On June 2, 2026, the United States crossed a quiet but important threshold in the governance of artificial intelligence. The federal government created a voluntary pathway for leading AI developers to provide pre-release access to advanced models for national security and cybersecurity review. The review window was limited, the framework was not mandatory, and the order did not create a licensing regime for frontier AI. Yet the signal was clear: the most capable AI systems are no longer being treated only as commercial products. They are beginning to be treated as infrastructure-adjacent technologies with national consequences.
The immediate issue was not synthetic consciousness, autonomous weapons, or any of the more theatrical fears that often dominate public discussion of AI. The immediate issue was software. More precisely, it was the growing ability of frontier AI systems to discover, reason about, and potentially operationalize software vulnerabilities at a speed and scale that existing institutions were not built to absorb. A model that helps a trusted security team find unknown defects in critical software can be a defensive breakthrough. The same model, released without adequate controls or stolen from its developer, can become a force multiplier for adversaries.

That is the dual-use problem in its most practical form. It is also why the issue belongs at the center of the AIxEnergy conversation. The public debate still treats AI and energy mainly as a load-growth story: data centers need power, chips need cooling, transmission queues are filling, utilities are revising forecasts, and large technology companies are searching for firm electricity supplies. Those pressures are real. They are already reshaping utility planning, generation procurement, gas infrastructure, nuclear strategy, hydropower contracting, behind-the-meter development, and demand flexibility.
But the load-growth story is only the visible edge of a deeper transition. AI is not merely consuming electricity. It is beginning to enter the operating layer of the systems that produce, deliver, price, protect, and govern electricity. The grid is becoming more digital at the same moment AI is becoming more capable. That convergence changes the meaning of cybersecurity. Cybersecurity is no longer only about protecting networks from intrusion. It is increasingly about preserving the integrity of the machine layer beneath modern life.
The Old Bargain: Fast Software, Deferred Security
Modern civilization rests on software that was not designed for the weight it now carries. Banks, hospitals, water systems, airports, pipelines, telecom networks, public agencies, data centers, cloud platforms, manufacturing plants, and electric utilities all depend on code assembled over decades. Some of that code is modern, tested, and well maintained. Much of it is not. It includes legacy systems, vendor packages, open-source libraries, embedded firmware, remote-access tools, identity platforms, cloud services, operational databases, field devices, scripts, and interfaces that were never built for a permanently contested digital environment.
For years, the software economy lived under a tacit bargain. Build quickly, add features, ship updates, expand functionality, and patch later. Cybersecurity became the compensating industry around that bargain. Firewalls, endpoint protection, vulnerability scanners, managed detection, threat intelligence, penetration testing, incident-response retainers, cyber insurance, identity platforms, and compliance programs grew around the fact that the underlying software base remained structurally fragile. The premise was not that the system was secure. The premise was that insecurity could be managed.
AI challenges that premise because it changes the economics of finding flaws. Historically, serious vulnerability discovery required scarce expertise. A capable researcher needed to understand the target, inspect code or binaries, infer system behavior, test inputs, trace failure conditions, and determine whether a weakness could be exploited. Automation helped, but high-end vulnerability research still depended on specialized human judgment, patience, and domain knowledge.
Frontier AI weakens those constraints. A sufficiently capable model can analyze large codebases, identify suspicious implementation patterns, reason across dependencies, generate test cases, inspect authentication flows, compare code against known weakness classes, and assist with exploitability analysis. It may not replace elite human researchers, but it can multiply them. It can also give less capable actors access to methods they could not previously use.
That is the central cyber transition. Vulnerability discovery is moving from expert craft toward industrial-scale cognitive automation. The first-order effect is more findings. The second-order effect is shorter time between discovery and exploitation. The third-order effect is institutional overload. It is one thing for AI to identify thousands of weaknesses. It is another for vendors, hospitals, utilities, banks, water systems, and public agencies to validate, prioritize, patch, and monitor those weaknesses before adversaries act.
This is where the issue stops being only technical. Discovery can move at model speed. Remediation still moves at organizational speed. The gap between those two speeds may become one of the defining infrastructure risks of the AI era.
