惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

宝玉的分享
宝玉的分享
T
The Blog of Author Tim Ferriss
Y
Y Combinator Blog
Apple Machine Learning Research
Apple Machine Learning Research
Last Week in AI
Last Week in AI
Recorded Future
Recorded Future
博客园 - 司徒正美
V
Vulnerabilities – Threatpost
月光博客
月光博客
C
CXSECURITY Database RSS Feed - CXSecurity.com
D
Darknet – Hacking Tools, Hacker News & Cyber Security
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Microsoft Azure Blog
Microsoft Azure Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
W
WeLiveSecurity
Jina AI
Jina AI
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Hacker News: Ask HN
Hacker News: Ask HN
S
Security Affairs
V
Visual Studio Blog
Schneier on Security
Schneier on Security
T
Tailwind CSS Blog
Martin Fowler
Martin Fowler
V2EX - 技术
V2EX - 技术
博客园 - Franky
S
Secure Thoughts
Blog — PlanetScale
Blog — PlanetScale
G
GRAHAM CLULEY
D
DataBreaches.Net
O
OpenAI News
Forbes - Security
Forbes - Security
云风的 BLOG
云风的 BLOG
Google Online Security Blog
Google Online Security Blog
博客园 - 三生石上(FineUI控件)
T
Tor Project blog
T
Tenable Blog
Latest news
Latest news
N
News and Events Feed by Topic
博客园_首页
Simon Willison's Weblog
Simon Willison's Weblog
C
Cybersecurity and Infrastructure Security Agency CISA
美团技术团队
T
The Exploit Database - CXSecurity.com
K
Kaspersky official blog
B
Blog
阮一峰的网络日志
阮一峰的网络日志
T
Threat Research - Cisco Blogs
SecWiki News
SecWiki News
PCI Perspectives
PCI Perspectives
GbyAI
GbyAI

