Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ A blocking link-check workflow runs on pull requests and monthly. `REVIEW_STATUS
### United States

- **[NIST AI Risk Management Framework](https://airc.nist.gov/home)** — NIST’s official hub for the voluntary framework organized around Govern, Map, Measure, and Manage.
- **[NIST AI Safety Institute](https://www.nist.gov/artificial-intelligence/executive-order-safe-secure-and-trustworthy-artificial-intelligence)** — Federal AI safety research and standards coordination.
- **[NIST AI Program and Center for AI Standards and Innovation](https://www.nist.gov/artificial-intelligence)** — NIST’s official AI hub covering AI RMF resources, measurement science, standards, evaluations, and related federal AI programs.
- **[OMB AI Governance Policy M-24-10](https://www.whitehouse.gov/wp-content/uploads/2024/03/M-24-10-Advancing-Governance-Innovation-and-Risk-Management-for-Agency-Use-of-Artificial-Intelligence.pdf)** — U.S. federal agency governance and risk-management requirements for AI use.

### European Union
Expand All @@ -70,7 +70,7 @@ A blocking link-check workflow runs on pull requests and monthly. `REVIEW_STATUS
- **[Microsoft Responsible AI Standard](https://blogs.microsoft.com/wp-content/uploads/prod/sites/5/2022/06/Microsoft-Responsible-AI-Standard-v2-General-Requirements-3.pdf)** — Public responsible-AI standard and requirements guide.
- **[Google PAIR Guidebook](https://pair.withgoogle.com/guidebook/)** — People + AI Research guidebook for human-centered AI design.
- **[MITRE ATLAS](https://atlas.mitre.org/)** — Knowledge base of AI-specific adversarial tactics and techniques.
- **[OWASP Top 10 for LLMs](https://owasp.org/www-project-top-10-for-large-language-model-applications/)** — Common security risks in LLM applications.
- **[OWASP Top 10 for LLMs and GenAI Apps](https://genai.owasp.org/llm-top-10/)** — Current OWASP GenAI Security Project page for LLM and generative-AI application risks and mitigations.

---

Expand Down Expand Up @@ -191,4 +191,4 @@ When adding a resource:

[![CC0](https://mirrors.creativecommons.org/presskit/buttons/88x31/svg/cc-zero.svg)](https://creativecommons.org/publicdomain/zero/1.0/)

To the extent possible under law, Sima Bagheri has waived all copyright and related or neighboring rights to this work.
To the extent possible under law, Sima Bagheri has waived all copyright and related or neighboring rights to this work.
10 changes: 7 additions & 3 deletions REVIEW_STATUS.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,13 +6,15 @@ This ledger distinguishes automated link health from manual content freshness. A
**Review owner:** Repository maintainer
**Rule:** Record a dated content review only after checking the linked primary source and the description in `README.md`.

See [`docs/source-reviews/2026-07-core-authoritative-sources.md`](docs/source-reviews/2026-07-core-authoritative-sources.md) for the scope and limits of the first documented source review.

## Regulatory Frameworks

| Section | Last confirmed content review | Next review due | Status |
|---|---:|---:|---|
| United States | Not yet recorded | 2026-12-24 | Requires initial manual review |
| European Union | Not yet recorded | 2026-12-24 | Requires initial manual review |
| International Standards | Not yet recorded | 2026-12-24 | Requires initial manual review |
| United States | 2026-07-07 | 2026-10-07 | Initial NIST AI hub source classification reviewed; OMB source remains pending |
| European Union | 2026-07-07 | 2026-10-07 | Initial source classification reviewed; legal-timeline interpretation remains out of scope |
| International Standards | 2026-07-07 | 2026-10-07 | Initial ISO/OECD source and description review completed; IEEE and ISO/IEC 23894 remain pending |

## Other active resources

Expand All @@ -21,6 +23,8 @@ This ledger distinguishes automated link health from manual content freshness. A
| Open-source tools and platforms | Not yet recorded | 2026-09-24 | Requires initial manual review |
| Benchmarks and evaluation frameworks | Not yet recorded | 2026-09-24 | Requires initial manual review |
| Communities and courses | Not yet recorded | 2026-12-24 | Requires initial manual review |
| LLM security guidance | 2026-07-07 | 2026-10-07 | OWASP source reviewed and README destination refreshed to the current GenAI Security Project page |
| Adversarial-AI knowledge bases | 2026-07-07 | 2026-10-07 | MITRE ATLAS source classification reviewed; technique coverage review remains pending |

## Update procedure

Expand Down
28 changes: 28 additions & 0 deletions docs/source-reviews/2026-07-core-authoritative-sources.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
# Core Authoritative-Source Review — 2026-07-07

## Scope

This was a limited first-pass content review of the core authoritative sources that anchor PRISM's regulatory and security sections. It did **not** validate every linked tool, benchmark, community, course, or secondary guide.

## Reviewed sources and findings

| Resource | Result | README description check | Follow-up |
|---|---|---|---|
| NIST AI program hub | Official NIST page identifies the AI RMF, Center for AI Standards and Innovation, AI Resource Center, standards work, evaluations, and NIST's nonregulatory measurement-science role. | Updated the U.S. entry to point to the broader current NIST AI hub rather than an older executive-order page. | Review the AI RMF and supporting resources separately, including current profiles and implementation guidance. |
| ISO/IEC 42001:2023 | Official ISO page identifies it as a published international standard for an AI management system. | Accurate. | Keep the existing ISO link and review on the normal standards cadence. |
| OECD AI Principles | Official OECD page states that the principles promote innovative, trustworthy AI and were updated in May 2024. | Accurate but could eventually note the 2024 update. | Keep the existing link. |
| OWASP Top 10 for LLM Applications | Official OWASP page states that the original Top 10 is now part of the broader OWASP GenAI Security Project and directs readers to the current dedicated LLM Top 10 location. | Updated the README destination and label to the current GenAI Security Project LLM Top 10 page. | Review OWASP's agentic-app and GenAI governance resources separately. |
| EU AI Act | The README links directly to the official EUR-Lex text for Regulation (EU) 2024/1689. | Accurate as a source classification. | Review implementation dates and related secondary guidance separately; do not rely on the hub's one-line entry for legal interpretation. |
| MITRE ATLAS | The README links to the official MITRE ATLAS site. | Accurate as a source classification. | Perform a separate content review of ATLAS technique coverage and release/versioning. |

## Review discipline

- A source was recorded as reviewed only where the source owner and high-level description could be checked directly.
- This review did not certify legal currency, implementation completeness, safety sufficiency, or applicability to any organization.
- Secondary summaries remain secondary. The EU AI Act summary entry should continue to direct readers back to EUR-Lex for legal interpretation.

## Next review priorities

1. Review NIST AI RMF and related implementation resources separately, including current supporting profiles and resources.
2. Review OWASP's agentic-app security, AI security governance checklist, and GenAI Security Project resources beyond the LLM Top 10.
3. Complete the first manual review of open-source tools, benchmarks, and communities using the criteria in `CURATION.md`.
Loading