The Vulnerability Window is Becoming the Critical Variable
Every vulnerability has a life cycle. It begins as a latent defect, becomes a security issue when someone discovers it, becomes an operational problem when someone can exploit it, becomes systemic when the affected software is widely deployed, and becomes a crisis when defenders cannot patch before attackers move. AI does not create that cycle. It compresses it.
In the pre-AI cyber model, defenders could still rely on friction. Attackers needed time, skill, infrastructure, target knowledge, and operational discipline. Even when criminal groups or state actors had advanced capabilities, the work still had bottlenecks. AI reduces those bottlenecks by making reconnaissance, code analysis, exploit-hypothesis generation, phishing, malware variation, configuration review, and vulnerability triage faster and cheaper.
This does not mean every AI-assisted operation will succeed. Cyber operations still require access, persistence, command infrastructure, operational security, target selection, and execution. But AI shifts the frontier by increasing the number of actors who can attempt sophisticated work, increasing the number of systems that can be scanned intelligently, and increasing the pressure on defenders who already struggle with patch backlogs, asset inventories, vendor dependencies, and operational constraints.
The most important metric in AI-era cybersecurity may become the vulnerability window: the period between the moment a serious flaw becomes discoverable and the moment it is effectively mitigated across exposed systems. That window is especially hard to close in critical infrastructure. A consumer application can often be patched rapidly. A substation environment, hospital network, water treatment plant, pipeline control environment, or grid operations platform may require vendor coordination, safety validation, scheduled maintenance windows, backup procedures, operator training, regulatory awareness, and careful testing before changes can be made.
The defender’s paradox is therefore acute. AI can help find more vulnerabilities, but finding more vulnerabilities does not automatically make society safer. It can simply enlarge the known-risk backlog unless the institutions responsible for repair become faster, better coordinated, and better resourced. A world that accelerates discovery without accelerating remediation does not become more secure. It becomes more aware of its fragility.
This is why the June 2026 policy signal matters. The issue is not whether one executive order is sufficient. It is not. The deeper point is that government and industry are beginning to recognize that frontier AI cyber capability cannot be treated as an ordinary software release. If a model can materially improve the discovery of dangerous vulnerabilities in widely used software, then release discipline becomes an infrastructure question.
Why the Electric Grid is Uniquely Exposed
The electric system is not simply one critical infrastructure sector among many. It is the enabling platform beneath the others. Hospitals need electricity. Water systems need electricity. Telecom networks need electricity. Emergency response needs electricity. Fuel logistics need electricity. Financial systems need electricity. Data centers need electricity. Modern government needs electricity. The digital economy sits on top of the power system.
That makes grid cybersecurity different in kind. A cyber incident in a single company can be costly, disruptive, and damaging. A cyber incident that affects electricity operations can propagate into public safety, economic continuity, fuel supply, communications, emergency response, and national security. The grid is also becoming more complex at the same moment AI demand is creating new load growth, new interconnection pressure, new data center clusters, and new operational volatility.
The system itself is changing. It is moving from a centralized machine built around large thermal and hydro plants toward a more distributed, inverter-rich, data-intensive, software-mediated system. Solar, wind, batteries, electric vehicles, heat pumps, flexible buildings, smart meters, grid-enhancing technologies, distributed energy resources, data centers, and advanced forecasting systems all increase the number of digital interfaces involved in planning and operations.
Each interface creates value. Each also creates exposure. The traditional grid was already cyber-physical. SCADA systems, energy management systems, distribution management systems, protective relays, outage management platforms, market systems, telecommunications networks, and field devices have long connected digital systems to physical consequences. But the AI-native grid adds a new layer: probabilistic, adaptive, data-hungry intelligence that may influence planning, operations, maintenance, markets, and emergency response.
This is not inherently bad. AI may be necessary to manage the complexity of the modern grid. The system is becoming too dynamic for purely deterministic tools and slow planning cycles. Operators need better forecasting, anomaly detection, asset intelligence, situational awareness, and decision support. Utilities need tools that can help interpret weather volatility, distributed resource behavior, customer load changes, equipment conditions, cyber alerts, and data center demand at speeds traditional workflows cannot match.