Databricks

How lakebase architecture delivers 5x faster Postgres writes Why Talent Transformation Is the Missing Focus of Enterprise AI Public Health Intelligence Shouldn't Require a Data Scientist Mean Time to Detect Is a Data Access Problem First-party audience data is the ad sales relationship now Rethinking Distributed Systems for Serverless Performance and Reliability The AI Scaling Gap Hiding in Digital Native Companies 10 trillion samples a day: Scaling beyond traditional monitoring infra at Databricks AI success starts with clean data, not just better models How nOps Rebuilt Their Cloud Optimization Platform on Databricks Lakebase, and Why Other ISVs Should Too Peril Predicts: Precision Payouts for a Volatile World The foundation of AI scalability: one team, one platform, one operating model The Federal Data Paradox: Rich in Data, Poor in Access Driving Budapest Forward: How BKK Uses Databricks to Transform City Mobility LLM Vs AI: A Practical Guide to Differences, Use Cases, and Tools Model Risk Governance Is Not the Same as Risk Intelligence Generative AI for Business: A Complete Strategy and Implementation Guide Data Science vs Data Engineering: Choosing Analysis or Infrastructure AI Applications: Tools, Use Cases, and Platforms MLOps vs DevOps: A Practical Guide for Data Scientists and IT Teams Top Data Warehouse Tools For Modern Data Analytics Unlocking SAP Business Context in Databricks with Semantic Metadata Delta Sharing The marketing activation gap has a fix: Databricks and Stitch partner to turn data infrastructure into marketing performance Alert Fatigue Is a Business Risk Backstage with Lakebase Shipping Faster isn’t Learning Faster Why Your OEE Dashboard Is Lying to You The Turbine That Tried to Tell You It Was Failing Predicting Readmissions Isn't Enough. Acting in Time Is. Clinical Trials Run Longer Than They Have To. That's a Patient Problem Network Quality Is a Revenue Problem, Not a Technical One Shelf Availability Starts with Better Demand Visibility When Predicting the Next Hit Requires More Than Intuition Approximate Answers, Exact Decisions: New Sketch Functions for Analytics Companies Winning with AI Built the Data Layer First Rethinking SQL ETL for modern data platforms Stripe data now available on Databricks via Databricks Marketplace Databricks and Stripe Projects: Infrastructure Built for Agents Agents are ready but your architecture probably isn't Interoperability Between Unity Catalog and Google BigQuery via Catalog Federation Built In, Not Bolted On: What AI-Native Actually Means in Cybersecurity Operationalizing AI for public sector fraud prevention From months to minutes: Building real-time clinical data pipelines with natural language Agentic Data Engineering with Genie Code and Lakeflow Securely send first-party conversion signals with Snapchat Conversions API on Databricks Marketplace How leading tech companies are killing the builder’s tax with Lakebase Inside one of the first production deployments of Lakebase: LangGuard's agentic workflow governance engine The next generation of Databricks Genie Model Risk Management in 2026: A Banker’s Guide to the Revised Interagency Guidance OpenAI GPT-5.5 now available on Databricks, fully-governed through Unity AI Gateway Operational databases: How they work and when to use them Databricks partners with OpenAI on GPT-5.5 Announcing the Public Preview of Lakeflow Designer Are LLM agents good at join order optimization? How conversational analytics removes the BI bottleneck How to transform document activation workflows with Genie and Agent Bricks Beyond the spreadsheet: how Databricks is delivering the modern CFO in Financial Services AI App Development: Guide To Building AI-Powered Apps IoT in Manufacturing: Strategy, Components, Use Cases, and Challenges Stop Hand-Coding Change Data Capture Pipelines Multimodal Data Integration: Production Architectures for Healthcare AI Personalization Strategies for Media Companies Introducing the Databricks Excel Add-in for Business Users Real-Time Decisioning for AI Agents: Why you Need a Customer Context Layer First A Practical Guide to LLM Fine Tuning AI Data Transformation Guide for Data Engineers and Data Scientists Concurrency Control in DBMS: How Locking, MVCC and Optimistic Strategies Keep Data Consistent Bridging data science and marketing: Databricks unveils Delta Sharing integration for Adobe Experience Platform and agentic marketing workflows Take Control: Customer-Managed Keys for Lakebase Postgres Get hands on with agents, vibe coding and more at Data+ AI Summit Mercedes-Benz Builds a Cross-Cloud Data Mesh with Delta Sharing and Intelligent Replication, Cutting Costs by 66% What Is a Transactional Database? Introducing Genie Agent Mode Governing coding agent sprawl with Unity AI Gateway Governing Coding Agent Sprawl with Unity AI Gateway What is pgvector? Banks Don’t Have an AI Problem – They Have a Data Platform Problem Open Platform, Unified Pipelines: Why dbt on Databricks is Accelerating Why Your Agents Can’t Read Enterprise Documents — and How to Fix It Building with Databricks Document Intelligence and Lakeflow Databricks on Google Cloud: Innovate Faster. Smarter. Together. Introducing the Databricks Connector for Google Sheets: Real-Time, Governed Lakehouse Data in the Sheets Users Love Unity AI Gateway: How to connect agents to external MCPs securely Expanding agent governance with Unity AI Gateway Agentic reasoning in practice: Making sense of structured and unstructured data Agent Bricks: The Governed Enterprise Agent Platform 8 AI and data trends shaping financial services in 2026 Building real-time product search on Databricks Lovable + Databricks: Build Data-Driven Apps at the Speed of Thought Memory scaling for AI agents Powering clinical research innovation: How TriNetX uses Databricks to accelerate drug development Database Branching in Postgres: Git-Style Workflows with Databricks Lakebase How Zalando built a unified data foundation for AI and analytics on Databricks The next era of the open lakehouse: Apache Iceberg™ v3 in Public Preview on Databricks How FSIs eliminate silos between clients, operations, and finance How MakeMyTrip achieved millisecond personalization at scale with Databricks A multi-agent approach to audience intelligence AiChemy: Next-generation agent with MCP, skills and custom data for drug discovery Accelerate business insights with Lakeflow Connect, now with a Free Tier Unlocking Next-Gen Customer Experiences with Data Intelligence for Marketing
A Modern AI Risk Management Framework
2026-04-22 · via Databricks

Why AI Risks Demand a Dedicated Risk Management Framework

Managing AI risks is no longer optional. Organizations deploying AI systems face a fundamentally different landscape than traditional IT — one defined by model drift, adversarial manipulation, and algorithmic bias. An AI risk management framework gives teams the structure to identify, assess, and mitigate AI risks before they cause harm or stall artificial intelligence initiatives.

