The Department of Homeland Security (DHS) has issued ‘Mitigating Artificial Intelligence (AI) Risk: Safety and Security Guidelines for Critical Infrastructure Owners and Operators’.
The new guidance, developed in coordination with the Cybersecurity and Infrastructure Security Agency (CISA), is organized around three overarching categories of system-level risk:
- Attacks Using AI: the use of AI to enhance, plan, or scale physical attacks on, or cyber compromises of, critical infrastructure.
- Attacks Targeting AI Systems: targeted attacks on AI systems supporting critical infrastructure.
- Failures in AI Design and Implementation: deficiencies or inadequacies in the planning, structure, implementation, or execution of an AI tool or system leading to malfunctions or other unintended consequences that affect critical infrastructure operations.
To address these risks, DHS outlines a four-part mitigation strategy, building upon the National Institute of Standards and Technology’s (NIST) AI Risk Management Framework (RMF), that critical infrastructure owners and users can consider when approaching contextual and unique AI risk situations:
Govern: establish an organizational culture of AI risk management
Prioritize and take ownership of safety and security outcomes, embrace radical transparency, and build organizational structures that make security a top business priority.
Map: understand your individual AI use context and risk profile
Establish and understand the foundational context from which AI risks can be evaluated and mitigated.
Measure: develop systems to assess, analyze, and track AI risks
Identify repeatable methods and metrics for measuring and monitoring AI risks and impacts.
Manage: prioritize and act upon AI risks to safety and security
Implement and maintain identified risk management controls to maximize the benefits of AI systems while decreasing the likelihood of harmful safety and security impacts.






