<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>AI Risk |</title><link>https://sanaamironov.com/tags/ai-risk/</link><atom:link href="https://sanaamironov.com/tags/ai-risk/index.xml" rel="self" type="application/rss+xml"/><description>AI Risk</description><generator>HugoBlox Kit (https://hugoblox.com)</generator><language>en</language><lastBuildDate>Wed, 27 May 2026 00:00:00 +0000</lastBuildDate><image><url>https://sanaamironov.com/media/sharing.png</url><title>AI Risk</title><link>https://sanaamironov.com/tags/ai-risk/</link></image><item><title>LLM-Enabled IAM Risk Mapping</title><link>https://sanaamironov.com/projects/llm-iam-risk-mapping/</link><pubDate>Wed, 27 May 2026 00:00:00 +0000</pubDate><guid>https://sanaamironov.com/projects/llm-iam-risk-mapping/</guid><description>&lt;p&gt;This research project examines how LLM-enabled identity and access management tools introduce new risk patterns across common IAM workflows.&lt;/p&gt;
&lt;p&gt;The project uses the OWASP Top 10 for LLM Applications and NIST Cybersecurity Framework 2.0 as organizing lenses for analyzing use cases such as account recovery, MFA reset, access request triage, provisioning, deprovisioning, policy Q&amp;amp;A, and privileged-access handling.&lt;/p&gt;
&lt;p&gt;The repository includes manuscript materials, experiment artifacts, local-model testing notes, and reproducibility instructions.&lt;/p&gt;
&lt;p&gt;Key themes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Workflow-centered AI risk assessment&lt;/li&gt;
&lt;li&gt;Mapping LLM threat taxonomies to governance frameworks&lt;/li&gt;
&lt;li&gt;Local model testing with open-weight LLMs&lt;/li&gt;
&lt;li&gt;Reproducibility materials for research review&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Next site pass: add the final abstract, paper status, and selected figures.&lt;/p&gt;</description></item><item><title>Mapping LLM Risks in Identity Workflows</title><link>https://sanaamironov.com/blog/llm-identity-risk-mapping/</link><pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate><guid>https://sanaamironov.com/blog/llm-identity-risk-mapping/</guid><description>&lt;p&gt;Identity workflows are sensitive because they connect people, permissions, access, and institutional trust. When LLMs enter those workflows, the risk surface changes.&lt;/p&gt;
&lt;p&gt;A useful risk mapping does more than list threats. It connects technical failure modes to security outcomes, governance responsibilities, and concrete controls. That is why frameworks such as OWASP LLM Top 10 and NIST CSF 2.0 are useful starting points.&lt;/p&gt;
&lt;p&gt;The goal is not to reject LLM-enabled tools. It is to understand where they can help, where they can fail, and what evidence teams need before trusting them in identity-related decisions.&lt;/p&gt;</description></item></channel></rss>