{"id":44355,"date":"2021-12-09T21:00:43","date_gmt":"2021-12-09T21:00:43","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=102582"},"modified":"2021-12-09T21:00:43","modified_gmt":"2021-12-09T21:00:43","slug":"best-practices-for-ai-security-risk-management","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/","title":{"rendered":"Best practices for AI security risk management"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/12\/MSC16_slalom_018.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Today, we are releasing an <a href=\"https:\/\/aka.ms\/airiskassessment\" target=\"_blank\" rel=\"noopener\">AI security risk assessment framework<\/a> as a step to empower organizations to reliably audit, track, and improve the security of the AI systems. In addition, we are providing <a href=\"https:\/\/aka.ms\/counterfit\" target=\"_blank\" rel=\"noopener\">new updates to Counterfit<\/a>, our open-source tool to simplify assessing the security posture of AI systems.<\/p>\n<p>There is a marked interest in securing AI systems from adversaries. Counterfit has been heavily downloaded and explored by organizations of all sizes\u2014from startups to governments and large-scale organizations\u2014to proactively secure their AI systems. From a different vantage point, the <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/07\/29\/attack-ai-systems-in-machine-learning-evasion-competition\/\" target=\"_blank\" rel=\"noopener\">Machine Learning Evasion Competition<\/a> we organized to help security professionals exercise their muscles to defend and attack AI systems in a realistic setting saw record participation, doubling the amount of participants and techniques than the previous year.<\/p>\n<p>This interest demonstrates the growth mindset and opportunity in securing AI systems. But how do we harness interest into action that can raise the security posture of AI systems? When the rubber hits the road, how can a security engineer think about mitigating the risk of an AI system being compromised?<\/p>\n<h2>AI security risk assessment framework<\/h2>\n<p>The deficit is clear: according to Gartner\u00ae <a href=\"https:\/\/www.gartner.com\/en\/documents\/4005344\/market-guide-for-ai-trust-risk-and-security-management\" target=\"_blank\" rel=\"noopener\">Market Guide for AI Trust, Risk and Security Management<\/a> published in September 2021, \u201c<em>AI poses new trust, risk and security management requirements that conventional controls do not address.<\/em>\u201d<sup>1<\/sup> To address this gap, we did not want to invent a new process. We acknowledge that security professionals are already overwhelmed. Moreover, we believe that even though the attacks on AI systems pose a new security risk, current software security practices are relevant and can be adapted to manage this novel risk. To that end, we fashioned our AI security risk assessment in the spirit of the current security risk assessment frameworks.<\/p>\n<p>We believe that to comprehensively assess the security risk for an AI system, we need to look at the entire lifecycle of system development and deployment. An overreliance on securing machine learning models through academic adversarial machine learning oversimplifies the problem in practice. This means, to truly secure the AI model, we need to account for securing the entire supply chain and management of AI systems.<\/p>\n<p>Through our own operations experience in building and red teaming models at Microsoft, we recognize that securing AI systems is a team sport. AI researchers design model architectures. Machine learning engineers build data ingestion, model training, and deployment pipelines. Security architects establish appropriate security policies. Security analysts respond to threats. To that end, we envisioned a framework that would involve participation from each of these stakeholders.<\/p>\n<blockquote>\n<p><em>\u201cDesigning and developing secure AI is a cornerstone of AI product development at Boston Consulting Group (BCG).&nbsp;As the societal need to secure our AI systems becomes increasingly apparent, assets like Microsoft\u2019s AI security risk management framework&nbsp;can be foundational contributions.&nbsp;We already implement best practices found in this framework in the AI systems we develop for our clients and are excited that Microsoft has developed and open sourced this framework for the benefit of the entire industry.\u201d<\/em>\u2014Jack Molloy, Senior Security Engineer, BCG<\/p>\n<\/blockquote>\n<p>As a result of our Microsoft-wide collaboration, our framework features the following characteristics:<\/p>\n<ol>\n<li><strong>Provides a comprehensive perspective to AI<\/strong><strong> system security<\/strong>. We looked at each element of the AI system lifecycle in a production setting: from data collection, data processing, to model deployment. We also accounted for AI supply chains, as well as the controls and policies with respect to backup, recovery, and contingency planning related to AI systems.<\/li>\n<li><strong>Outlines<\/strong><strong> machine learning threats and recommendations to abate them<\/strong>. To directly help engineers and security professionals, we enumerated the threat statement at each step of the AI system building process. Next, we provided a set of best practices that overlay and reinforce existing software security practices in the context of securing AI systems.