Issue BriefHarmonizingAl GuidanceDistiling Voluntary Standardsand Best Practices into aUnified FrameworkAuthorsKyleCrichtonAbhiramReddyJessicaJiAli CrawfordMia HoffmannColin Shea-BlymyerJohn BansemerCSETSeptember2025CENTERforSECURITYand
FxecutiveSummaryOraanizations lookina to develop or deplov artificial intelligence (Al) systemsfacemany barriers in trying to operationalize Al-related best practices. In addition to themany practical hurdles to implementation, such as a lack of resources or in-houseexpertise, the complex landscape ofexisting Al guidance itselfpresents a substantialchallenae.Oraanizations face an overload of information. comina from amvriad of disparate sources, that is often written in language that can be inaccessible to manyorganizations. This places an enormous burden on practitioners to sort through anedecipher this guidance on their own-requiring time, resources, and expertise thatmany organizations, particularly smaller ones. cannot afford.Toaddress these challenges. the researchers at CSET have attempted to do thisintensive workfororaanizations In thic ranort wesent a harmonized framework forhow an organization should govern, manage, and protect its technology-and how tointegrate emerging technologies such as artficial intelligence into its existing practicesThis workdistilsmorethan2.000immandations collected from52 differentguidance document,into a condensed set of 258recommendations.These recommendations are rouped into 5 overarching cateconies and 34 toic areasenabling organizations to auicklvidentifvth,set of disciplines. The breadth of content covered in this framework exceeds that of any existing indvidual guidance document To match this scope organizations woulotherwiseneedmore than 900 recommendations fromsevenormoredifferentfor harmonization and methods to validate the results that can be reused for otherAlongside each recommendation, we indicate the dearee towhich the contentisdeveloped from Al-specific guidance. This information, derived from the harmonizationprocess, helps to illustrate how new Al guidance overlays with existing cybersecurityprivacy, and risk man agement practices. We condude our analy sis by identifyingwhere current Al reports have been focused and highlighting gaps in existingknowledge, work that forthcoming CSET research aims to address.CenterforSecurity and Emerging Technology|1
Table of ContentsFxecutiveSummary.7Intautio...........................................Rackaround.AADividedandShitingLa.....Challenaes inOnerationalizinaAlGuidance7Meto...............................12HarmonizinaRecommendatio.膈...13Limitations......15HarmonizationRes.....eClustering.....FrameworkValidation..12CSET'sHarmonizedAlFramework2Governance........Strateay&Leade...膈.....................................RiskManage...............................ITManagement..................................SupplyCa.........................................Workforce&Trin................................Inventory.....Audit&om................Safety....ResponsibleBusinessCn.............