But AI also changes the control surface. A load forecast is not just a forecast if it informs dispatch, procurement, demand response, emergency operations, or capital planning. A distributed energy resource orchestration platform is not just software if it can shape megawatt-scale load behavior. A data center flexibility system is not just a commercial optimization tool if it can respond to price or grid signals at scale. An AI assistant is not just an assistant if it can read internal documents, query operational databases, draft configuration changes, open tickets, recommend switching actions, or trigger workflows.
The practical distinction is not between AI and non-AI. It is between advisory AI and agentic AI. It is between systems that inform humans and systems that act through permissions. This is where many energy organizations will underestimate the risk. They will evaluate the model when they should evaluate the model’s authority. A modest model with broad access may be more dangerous than a powerful model confined to a sandbox. The question is not only how capable the AI is. The question is what the AI can touch.
The New Risk Stack: From Prompt Injection to Physical Consequence
AI systems introduce a risk stack that traditional cybersecurity programs were not built to manage. The first layer is prompt injection. Large language models blur the boundary between instructions and data. A malicious instruction hidden inside an email, webpage, document, ticket, code comment, vendor advisory, or retrieved file can manipulate the model’s behavior. In a passive chatbot, this may produce a bad answer. In an agentic system connected to tools, it can cause data exposure, unsafe actions, or compromised workflows.
The second layer is insecure output handling. AI-generated output may be treated as trusted when it is not. If a model writes code, SQL, shell commands, configuration files, policy language, relay-setting suggestions, or control recommendations, those outputs must be validated before execution. Otherwise, the model becomes an untrusted code generator operating inside a trusted environment.
The third layer is training data poisoning and retrieval poisoning. AI systems depend on data. If training data, fine-tuning data, embeddings, retrieval sources, logs, tickets, telemetry, inspection records, market data, or asset records are manipulated, model outputs can be corrupted. In the energy sector, poisoned data can distort load forecasts, asset health models, wildfire risk tools, DER coordination systems, interconnection screening, or cyber defense triage.
The fourth layer is excessive agency. This is the risk created when AI systems are granted too much autonomy or too many permissions. An AI agent that can read, write, execute, approve, connect, or modify systems can create consequences beyond the intent of its designers. The problem is not intelligence alone. It is intelligence plus authority.
The fifth layer is model theft. A frontier model, fine-tuned model, prompt architecture, tool configuration, embedding database, or energy-specific AI system may encode sensitive knowledge. If stolen, it may reveal operational patterns, system dependencies, code vulnerabilities, asset conditions, defensive methods, or vendor relationships. A compromised model can become an adversary’s map.
The sixth layer is overreliance. Humans may trust AI outputs because they are fluent, fast, and confident. In grid operations, this is especially dangerous. An AI recommendation can be useful without being authoritative. Operators need decision support, not decision displacement.
These risks are no longer speculative. NIST’s AI Risk Management Framework gives organizations a structure for governing, mapping, measuring, and managing AI risk. NIST’s Generative AI Profile extends that structure to the distinctive risks of generative systems. NIST’s 2026 critical-infrastructure profile concept points toward the next stage: translating AI risk management into the operational context of infrastructure sectors. OWASP’s GenAI security work identifies concrete LLM application vulnerabilities, including prompt injection, insecure output handling, training data poisoning, excessive agency, overreliance, supply-chain vulnerabilities, and model theft.
The energy sector should not read these frameworks as compliance paperwork. It should read them as early maps of a new operating terrain. The danger is not that AI will suddenly make the grid unmanageable. The danger is that energy organizations will adopt AI into critical workflows faster than they adapt their cyber, data, governance, and operating disciplines.
The Cyber-Physical Clearinghouse Problem
The hardest problem in AI-enabled vulnerability discovery is not discovery. It is coordinated repair. Consider a plausible case. A frontier AI system identifies a serious vulnerability in a software component used across hospital backup-power systems, municipal utility control environments, building automation systems, and distributed energy resource platforms. The model flags a pattern. Researchers validate the issue. The vendor confirms the flaw. The affected product versions are widespread.
What happens next cannot be left to improvisation. The vulnerability must be validated. False positives must be removed. Affected versions must be identified. Vendors must develop patches or mitigations. Asset owners must know whether they are exposed. Critical infrastructure operators must receive enough information to act, but not so much that the vulnerability is handed to attackers. Smaller organizations may need direct technical assistance. Public disclosure must be timed. Exploitation must be monitored. Emergency mitigations may be needed before patches are available.