<\/li>\n<li><strong>Enables organizations<\/strong><strong> to conduct risk assessments<\/strong>. The framework provides the ability to gather information about the current state of security of AI systems in an organization, perform gap analysis, and track the progress of the security posture.<\/li>\n<\/ol>\n<h2>Updates to Counterfit<\/h2>\n<p>To help security professionals get a broader view of the security posture of the AI systems, we have also significantly expanded Counterfit. The first release of Counterfit wrapped two popular frameworks\u2014<a href=\"https:\/\/github.com\/Trusted-AI\/adversarial-robustness-toolbox\" target=\"_blank\" rel=\"noopener\">Adversarial Robustness Toolbox<\/a> (ART) and <a href=\"https:\/\/github.com\/QData\/TextAttack\" target=\"_blank\" rel=\"noopener\">TextAttack<\/a>\u2014to provide evasion attacks against models operating on tabular, image, and textual inputs. With the new release, Counterfit now features the following:<\/p>\n<ul>\n<li>An extensible architecture that simplifies integration of new attack frameworks.<\/li>\n<li>Attacks that include both access to the internals of the machine learning model and with just query access to the machine learning model.<\/li>\n<li>Threat paradigms that include evasion, model inversion, model inference, and model extraction.<\/li>\n<li>In addition to algorithmic attacks provided, common corruption attacks <a href=\"https:\/\/github.com\/facebookresearch\/AugLy\" target=\"_blank\" rel=\"noopener\">through AugLy<\/a> are also included.<\/li>\n<li>Attacks are supported for models that accept tabular data, images, text, HTML, or Windows executable files as input.<\/li>\n<\/ul>\n<h2>Learn More<\/h2>\n<p>These efforts are part of broader investment at Microsoft to empower engineers to securely develop and deploy AI systems. We recommend using it alongside the following resources:<\/p>\n<ul>\n<li>For security analysts to orient to threats against AI systems, Microsoft, in collaboration with MITRE, released an ATT&amp;CK style&nbsp;<a href=\"https:\/\/github.com\/mitre\/advmlthreatmatrix\" target=\"_blank\" rel=\"noopener\">Adversarial Threat Matrix<\/a>&nbsp;complete with case studies of attacks on production machine learning systems, which has evolved into <a href=\"https:\/\/atlas.mitre.org\/studies\" target=\"_blank\" rel=\"noopener\">MITRE ATLAS<\/a>.<\/li>\n<li>For security incident responders, we released our own&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/security\/engineering\/bug-bar-aiml\" target=\"_blank\" rel=\"noopener\">bug bar<\/a>&nbsp;to systematically triage attacks on machine learning systems.<\/li>\n<li>For developers, we released&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/security\/engineering\/threat-modeling-aiml\" target=\"_blank\" rel=\"noopener\">threat modeling guidance<\/a>&nbsp;specifically for machine learning systems.<\/li>\n<li>For engineers and policymakers, Microsoft, in collaboration with Berkman Klein Center at Harvard University,&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/security\/engineering\/failure-modes-in-machine-learning\" target=\"_blank\" rel=\"noopener\">released a taxonomy<\/a>&nbsp;documenting various machine learning failure modes.<\/li>\n<li>For security professionals, <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/05\/03\/ai-security-risk-assessment-using-counterfit\/\" target=\"_blank\" rel=\"noopener\">Microsoft open sourced Counterfit<\/a> to help with assessing the posture of AI systems.<\/li>\n<li>For the broader security community, Microsoft hosted the annual <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/07\/29\/attack-ai-systems-in-machine-learning-evasion-competition\/\" target=\"_blank\" rel=\"noopener\">Machine Learning Evasion Competition<\/a>.<\/li>\n<li>For Azure machine learning customers, we provided guidance on <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/machine-learning\/concept-enterprise-security\" target=\"_blank\" rel=\"noopener\">enterprise security and governance<\/a>.<\/li>\n<\/ul>\n<p>This is a living framework. If you have questions or feedback, please <a href=\"mailto:atml@microsoft.com\" target=\"_blank\" rel=\"noopener\">contact us<\/a>.<\/p>\n<p>To learn more about Microsoft Security solutions,&nbsp;<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/solutions\" target=\"_blank\" rel=\"noopener\">visit our&nbsp;website<\/a>.&nbsp;Bookmark the&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noopener\">Security blog<\/a>&nbsp;to keep up with our expert coverage on security matters. Also, follow us at&nbsp;<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noopener\">@MSFTSecurity<\/a>&nbsp;for the latest news and updates on cybersecurity.<\/p>\n<hr>\n<p><sup>1<\/sup> Gartner, <a href=\"https:\/\/www.gartner.com\/en\/documents\/4005344\/market-guide-for-ai-trust-risk-and-security-management\" target=\"_blank\" rel=\"noopener\">Market Guide for AI Trust, Risk and Security Management<\/a>, Avivah Litan, et al., 1 September 2021 GARTNER is a registered trademark and service mark of Gartner, Inc. and\/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.