AI Governance Library

A Sensible Regulatory Framework for AI Security

MITRE paper proposing elements of a US regulatory framework for AI security, organised around three categories of AI application — subsystem, human augmentation and agency — with twelve recommendations on assurance, auditability, transparency and critical infrastructure.
Cover of A Sensible Regulatory Framework for AI Security

⚡ Quick Summary

Published by MITRE, this paper of 2 June 2023 proposes elements of a regulatory framework for AI security built on a vulnerability, threat and risk calculus. It argues that any attempt to secure or regulate a new technology should be informed by its vulnerabilities, the threats that exploit them, and the resulting risk of harm to life, health, property or the environment, and that these differ according to how AI manifests in applications.

The paper divides the AI ecosystem into three categories: engineered systems that use AI as a component or subsystem, AI as an augmentation of human capabilities, and AI operating autonomously under its own agency. It reviews regulatory concepts under debate — third-party auditing and certification, regulating access to computational power, national AI agencies, liability for AI-caused harms, tracking model leaks, AI safety research funding and standards for AI-generated content — finding some with merit and others likely to limit competition or lack sector context. It favours regulating AI at the point where it intersects an already regulated industry, citing extension of the Food and Drug Administration's "Software as a Medical Device" regime as an example.

Its deliverable is a matrix pairing each category with the action MITRE considers most critical, followed by twelve numbered recommendations covering assurance, auditability, transparency, critical infrastructure hardening and AI alignment research funding.

🧩 What’s Covered

The paper moves from technology context to a decomposition of AI applications, then to a set of sector-facing recommendations.

  • Background: traces the advances behind the current wave, including GPU-enabled training of deep neural networks in 2012 and Google researchers' 2017 transformer networks, and lists resulting capabilities such as improved machine perception, reinforcement-learning optimisation and planning engines, and generative algorithms producing text, audio and images.
  • Three-category decomposition: separates the AI ecosystem into AI as a component or subsystem, AI as human augmentation, and AI with agency, because threats, risks and mitigations differ by category.
  • AI as a subsystem: covers data poisoning and adversarial input attacks, the MITRE ATLAS framework, the Arsenal red-teaming tool released with Microsoft, model cards, MITRE's definition of AI assurance as a lifecycle process, and the NIST AI Risk Management Framework as an example approach.
  • AI as human augmentation and AI with agency: discusses LLMs in white-collar tasks, bad actors using AI as a "co-pilot" for cyber operations and mis/disinformation, and goal-seeking systems such as Auto-GPT and Chaos-GPT, with Stuxnet cited as an early example of autonomous malware.
  • Regulatory approaches: quotes the Future of Life Institute's seven policymaking recommendations, summarises congressional debate topics, argues against compute as a regulatory throttle, and sets out four analysis questions about objects, problems, governance mechanisms and instruments.
  • Framework matrix and recommendations 1–6: pairs each category with its most critical action and details requirements for software and AI-specific assurance, sector NIST AI RMF response plans, component-interaction risk, pre-deployment assurance cases, use-context and domain-specific regulation, continuous regulatory analysis, and trusted information sharing.
  • Recommendations 7–12: covers system auditability to hold human misusers accountable, accountability scaled with risk, third-party and public transparency for detecting AI misuse, critical infrastructure plans and automated red teaming, federal funding for AI alignment vocabulary and frameworks, and safe regulated research environments.

💡 Why it matters?

The paper gives governance and assurance practitioners a way to sort AI use cases before arguing about rules: whether AI acts as a component, an augmentation or an agent determines the threat model and the mitigations that follow. It argues for placing AI regulation inside existing sector regulators rather than a new federal agency, and recommends concrete artefacts — sector-level NIST AI RMF response plans, pre-deployment assurance cases, component-interaction testing, system auditability, and information sharing built on ATT&CK and ATLAS. For teams drafting policy, assessing risk or assembling assurance arguments, it supplies shared vocabulary and testable expectations to map against their own obligations.

❓ What’s Missing

The paper offers principles rather than instruments: it names no statutory text, thresholds, reporting timelines or assurance-case template, and it does not define AI, noting only that no single widely accepted definition exists. Recommendations are addressed to US federal and industry regulators and assume capable existing sector regulators; cross-border coordination is left unresolved beyond a rejection of compute-based arms control. The content reflects the policy debate of June 2023, and near-term projections such as AI-enabled cyber operations before the end of 2023 are dated. Costs, staffing and implementation sequencing are not estimated.

👥 Best For

Best for policy and regulatory affairs staff tracking AI security debates, sector regulators weighing how to extend existing regimes to AI-enabled products, and assurance or security engineering teams that need to build NIST AI RMF response plans, assurance cases and auditability requirements for AI components in critical systems.

📄 Source Details

The paper is A Sensible Regulatory Framework for AI Security, published by MITRE (The MITRE Corporation) and dated 2 June 2023. Authors listed under "About the Authors" are T. Charles Clancy, Douglas P. Robbins, Ozgur Eris, Lashon B. Booker and Katie Enos. The document runs to 13 pages and carries public release case number 23-1943; mitre.org is printed on page 13, but no URL for the document itself appears. Text extraction covered all 13 pages, although the cover page yielded no extractable text.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.