Traditional risk management practices were built for deterministic systems. AI systems are probabilistic. They produce AI outputs that can be difficult to audit and introduce AI risks that existing security tools were never built to handle. The challenges posed by this shift require a dedicated AI risk management approach.

Effective AI risk management is an ongoing process. As AI technologies evolve, the risk management framework must evolve with them — incorporating new risks, updated regulatory requirements, and lessons learned across the full AI lifecycle.

Overview of AI Risk Management Frameworks and Core Functions

Several major frameworks now define best practice for managing AI risks globally. The NIST AI Risk Management Framework (AI RMF) is the most widely adopted voluntary standard in the United States. Developed over 18 months with input from more than 240 organizations, the NIST AI risk management framework emphasizes a socio-technical approach that addresses both technical AI risks and broader societal impacts. The NIST AI RMF is designed to evolve with AI technologies and applies across every industry and maturity level.

The EU AI Act introduces a risk-based categorization system for AI applications, imposing mandatory requirements on high-risk AI systems. For organizations operating in European markets, this regulation reshapes the entire AI risk management framework — from documentation to conformity assessments. The NIST AI risk management framework and the EU AI Act are complementary: the NIST AI RMF provides the governance structure, while the Act defines the regulatory floor.

ISO/IEC 23894:2023 provides an internationally recognized standard for AI risk management that complements both the NIST AI RMF and EU regulatory requirements. Multiple frameworks exist because the challenges posed by AI are global and context-dependent. Organizations seeking comprehensive coverage often synthesize all three, using the NIST AI risk management framework as the operational foundation.

AI RMF Core Functions: Govern, Map, Measure, Manage

The AI RMF's core functions — Govern, Map, Measure, and Manage — are the operational backbone of the NIST AI risk management framework. These core functions provide a shared language for compliance teams, data scientists, and risk owners managing AI risks across the organization.

Govern

The Govern function establishes accountability for AI risk management. It sets risk tolerance thresholds, defines ethical guidelines for responsible AI development, and ensures governance policies align with regulatory requirements. All downstream AI risk management activities in the management framework AI RMF depend on the clear ownership defined here.

Establishing a cross-functional committee — including legal, IT, data scientists, and business leadership — is essential for operationalizing Govern and preventing fragmented AI risk management.

Map

Map involves identifying the specific context of each AI system: its purpose, intended users, data dependencies, and potential negative impacts. This core function drives risk identification by cataloging all AI systems in use and characterizing the AI risks associated with each deployment across the AI lifecycle.

Mapping must account for not just technical risks but also ethical implications and societal AI risks. AI risks that seem abstract at design time — unintended consequences, algorithmic bias — become concrete liabilities once AI systems reach production.

Measure

Measure defines the metrics and methodologies for assessing AI risks. This core function covers fairness evaluations, explainability assessments, and risk assessment of both technical risks and ethical implications. By establishing measurable baselines, organizations can track AI risks and detect emerging risks before they escalate.

Threat modeling and scenario planning are both valuable tools within the Measure function. Simulating adversarial conditions helps teams uncover unique risks — including security threats like data poisoning and model inversion attacks that can compromise AI outputs.

Manage

Manage translates risk insights into action. This core function covers the implementation of risk mitigation strategies, the deployment of security controls, and the documentation of incident response procedures for AI incidents. Managing AI risks at this stage means prioritizing the most pressing threats and applying controls to each AI system based on the organization's risk tolerance.

The NIST AI RMF Playbook provides practical implementation guidance aligned with the core functions. Adapting the AI RMF Playbook to organizational needs means creating step-by-step checklists and scheduling regular governance reviews.

AI Governance and Roles for Responsible AI Systems

Responsible AI development begins with governance structure. Establishing an AI governance committee that spans legal, security, data science, and business leadership creates the accountability foundation the NIST AI RMF requires. This committee owns AI risk management policy and approves AI products before production deployment.

Clear AI risk ownership is equally critical. Without designated owners, managing AI risks becomes reactive. Each AI project should have a named risk lead responsible for maintaining risk documentation and escalating AI risks that exceed risk tolerance.

Responsible AI development means embedding governance into every stage of AI development — from model selection through decommissioning — and defining escalation paths for AI risks before models reach production. Doing so helps organizations proactively mitigate risks rather than respond to incidents after the fact.

