Quantifying Security Vulnerabilities: A Metric-Driven Security Analysis of Gaps in Current AI Standards
AI governance frameworks are proliferating, but their actual security coverage is rarely audited quantitatively. This paper audits and quantifies security risk gaps in three major AI governance standards — NIST AI RMF 1.0, the UK ICO’s AI and Data Protection Risk Toolkit, and the EU’s ALTAI — developing four metrics for the analysis: a Risk Severity Index, an Attack Vector Potential Index, a Compliance-Security Gap Percentage, and a Root Cause Vulnerability Score. Across 136 identified concerns, NIST fails to address 69.23% of identified risks, ALTAI shows the highest attack-vector vulnerability (AVPI = 0.51), and the ICO Toolkit shows the largest compliance-security gap, with 80% of its high-risk concerns left unresolved. Root-cause analysis points to under-defined processes and weak implementation guidance as the primary drivers of these gaps, and the paper concludes that current AI standards need stronger, enforceable security controls.
