What problem does it solve?
Most organizations deploying AI systems in 2026 rely on outdated governance frameworks that have no controls for AI-specific threats like prompt injection, MCP supply chain compromise, and AI-as-C2. Existing standards such as NIST 800-53 and SOC 2 were designed for network-centric, on-prem environments and fail to address AI pipeline integrity, agent trust boundaries, or AI-discovered zero-day vulnerabilities. This skill fills that gap by operationalizing modern AI governance frameworks into concrete, auditable artefacts.
Core Features & Use Cases
- AI Inventory Ledger: Enumerate every AI asset in your organization including LLM APIs, agent runtimes, MCP servers, RAG corpora, and model weights to eliminate unknown AI surface area.
- Framework Operationalization: Translate requirements from ISO/IEC 42001, ISO/IEC 23894, NIST AI RMF 1.0, and the EU AI Act into actionable risk treatment registers, red-team programmes, and incident response playbooks.
- Threat-Aligned Governance: Map governance gaps to real-world 2026 threats including MITRE ATLAS TTPs, CVE vulnerabilities, and CWE weakness classes to ensure controls address actual attack patterns.
- Use Case: A fintech deploying LLM-powered customer service agents can use this skill to classify use cases per EU AI Act risk tiers, build a compliant AI inventory, and set up a quarterly red-team cadence mapped to prompt injection and agent compromise TTPs.
Quick Start
Use the ai-risk-management skill to build a complete, auditable AI governance programme for your organization's LLM, agent, and RAG deployments, aligned to ISO 42001 and EU AI Act high-risk obligations.