R0043/2026-03-28/Q003/SRC02
Standardized Threat Taxonomy for AI Security, Governance, and Regulatory Compliance
Source
| Field |
Value |
| Title |
Standardized Threat Taxonomy for AI Security, Governance, and Regulatory Compliance |
| Publisher |
arXiv |
| Author(s) |
Various |
| Date |
November 2025 |
| URL |
https://arxiv.org/html/2511.21901 |
| Type |
Research paper (preprint) |
Summary
| Dimension |
Rating |
| Reliability |
Medium-High |
| Relevance |
High |
| Bias: Missing data |
Some concerns |
| Bias: Measurement |
Low risk |
| Bias: Selective reporting |
Low risk |
| Bias: Randomization |
N/A — not an RCT |
| Bias: Protocol deviation |
N/A — not an RCT |
| Bias: COI/Funding |
Low risk |
Rationale
| Dimension |
Rationale |
| Reliability |
Preprint but comprehensive; CC-BY 4.0 licensed; maps to NIST, ISO, and EU frameworks |
| Relevance |
Most systematic bridging effort found; explicitly identifies the disciplinary disconnect |
| Bias flags |
Missing data concern: explicitly omits sycophancy/overreliance as a threat category |
| Evidence ID |
Summary |
| SRC02-E01 |
53-threat taxonomy bridges technical and regulatory domains but omits sycophancy as a distinct threat |