AI Governance Library

AI Assurance – Challenges, Maturity, and Paths Forward

MITRE policy wrapper summarising its 6 June 2024 AI Assurance Summit, where more than 150 federal attendees discussed AI assurance challenges, technical capability maturity and paths forward including assurance labs and automation.
Cover of AI Assurance – Challenges, Maturity, and Paths Forward

⚡ Quick Summary

Published by MITRE, this policy wrapper reports on an AI Assurance Summit hosted on 6 June 2024 that connected AI leaders from more than 20 U.S. federal agencies, with more than 150 in-person attendees and 13 government experts across two keynotes and three panels. MITRE defines AI assurance as "a process for discovering, assessing, and managing risk throughout the life cycle of an AI-enabled system so that it operates effectively to the benefit of its stakeholders", with outputs intended to support decisions on acquisition, deployment and use.

The stated goal is to identify common practices and capabilities to guarantee the safe, secure and effective application of AI in the United States. The discussion is organised around three themes: AI assurance challenges on the horizon, technical capability maturity, and actionable paths forward. It cites a 2023 Harris poll finding that 48 percent of Americans believe AI is safe and secure while 78 percent express concern about malicious use.

The deliverable is a set of summit outcomes and next steps: focus on problem-driven rather than technology-driven solutions, assure use cases rather than models alone, scale through automation and interoperability such as standard data sheets and model cards, and build a nationwide network of assurance labs with FFRDCs as trusted partners, supported by red teaming and AI incident reporting modelled on MITRE's ATLAS.

🧩 What’s Covered

The document follows the arc of the summit discussion, from framing to next steps.

  • The issue: the case for AI assurance, the dual challenge of keeping pace with rapid technological change while maintaining public trust, and 2023 Harris poll figures (48 percent of Americans believe AI is safe and secure; 78 percent are concerned about malicious use).
  • What MITRE did: the definition of AI assurance as a life-cycle risk process, MITRE's role operating six FFRDCs, and the summit design — invited federal agencies under Chatham House rules, more than 150 attendees from more than 20 agencies, two keynotes and three panels with 13 government experts.
  • Challenges on the horizon: beneficial uses such as citizen services, fraud detection, data triage and regulatory streamlining; appropriate versus inappropriate use; intentional and unintentional use; bias from training data and proxies; transparency and fairness; traceability and auditability where explainability is infeasible; and the data, model, software and hardware stack.
  • Generative AI concerns: prompt injections, hallucinations, sensitive data exposure, poisoned sources, lack of repeatability and user over-reliance.
  • Technical capability maturity: existing software assurance and cybersecurity practice as starting points, plus open questions on mission alignment, stakeholder objectives, adversarial users, evaluation scale, sociotechnical impact, operational design domains, model belief representations, and interoperability through data sheets and model cards.
  • Paths forward and outcomes: safe mission-driven experimental environments, learning from specific use cases, automation as the greatest return on investment, problem-driven rather than technology-driven solutions, multi-disciplinary stakeholders, cost commensurate with risk, a nationwide network of assurance labs, and ATLAS as a model for incident reporting and vulnerability sharing.
  • Resources and about MITRE: citations to the MITRE-Harris poll and a companion MITRE publication on a repeatable assurance process, the March 2024 AI Assurance and Discovery (AIAD) Lab, and more than 800 AI engineers and data scientists.

💡 Why it matters?

For federal and other public-sector teams facing what the document describes as a rapidly growing set of government AI adoption requirements, the wrapper gives a compact statement of what AI assurance is and where practitioners say it remains immature. It frames assurance as a life-cycle risk process whose outputs feed acquisition, deployment and use decisions, helping governance and acquisition staff connect assurance work to concrete decisions. The open questions on evaluation scope, sociotechnical impact, operational design domains and interoperability point to where tooling, documentation and standards work is still needed, and the emphasis on red teaming and incident reporting shows the security operations dimension of assurance.

❓ What’s Missing

The document summarises a closed, invitation-only summit held under Chatham House rules, so speakers are not attributed and individual positions cannot be traced. It offers no methodology, assessment criteria, implementation steps or worked use cases, and it names no specific regulations or standards. Quantitative content is limited to the Harris poll figures and attendance counts. Open questions — how to scale evaluations, cost assurance, document operational design domains or represent model beliefs — are raised without proposed answers. The ATLAS reference points to a platform the document does not describe in detail.

👥 Best For

Best for policy and governance staff in government agencies who need a short orientation to AI assurance terminology, challenges and direction of travel, and for programme leads who must justify assurance resources. It also suits risk and security teams standing up assurance or red-teaming functions, and anyone tracking U.S. public-sector AI assurance priorities.

📄 Source Details

The resource is AI Assurance – Challenges, Maturity, and Paths Forward, a MITRE policy wrapper dated June 2024 and marked "© 2024 MITRE. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED. PUBLIC RELEASE CASE NUMBER 23-02057-30". No authors are named. The file runs to four pages, and the extracted text of all four pages was available for this review. The URLs printed in the document point to other MITRE resources — the Harris poll release, a companion publication on a repeatable assurance process, and atlas.mitre.org — not to this document.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.