This is not a model capability problem. It is an institutional design problem. AI creates the possibility of discovering vulnerabilities faster than society can fix them. That means any serious defensive AI strategy must include a clearinghouse function: a trusted mechanism for moving from vulnerability discovery to validation, prioritization, remediation, and monitoring across sectors.
The clearinghouse cannot be merely a reporting inbox. It needs technical expertise, secure channels, sector-specific triage, vendor coordination, legal clarity, disclosure protocols, and support for resource-constrained infrastructure operators. It must understand that a vulnerability in a consumer application and a vulnerability in a rural hospital network are different kinds of events. It must also understand that a small municipal utility may not have the staff, budget, or test environment to respond like a major investor-owned utility or cloud provider.
This is where national cybersecurity and energy policy meet. A society that accelerates AI-enabled vulnerability discovery without building remediation capacity may increase awareness while leaving risk unresolved. That is not resilience. It is illuminated fragility.
Release Discipline for Frontier Cyber-Capable Models
The phrase “AI regulation” is too broad to be useful here. The better term is release discipline. Not every AI system requires the same controls. A small model summarizing public documents is not equivalent to a frontier model that can discover unknown vulnerabilities in widely used software. A model with no tools is not equivalent to an agent that can scan networks, write code, call APIs, execute commands, or interact with production systems. A research model available to a controlled group is not equivalent to a widely released system that can be copied, fine-tuned, wrapped, jailbroken, or stolen.
The right governance architecture should be capability-based. The highest scrutiny should apply to systems that can materially improve offensive cyber capability, especially against critical infrastructure, cloud platforms, identity systems, operational technology, widely used open-source packages, firmware, or software supply chains. Evaluation should ask practical questions. Can the model identify previously unknown vulnerabilities in real codebases? Can it reason from a bug to an exploit path? Can it chain multiple weaknesses? Can it generate reliable proof-of-concept exploit code? Can it automate reconnaissance? Can it improve phishing, malware development, privilege escalation, persistence, or lateral movement? Can it increase the capability of a low-skilled actor? Can it operate through tools without close human supervision?
If the answer is yes, then the release process should not look like an ordinary product launch. It should include structured red teaming, staged access, abuse monitoring, secure development practices, independent evaluation for high-consequence capabilities, vulnerability disclosure coordination, tool-use constraints, model security controls, and post-release monitoring. The strongest capabilities may need tiered access limited to trusted defenders, researchers, vendors, and infrastructure operators.
This does not mean freezing innovation. It means recognizing that some AI capabilities are dual-use in the classic sense. They can support legitimate defense, research, and software improvement. They can also cause harm if distributed carelessly. The governance challenge is not to suppress the capability, but to control the pathway by which it enters the world.
Energy Organizations Need an AI Cyber-Control Plane
Energy companies should not wait for perfect federal rules. The operational exposure is already arriving through vendors, employees, cloud platforms, analytics tools, grid modernization programs, and informal use of public AI systems. The first task is inventory. Every energy organization needs to know where AI is being used, what data it touches, what systems it connects to, what vendors are involved, whether outputs are used in decisions, and whether the AI system can take actions. Shadow AI is now a material enterprise risk.
The second task is consequence classification. AI tools should be tiered by operational consequence. Low-risk tools can move quickly. High-consequence tools need deeper review. Any AI system connected to grid operations, cyber defense, code repositories, identity systems, market participation, customer data, operational technology, engineering records, or emergency response should receive elevated scrutiny.
The third task is permission design. AI systems should have their own identities. They should not casually inherit broad human credentials. They should operate under least privilege. Their access should be scoped, logged, time-limited, and revocable. High-impact actions should require human approval. Read-only should be the default posture for operational environments unless there is a strong reason to move beyond it.
The fourth task is runtime containment. AI agents should operate in sandboxes. Tool access should be constrained. External content should be treated as untrusted. Outputs should be validated before execution. The system should separate instructions from data wherever possible, even though large language models do not naturally enforce that boundary. The architecture should assume prompt injection will occur and limit the blast radius.
The fifth task is data integrity. AI models are only as trustworthy as the data systems around them. Energy organizations need provenance, access control, anomaly detection, data quality checks, change logs, and clean recovery paths for training data, retrieval systems, telemetry, asset records, inspection data, and operational feeds.
The sixth task is vendor assurance. Vendors should disclose AI functionality, model dependencies, data retention practices, tool permissions, update processes, security testing, incident notification procedures, and subcontractor exposure. A vendor adding AI to a grid-relevant product is not merely adding a feature. It is changing the risk profile of the product.
The seventh task is incident response. Energy organizations need playbooks for AI-specific cyber events: prompt injection, model compromise, data leakage, poisoned retrieval systems, unsafe agent behavior, malicious code generation, vendor AI breach, model theft, and AI-enabled social engineering. Recovery plans should include disabling AI functions, revoking credentials, rolling back model updates, restoring clean data, and communicating with regulators and partners.
This is the energy-sector version of AI governance. It is not a board memo about ethics. It is an operating architecture.
Defensive AI May be the Only Way to Keep Pace
The answer to AI-enabled cyber risk cannot be less AI. Defenders will need AI to keep pace. AI can help identify vulnerabilities, review code, summarize threat intelligence, correlate logs, prioritize alerts, generate detection rules, assist incident response, inspect infrastructure-as-code templates, translate vendor advisories into asset-specific guidance, and help smaller organizations understand what matters. It can also help bridge the cultural gap between IT security teams and operational technology teams.
That bridge is essential in energy. Cyber teams may understand attack chains but not grid operations. Grid operators may understand physical consequences but not cloud identity, software supply chains, or AI-specific vulnerabilities. AI systems, if governed well, can help translate between those domains. They can map a software weakness to an operational consequence. They can identify which substations, control centers, DER platforms, market systems, or vendor dependencies are most exposed. They can support faster triage during the first hours of an incident, when confusion is high and time is scarce.
The goal is not to remove humans from the loop. It is to give humans a better loop. In the AI-native grid, the best systems will combine machine-speed analysis with human accountability. AI should shorten the distance from signal to understanding. It should not collapse the distance from recommendation to action without governance.
The New Doctrine: Govern Agency
The central doctrine for critical infrastructure AI should be simple: govern agency, not just intelligence. Model capability matters. But the greater operational risk often comes from the interaction between model capability, data access, tool access, permissions, institutional dependence, and human overtrust. A high-capability model in a sealed research environment may pose less immediate infrastructure risk than a less capable agent with access to production systems, credentials, workflows, and operational data.
This doctrine has several implications. AI assurance must move beyond benchmark performance and include authority mapping. What can the system read? What can it write? What can it execute? What can it trigger? What can it expose? What can it change? Those questions matter as much as accuracy scores, latency, or user experience.
AI governance must also be continuous. A model update, new plugin, new retrieval source, new workflow integration, or new vendor feature can change the risk profile without changing the product name. AI security must include the supply chain: models, datasets, prompts, embeddings, APIs, tools, agents, cloud infrastructure, hardware, firmware, and vendors all form part of the system.
AI risk must also be measured by consequence. A hallucinated travel recommendation is not the same as a hallucinated grid operating recommendation. A data leak from a public marketing tool is not the same as a data leak from an operational technology environment. A prompt injection in a public chatbot is not the same as a prompt injection in an AI assistant connected to engineering records, incident tickets, or control-room workflows.
The final requirement is reversibility. AI deployment in infrastructure must preserve the ability to degrade gracefully. Operators should be able to disable AI functions, fall back to conventional tools, revoke credentials, restore clean data, and maintain operations under degraded conditions. The test of AI governance is not whether the system works when everything is normal. It is whether the organization can control it when something goes wrong.
From Electricity Demand to Intelligent Infrastructure
The AI-energy debate began with megawatts. It will not end there. Load growth is real. Data centers are reshaping utility planning. Power availability is becoming a strategic constraint on AI deployment. But the deeper transition is that AI is entering the operating fabric of infrastructure itself. It is becoming part of how systems forecast, optimize, defend, repair, trade, and coordinate.
