The CoSAI Risk Map is a framework for identifying, analyzing, and mitigating security risks in Artificial Intelligence systems. As traditional software security practices are not always sufficient for AI, this project provides a shared understanding and a common language for addressing the unique security challenges of the AI development lifecycle.
Check whether a CoSAI Risk Map entry is pitched at the right altitude (granularity). For a control: objective-not-implementation, not-a-restated-risk, posture-not-mandate, solved-problem, no-duplication. For a risk: the merge-vs-distinct two-test, threat-not-control-gap, and real-not-hypothetical. For a component: the…
Audit framework mappings — an existing entity's mappings, the whole corpus, or a candidate value proposed for an entity not yet in the corpus — against the framework mappings style guide. Use when reviewing, auditing, or pre-PR authoring mapping changes for risks.yaml, controls.yaml, or personas.yaml.
Audit persona identification questions in personas.yaml against the identification questions style guide. Use when reviewing or proposing changes to identificationQuestions.
Ground CoSAI Risk Map terminology in established security terms of art. Use when authoring or critiquing a Control, Risk, Component, or Persona title or description to check a proposed term against the canonical (NIST-first) vocabulary, replace an invented term with its established equivalent, generalize a…
Select the structured references and framework mappings for a CoSAI Risk Map control or risk — for a control: which components it applies to, which risks it addresses, and which mappings (MITRE ATLAS mitigations, NIST AI RMF subcategories, OWASP LLM, EU AI Act articles) fit; for a risk: which components it impacts…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: