24

Immagine creata con IAAI-generated image

Before managing AI risks you have to be able to name them. Four tools, all public and free, offer as many perspectives: NIST’s management framework, MIT’s taxonomic repository with over 1,700 catalogued risks, the Cloud Security Alliance’s controls matrix and ENISA’s cybersecurity framework. A reasoned map for those building AI governance.

Anyone setting out to build a system of AI governance — by regulatory obligation or organisational choice — soon meets a preliminary difficulty: which risks are we talking about? A survey of the main public reference tools is useful, with the caveat that these are voluntary tools, which do not replace the AI Act obligations but can feed their implementation: from risk management under Article 9 to the impact assessments imposed by the binding European framework.

NIST AI RMF: the management framework

The first reference is American: the AI Risk Management Framework of the National Institute of Standards and Technology (NIST), published in January 2023. Its vocation is stated: “the NIST AI Risk Management Framework (AI RMF) is intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems”. Its operational heart is the Core, articulated in four functions: “the Core is composed of four functions: govern, map, measure, and manage”. GOVERN oversees culture and organisational set-up; MAP contextualises the system and identifies its risks; MEASURE analyses and quantifies them; MANAGE treats them.

MIT AI Risk Repository: the living taxonomy

Of a different nature is the AI Risk Repository of MIT: not a management framework, but “a comprehensive living database of over 1700 AI risks categorized by their cause and risk domain”. The database “captures 1700+ risks extracted from 74 existing frameworks and classifications of AI risks”, organised according to a causal taxonomy and a domain taxonomy classifying risks into seven domains and twenty-four subdomains. Its practical utility is notable: anyone conducting a risk assessment can use the repository as a completeness checklist, verifying that they have not overlooked entire risk domains — from disinformation to system security, from discrimination to loss of control.

CSA AI Controls Matrix: from risks to controls

The step from risk to control is the terrain of the AI Controls Matrix (AICM) of the Cloud Security Alliance, released in July 2025: “the AICM contains 243 control objectives distributed across 18 security domains. It maps to leading standards, including ISO 42001, ISO 27001, NIST AI RMF 1.0, and BSI AIC4”. The cross-mapping is its greatest merit: an organisation that has adopted an AI management system, or is preparing for the AI Act obligations, can use the matrix to translate high-level requirements into verifiable control objectives, in a language familiar to those coming from information security.

ENISA: the cybersecurity perspective

The survey closes with the Multilayer Framework for Good Cybersecurity Practices for AI of ENISA, of June 2023: “the framework consists of three layers (cybersecurity foundations, AI-specific cybersecurity and sector-specific cybersecurity for AI) and aims to provide a step-by-step approach on following good cybersecurity practices”. The layered logic is precious: it recalls that AI security rests on the foundations of general cybersecurity, specialises on the risks proper to learning systems, and is finally declined by sector.

How to use the map

Four tools, four complementary functions: NIST offers the process, MIT the taxonomy, CSA the controls, ENISA the security perspective. For a European organisation, the value lies not in adopting them all, but in using them as sources feeding its own obligations: the taxonomy so as not to forget risks, the process to govern them, the controls to implement them — all within the binding frame of the AI Act and, where adopted, its own management system. With the usual caveat: none of these tools generates presumptions of conformity, and their use must be documented as a methodological choice, not exhibited as a licence.

Conclusions

The proliferation of frameworks and taxonomies is, at once, a richness and a risk: a richness, because the public stock of knowledge on AI risks has never been so vast; a risk, because the multiplication of tools can fuel a façade compliance, made of juxtaposed and never-integrated mappings. In the light of the above, one wonders whether organisations will move from collecting frameworks to a genuinely integrated risk management, one that does not exhaust itself in the juxtaposition of matrices and taxonomies but is able to intercept the risks to people, who are the ultimate reason for every framework.


AI AnthropoCosmic In evidenzaAI AnthropoCosmicUn progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo, che mette al centro la dignità della persona nella progettazione dei sistemi. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicAn international project for an AI at the service of humanity, the environment and the cosmos, placing human dignity at the centre of system design. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article
Intervista Radio Radio IntervistaLegge e colossi del digitaleIl patteggiamento di Meta sui minori non è una condanna. Stati Uniti ed Europa seguono strade opposte, e sugli agenti di IA resta aperta la domanda su chi risponde.Un Giorno Speciale su Radio Radio, con Alessio De Paolis · audio dal minuto 2:26:00Ascolta l’intervistaGuarda il videoLeggi l’articolo
Digital Omnibus ContributoIl Digital Omnibus cambia l’AI ActNuove scadenze per i sistemi ad alto rischio e un chiarimento sull’obbligo di AI literacy: più tempo per adeguarsi, nessuno sconto sulla preparazione di persone e processi.Articolo scritto per il blog di SkillaLeggi su Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo tra i relatori del festival dedicato a protezione dei dati, archivi digitali e regole del futuro. Interviene sul tema «Le regole dell’IA: nuove leggi o principi del diritto?».Venerdì 6 novembre 2026, ore 16:30, Ex Convitto Palmieri, LecceL’interventoLa scheda relatriceIl festival
AI AnthropoCosmic 2026Moderatrice e relatriceAI AnthropoCosmic 2026Valentina Grazia Sapuppo nel progetto dell’Università Pontificia Salesiana su Persona, Ambiente e Cosmo: moderazione della sessione mattutina del Convegno finale e intervento negli AI Laboratori del Domani su commercio elettronico e IA.14 novembre 2026, online · 28 novembre 2026, Università Pontificia Salesiana, RomaIl convegnoL’incontroIl contributoLa relatriceIl progetto
Interview Radio Radio InterviewLaw and the digital giantsThe Meta settlement on minors is not a conviction. The United States and Europe take opposite paths, and on AI agents the question of who answers remains open.Un Giorno Speciale on Radio Radio, with Alessio De Paolis · audio from 2:26:00 · in ItalianListen to the interviewWatch the videoRead the article
Digital Omnibus ContributionThe Digital Omnibus reshapes the AI ActNew deadlines for high-risk systems and a clarification on the AI literacy duty: more time to comply, no discount on preparing people and processes.Article written for the Skilla blog, in ItalianRead on Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo among the speakers of the festival on data protection, digital archives and the rules of the future. She takes part in the panel «The rules of AI: new laws or principles of law?».Friday 6 November 2026, 16:30, Ex Convitto Palmieri, LecceThe panelSpeaker profileThe festival
AI AnthropoCosmic 2026Moderator and speakerAI AnthropoCosmic 2026Valentina Grazia Sapuppo in the project of the Università Pontificia Salesiana on Person, Environment and Cosmos: moderator of the morning session of the closing conference and speaker at the AI Laboratori del Domani on e-commerce and AI.14 November 2026, online · 28 November 2026, Università Pontificia Salesiana, Rome · sessions held in ItalianThe conferenceThe sessionThe contributionSpeakerThe project