieval, context, training-data provenance, outputs, and connected tools, and which weaknesses remain after model updates?
- Value hypothesis
- Component-level assessment could clarify compensating controls and residual-risk decisions.
- Potential engagement
- Threat-model one AI workflow and connect findings to existing vulnerability management.
- Evidence boundary
- RAND's 31 classes combine observed and theoretical evidence; they are not 31 verified defects in the customer's product. The framework excludes some harm categories and external infrastructure risks. Using it does not certify completeness, safety, compliance, or resistance to all forms of attack.
Pre-sales engineering
Role takeaway
- Fit
- Apply the taxonomy to sensitive context, retrieval, and tool-enabled systems.
- Architecture
- Map data provenance, embeddings, retrieval boundaries, prompts, output interfaces, and privileges separately rather than treating the model as the whole system.
- Prerequisites
- Component inventory, representative hostile inputs, and configuration and log access.
- Constraints
- Probabilistic behavior requires repeated testing; conventional patches may only reduce exposure.
- Security
- Validate least privilege, retrieval isolation, input/output controls, provenance, and resource-exhaustion protection alongside model safeguards.
- Proposed validation
- Exercise poisoning and injection repeatedly, record exploit conditions and control effectiveness, and rerun after model, corpus, or tool changes. Interpret findings as product-specific evidence rather than inheriting the report's class-level risk scores.
Delivery
Role takeaway
Work and dependencies: Add AI components and tests to existing vulnerability, change, incident, and supplier processes.
- Ownership
- Platform and data owners implement controls; security tests them; service owners accept documented residual risk.
- Skills and adoption
- Train operations staff to investigate intermittent failures and preserve reproducible evidence without exposing sensitive prompts.
- Governance checkpoints
- Review control coverage before launch and after data, retrieval, model, or permission changes.
- Proposed acceptance
- Material components have owners, repeatable tests, compensating controls, monitoring, and a recorded response to unresolved findings.
- Risks
- A taxonomy checklist may miss product-specific paths, and stochastic noise can obscure exposure. Keep conventional infrastructure security and excluded harm assessments covered through their existing processes rather than assuming this framework replaces them.
Implementation considerations
Lighthouse Advisory interpretation across the operating dimensions a public-sector buyer must settle before this evidence becomes a design. Each note answers the question under its heading for this specific source.
Architecture and integration
What must connect, and where does the AI sit in the workflow?
Threat-model training and fine-tuning data, provenance, embeddings, context, retrieval, prompts, output interfaces, and any connected tools separately. Add input validation, retrieval isolation, provenance checks, least privilege, output controls, anomaly detection, and stochastic adversarial testing as compensating controls.
Governance
Who approves, reviews and stays accountable for outcomes?
Require component-level risk assessments and residual-risk acceptance; connect AI findings to existing vulnerability, change, incident, and supplier-management processes; and re-evaluate after model, data, retrieval, or tool changes.
Security and privacy
What data, permissions and controls need testing?
Prioritize dataset provenance and controls at context and retrieval boundaries, where poisoned or injected content can affect confidentiality and integrity. Logging and monitoring must detect probabilistic exploitation and resource-exhaustion patterns, not only deterministic signatures.
The preserved archive analysis covered architecture, governance and security. Not assessed for this record: accessibility and workforce, procurement, operating model.
Publication history
- 2026-08-30SLED-wide archive · Issue 035 resources
Stable resource ID: rand-ai-vulnerability-framework