That means the electric grid is no longer only supplying AI. It is being changed by AI. In the old grid, hidden defects were physical: a failing transformer, a cracked insulator, an overloaded line, a mis-set relay, a corroded connector, or a tree too close to a conductor. In the AI-native grid, the hidden defect may be a poisoned dataset, a vulnerable software library, an over-permissioned agent, a compromised model, a manipulated forecast, a prompt injection buried in a maintenance document, or a vendor feature that quietly creates a new pathway into operational systems.
The physics of the grid still matter. Frequency, voltage, inertia, reactive power, protection, thermal limits, and stability remain fundamental. But the digital layer around those physics is thickening. The security of that layer now shapes the reliability of the physical system.
This is the new infrastructure condition. AI makes software more powerful, and it makes software failure more consequential. It can help defenders repair the digital foundation of modern life. It can also help adversaries find the cracks faster. The outcome will depend less on slogans about innovation or regulation than on whether institutions can build disciplined pathways for release, access, testing, remediation, and operational control.
The frontier is not artificial intelligence alone. It is intelligent infrastructure. The first rule of intelligent infrastructure is that cognition must be governed before it is connected to consequence.
Notes
- Courtney Rozen, Ismail Shakil, and Bhargav Acharya, “Trump Administration to Ask US AI Firms to Voluntarily Submit Models for Cybersecurity Tests,” Reuters, June 2, 2026.
- Matt O’Brien, “Trump Signs an Executive Order That Invites Vetting of Top AI Models for National Security Risks,” Associated Press, June 2, 2026.
- Sanya Mansoor, “Trump Signs Executive Order Seeking Early Access to New AI Releases,” The Guardian, June 2, 2026.
- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (Gaithersburg, MD: National Institute of Standards and Technology, January 2023), https://doi.org/10.6028/NIST.AI.100-1.
- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1 (Gaithersburg, MD: National Institute of Standards and Technology, July 2024), https://doi.org/10.6028/NIST.AI.600-1.
- National Institute of Standards and Technology, “Concept Note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure,” April 7, 2026.
- OWASP Foundation, OWASP Top 10 for Large Language Model Applications, Version 2025, OWASP GenAI Security Project, 2025.
- MITRE, MITRE ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems, accessed June 4, 2026.
- National Institute of Standards and Technology, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 (Gaithersburg, MD: National Institute of Standards and Technology, February 26, 2024), https://doi.org/10.6028/NIST.CSWP.29.
- Miles Brundage et al., “Frontier AI Auditing: Toward Rigorous Third-Party Assessment of Safety and Security Practices at Leading AI Companies,” arXiv, January 16, 2026, revised February 7, 2026, https://doi.org/10.48550/arXiv.2601.11699.
Bibliography
Associated Press. “Trump Signs an Executive Order That Invites Vetting of Top AI Models for National Security Risks.” By Matt O’Brien. June 2, 2026.
Brundage, Miles, Noemi Dreksler, Aidan Homewood, Sean McGregor, Patricia Paskov, Conrad Stosz, Girish Sastry, et al. “Frontier AI Auditing: Toward Rigorous Third-Party Assessment of Safety and Security Practices at Leading AI Companies.” arXiv. January 16, 2026. Revised February 7, 2026. https://doi.org/10.48550/arXiv.2601.11699.
Mansoor, Sanya. “Trump Signs Executive Order Seeking Early Access to New AI Releases.” The Guardian. June 2, 2026.
MITRE. MITRE ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems. Accessed June 4, 2026.
National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1. Gaithersburg, MD: National Institute of Standards and Technology, January 2023. https://doi.org/10.6028/NIST.AI.100-1.
National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. NIST AI 600-1. Gaithersburg, MD: National Institute of Standards and Technology, July 2024. https://doi.org/10.6028/NIST.AI.600-1.
National Institute of Standards and Technology. “Concept Note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure.” April 7, 2026.
National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. Gaithersburg, MD: National Institute of Standards and Technology, February 26, 2024. https://doi.org/10.6028/NIST.CSWP.29.
OWASP Foundation. OWASP Top 10 for Large Language Model Applications. Version 2025. OWASP GenAI Security Project, 2025.
Rozen, Courtney, Ismail Shakil, and Bhargav Acharya. “Trump Administration to Ask US AI Firms to Voluntarily Submit Models for Cybersecurity Tests.” Reuters. June 2, 2026.