ai-risk-management

Generate AI governance artefacts mapped to ISO/IEC 42001 and EU AI Act.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill ai-risk-management-blamejs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ai-risk-management
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/ai-risk-management
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill ai-risk-management-blamejs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Most organizations deploying AI systems in 2026 rely on outdated governance frameworks that have no controls for AI-specific threats like prompt injection, MCP supply chain compromise, and AI-as-C2. Existing standards such as NIST 800-53 and SOC 2 were designed for network-centric, on-prem environments and fail to address AI pipeline integrity, agent trust boundaries, or AI-discovered zero-day vulnerabilities. This skill fills that gap by operationalizing modern AI governance frameworks into concrete, auditable artefacts.

Core Features & Use Cases

  • AI Inventory Ledger: Enumerate every AI asset in your organization including LLM APIs, agent runtimes, MCP servers, RAG corpora, and model weights to eliminate unknown AI surface area.
  • Framework Operationalization: Translate requirements from ISO/IEC 42001, ISO/IEC 23894, NIST AI RMF 1.0, and the EU AI Act into actionable risk treatment registers, red-team programmes, and incident response playbooks.
  • Threat-Aligned Governance: Map governance gaps to real-world 2026 threats including MITRE ATLAS TTPs, CVE vulnerabilities, and CWE weakness classes to ensure controls address actual attack patterns.
  • Use Case: A fintech deploying LLM-powered customer service agents can use this skill to classify use cases per EU AI Act risk tiers, build a compliant AI inventory, and set up a quarterly red-team cadence mapped to prompt injection and agent compromise TTPs.

Quick Start

Use the ai-risk-management skill to build a complete, auditable AI governance programme for your organization's LLM, agent, and RAG deployments, aligned to ISO 42001 and EU AI Act high-risk obligations.

Frequently Asked Questions about ai-risk-management

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build an AI governance program that addresses prompt injection and agent compromise threats?

To build AI governance for modern threats, you operationalize ISO 42001 and NIST AI RMF requirements into structured risk treatment registers and red-team playbooks mapped to MITRE ATLAS TTPs, ensuring controls address actual attack patterns.

What is the best way to create an EU AI Act high-risk compliant inventory for LLM deployments?

The best way to create an EU AI Act compliant inventory is to enumerate every AI asset including LLM APIs, agent runtimes, MCP servers, and RAG corpora into an auditable ledger, eliminating unknown AI surface area across your organization.

How do I translate ISO 42001 and ISO 23894 requirements into actionable risk treatment registers?

You translate ISO 42001 and ISO 23894 requirements into actionable risk treatment registers by mapping governance gaps to real-world threats including MITRE ATLAS TTPs and CWE weakness classes, producing auditable artefacts for your AI systems.

Can I use this AI risk management approach for RAG pipelines and MCP server environments?

Yes, this AI risk management approach explicitly applies to organizations deploying RAG pipelines and MCP servers, mapping governance controls to threats like MCP supply chain compromise and ensuring agent trust boundaries are documented.

Why does my legacy NIST 800-53 framework fail to cover AI-specific threats like AI-as-C2?

Legacy frameworks like NIST 800-53 fail for AI threats because they were designed for network-centric, on-prem environments and lack controls for AI pipeline integrity, agent trust boundaries, and AI-discovered zero-day vulnerabilities.

Do I need a red-team programme charter to comply with NIST AI RMF 1.0 high-risk obligations?

Yes, operationalizing NIST AI RMF 1.0 high-risk obligations requires a red-team programme charter mapped to prompt injection and agent compromise TTPs, establishing a quarterly cadence to test AI-specific threat resilience.