Map AI Systems Across the AI Lifecycle

Building an AI Bill of Materials (AI-BOM) is the foundation of the Map function in any AI risk management framework. An AI-BOM inventories all AI systems, categorizes them by risk and impact, and documents data flows, model dependencies, and stakeholder accountability across the AI lifecycle.

The AI lifecycle spans four major stages — data operations, model operations, model deployment, and platform management — each introducing distinct AI risks. Data operations AI risks include data poisoning and insufficient access controls. Model operations AI risks include model drift and malicious library injection. The deployment stage introduces prompt injection and LLM hallucination risks. Platform AI risks include lack of vulnerability management and insecure software development lifecycle practices.

Categorizing AI systems by impact and risk tolerance enables proportionate AI risk management. Organizations developing AI products for regulated industries face additional AI risks tied to sector-specific regulatory requirements.

Measure AI Risk and Metrics

A systematic approach to measurement distinguishes proactive AI risk management from reactive incident response. Organizations need quantitative AI risk metrics that capture likelihood and severity of harm across all active AI systems — not just traditional security metrics.

Risk assessment for AI should cover bias, explainability, data quality, and security vulnerabilities. Validating trustworthy AI systems requires ongoing evaluation of whether AI outputs reflect intended behavior or introduce unintended consequences. The NIST AI risk management framework provides structured guidance for defining trustworthiness metrics and operationalizing measurement across the AI lifecycle.

Organizations seeking to build trustworthy AI embed continuous evaluation into every stage rather than treating risk assessment as a one-time gate.

Manage Controls for AI Security and Risk Mitigation

Once AI risks are identified and measured, organizations must implement controls that mitigate risks effectively. Analysis of AI systems across industries has identified 62 distinct AI risks spanning 12 foundational components — from raw data and preprocessing through model serving and AI security at the platform level.

Effective risk mitigation strategies include: enforcing authentication at every model endpoint, implementing rate limiting and AI output filtering, running adversarial testing and red-teaming to surface security threats, and deploying Human-in-the-Loop (HITL) approval workflows for production model promotion.

Managing AI risks at the control level requires AI security practices that are continuous. The risk management framework AI RMF maps each technical control to a specific AI risk and AI system component — a structured approach that ensures risk management efforts are targeted, not generic.

Integrating Data Protection Into the AI Lifecycle

Privacy-by-design principles require embedding security controls during AI development — before AI systems reach production, not after. AI risks tied to data include data poisoning, unauthorized access to training datasets, and accidental exposure of personally identifiable information through AI outputs. Applying data minimization reduces the attack surface and limits AI related risks in model operations. Monitoring AI models for data leakage post-deployment is an ongoing requirement of any mature AI risk management framework.

AI Security Practices and Technical Safeguards

Layered defense is the baseline for any mature AI risk management framework. Encrypting sensitive data at rest and in transit, enforcing model access authentication, and isolating models in hardened runtime environments form the technical foundation for modern AI risks.

AI systems face unique risks that conventional cybersecurity was never designed to address — prompt injection, model inversion, LLM jailbreaking, and black-box adversarial attacks. Addressing these threats requires dedicated controls mapped to specific AI risks for each deployment model and continuous vulnerability scanning to neutralize cyber threats before they escalate.

The challenges posed by this landscape extend beyond perimeter defense. Governing model serving endpoints, auditing AI outputs, and enforcing security controls throughout the AI lifecycle all require coordinated risk management efforts across engineering, security, and compliance teams.

Operationalizing an AI RMF Playbook

The AI RMF Playbook provides practical implementation guidance aligned with the NIST AI risk management framework's core functions. Organizations seeking to operationalize responsible AI practices use the AI RMF Playbook to build step-by-step checklists, assign ownership, and schedule regular governance reviews.

Adapting the AI RMF Playbook means mapping each of the core functions to specific team roles and governance artifacts. It is a living document — updated whenever evolving technologies introduce new AI risks or the regulatory environment shifts. Responsible innovation depends on risk frameworks that grow alongside the AI systems they govern.

Comparison of AI Risk Management Frameworks and Standards

Each major AI risk management framework addresses managing AI risks from a distinct angle. The NIST AI risk management framework emphasizes voluntary adoption and flexibility — the management framework AI RMF is designed to be tailored, not prescribed. The NIST AI RMF provides a risk based approach suited to organizations developing AI products across any sector, and the NIST AI RMF's core functions apply regardless of organization size.

