NIST published a Generative AI Profile for its AI Risk Management Framework and secure-development guidance specific to generative AI and foundation models.
Mid-market firms need repeatable risk classification more than they need a large AI committee. The controls should scale with what the system can see, decide and do.
Internal drafting is different from retrieval over confidential records; retrieval is different from an agent that can update a CRM; an operational agent is different from a system influencing clinical, employment or financial decisions.
Maintain an AI inventory. Classify each use case by data sensitivity, decision impact and autonomy. Set an owner, an evaluation method, human-review rules and an escalation path before production.
Sources available by this date: NIST: Generative AI Profile, Jul. 26 2024 | NIST: Secure software development for generative AI, Jul. 26 2024
Leave a Reply