<\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/12\/09\/best-practices-for-ai-security-risk-management\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today, we are releasing an AI security risk assessment framework as a step to empower organizations to reliably audit, track, and improve the security of the AI systems. In addition, we are providing new updates to Counterfit, our open-source tool to simplify assessing the security posture of AI systems.<br \/>\nThe post Best practices for AI security risk management appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":44356,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[408,6859,347],"class_list":["post-44355","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-ai","tag-ai-and-machine-learning","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Best practices for AI security risk management 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Best practices for AI security risk management 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-12-09T21:00:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/12\/MSC16_slalom_018.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/best-practices-for-ai-security-risk-management\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/best-practices-for-ai-security-risk-management\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Best practices for AI security risk management\",\"datePublished\":\"2021-12-09T21:00:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/best-practices-for-ai-security-risk-management\\\/\"},\"wordCount\":1094,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/best-practices-for-ai-security-risk-management\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/best-practices-for-ai-security-risk-management.jpg\",\"keywords\":[\"AI\",\"AI and machine learning\",\"Cybersecurity\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/best-practices-for-ai-security-risk-management\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/best-practices-for-ai-security-risk-management\\\/\",\"name\":\"Best practices for AI security risk management 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/best-practices-for-ai-security-risk-management\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/best-practices-for-ai-security-risk-management\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/best-practices-for-ai-security-risk-management.jpg\",\"datePublished\":\"2021-12-09T21:00:43+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/best-practices-for-ai-security-risk-management\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/best-practices-for-ai-security-risk-management\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/best-practices-for-ai-security-risk-management\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/best-practices-for-ai-security-risk-management.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/best-practices-for-ai-security-risk-management.jpg\",\"width\":1200,\"height\":800},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/best-practices-for-ai-security-risk-management\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AI\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/ai\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Best practices for AI security risk management\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Best practices for AI security risk management 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/","og_locale":"en_US","og_type":"article","og_title":"Best practices for AI security risk management 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-12-09T21:00:43+00:00","og_image":[{"url":"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/12\/MSC16_slalom_018.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Best practices for AI security risk management","datePublished":"2021-12-09T21:00:43+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/"},"wordCount":1094,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/12\/best-practices-for-ai-security-risk-management.jpg","keywords":["AI","AI and machine learning","Cybersecurity"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/","url":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/","name":"Best practices for AI security risk management 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/12\/best-practices-for-ai-security-risk-management.jpg","datePublished":"2021-12-09T21:00:43+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/12\/best-practices-for-ai-security-risk-management.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/12\/best-practices-for-ai-security-risk-management.jpg","width":1200,"height":800},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/best-practices-for-ai-security-risk-management\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"AI","item":"https:\/\/www.threatshub.org\/blog\/tag\/ai\/"},{"@type":"ListItem","position":3,"name":"Best practices for AI security risk management"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/44355","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=44355"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/44355\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/44356"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=44355"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=44355"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=44355"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}