The EU AI Act takes a mandatory regulatory approach, classifying AI applications into risk tiers. For organizations operating in European markets, these requirements must be built into the AI risk management framework from the outset. ISO/IEC 23894:2023 provides globally applicable guidance for risk management framework AI implementation that complements both the NIST AI RMF and EU requirements. The risk management framework AI RMF remains the most broadly applicable foundation for organizations beginning or scaling their AI risk management programs.

Managing AI Risks Across the AI Lifecycle

Managing AI risks requires clear accountability at every stage of the AI lifecycle. During AI development, responsibilities include data quality validation, bias testing, and version control for AI models. Embedding trustworthy AI properties from the earliest design decisions ensures AI systems do not carry forward AI risks that become costly to remediate at scale.

At the deployment stage, securing models in production means enforcing access controls, validating that all risk mitigation strategies from the AI risk management framework are in place before release, and verifying EU regulatory alignment for markets in scope.

Monitoring and decommissioning carry their own AI risks. Trustworthy AI systems require ongoing audit of AI outputs, model monitoring for drift, and defined procedures for retiring AI systems that no longer meet performance or safety standards.

Implementation Challenges and Risk Mitigations

Managing AI risks in practice surfaces technical and organizational challenges posed by the probabilistic nature of AI systems. Technical challenges include model opacity, data quality inconsistencies, and the difficulty of applying traditional risk management practices to non-deterministic behavior. Organizational change actions are equally critical — effective AI risk management requires breaking down silos between compliance teams, security, data science, and legal, establishing shared governance practices and a common language for AI risks.

Regulatory compliance steps vary by geography. Organizations developing AI products in regulated sectors must map their risk management framework to applicable laws including the EU AI Act, HIPAA, and GDPR. Ethical review processes must run in parallel: reviewing ethical implications through diverse stakeholder input helps identify unintended consequences before AI reaches scale.

Tools, Templates, and Playbook Artifacts

Building a functioning AI risk management framework requires actionable artifacts. An AI-BOM template helps organizations inventory AI systems, document data lineage, and track accountability across the AI lifecycle. A risk assessment template structured around the NIST AI RMF's core functions guides teams through risk identification, impact scoring, and control selection.

For AI security testing, recommended tools include adversarial robustness libraries, automated bias detection platforms, and model monitoring solutions that track AI risks in production. Lakehouse AI governance capabilities provide centralized visibility across AI models, datasets, and AI outputs — supporting the ongoing AI risk management that trustworthy AI demands.

The AI RMF Playbook checklist maps each core function to team actions, timelines, and governance artifacts. Organizations seeking to align with leading responsible AI best practices will find the NIST AI risk management framework's AI RMF Playbook the most practical starting point for operationalizing trustworthy AI at scale.

Frequently Asked Questions About AI Risk Management

What is an AI risk management framework?

An AI risk management framework is a structured set of practices for identifying, assessing, and mitigating AI risks across the full AI lifecycle. The NIST AI risk management framework is the most widely adopted standard, with four core functions — Govern, Map, Measure, and Manage — guiding organizations from establishing governance policies through deploying security controls.

What are the four core functions of the NIST AI RMF?

The NIST AI RMF includes Govern, Map, Measure, and Manage as its core functions. These core functions provide a shared framework for managing AI risks and building trustworthy AI systems. The AI RMF Playbook provides step-by-step implementation guidance for each function.

How does the EU AI Act affect AI risk management?

The EU AI Act introduces mandatory risk-based requirements for AI applications in European markets, requiring organizations to classify systems by risk tier. Aligning with the NIST AI risk management framework accelerates compliance by providing the governance structure and documentation regulators require.

What makes AI security different from traditional cybersecurity?

AI systems face unique risks — prompt injection, model inversion, LLM hallucinations, and adversarial attacks — with no direct analog in traditional IT security. Effective AI security requires dedicated controls mapped to specific AI risks for each deployment model and continuous monitoring for new risks as AI technologies evolve.

How should organizations start managing AI risks?

Organizations seeking to begin managing AI risks should inventory all active AI systems, map AI risks using the NIST AI RMF, and establish a cross-functional AI governance committee with clear risk ownership. The AI RMF Playbook provides implementation guidance for every stage of the AI lifecycle and supports compliance with expanding regulatory requirements.