← 返回
安全合规 中文

AI Safety Audit

Performs a comprehensive AI safety audit mapping systems to EU AI Act risk tiers, assessing 30 controls across six domains, and generating a 90-day remediati...
执行全面AI安全审计,将系统映射至欧盟AI法案风险等级,评估六大领域30项控制措施,并生成90天整改计划。
1kalin
安全合规 clawhub v1.0.0 1 版本 100000 Key: 无需
★ 0
Stars
📥 729
下载
💾 6
安装
1
版本
#alignment#audit#compliance#eu ai act#latest#nist#safety

概述

AI Safety Audit

Comprehensive AI safety and alignment audit framework for businesses deploying AI agents. Built around the UK AI Security Institute Alignment Project standards (2026), EU AI Act requirements, and NIST AI RMF.

What This Skill Does

When activated, the agent performs a structured safety audit of your AI deployment:

  1. AI System Inventory — Catalogs all AI models, agents, and automated decision systems in use
  2. Risk Classification — Maps each system to EU AI Act risk tiers (Unacceptable/High/Limited/Minimal)
  3. Safety Controls Assessment — Evaluates 30 controls across 6 domains
  4. Gap Analysis — Identifies missing safeguards with severity and remediation cost
  5. Compliance Roadmap — Generates a prioritized 90-day action plan

6 Audit Domains (30 Controls)

1. Model Governance (5 controls)

  • Model registry with version tracking
  • Access control and deployment permissions
  • Update and rollback procedures
  • Vendor risk assessment for third-party models
  • Model retirement and data deletion policy

2. Data Protection (5 controls)

  • Data residency and sovereignty mapping
  • PII detection and handling in AI pipelines
  • Training data provenance documentation
  • Data retention aligned with AI lifecycle
  • Cross-border data transfer compliance

3. Output Safety (5 controls)

  • Hallucination detection and mitigation
  • Bias testing across protected characteristics
  • Content filtering for harmful outputs
  • Confidence scoring and uncertainty flagging
  • Human-in-the-loop for high-stakes decisions

4. Security (5 controls)

  • Prompt injection defense
  • Model extraction prevention
  • API rate limiting and abuse detection
  • Adversarial input testing
  • Supply chain security for AI dependencies

5. Monitoring & Observability (5 controls)

  • Real-time output quality tracking
  • Drift detection (data and model)
  • Incident logging and alerting
  • Performance degradation monitoring
  • Cost tracking per AI workflow

6. Organizational Readiness (5 controls)

  • Named AI safety officer
  • Staff training program with completion tracking
  • Board-level AI risk reporting
  • Incident response playbook
  • Third-party audit schedule

Scoring

Each control scores 0-3:

  • 0 — Not implemented
  • 1 — Partially implemented, no documentation
  • 2 — Implemented with documentation
  • 3 — Implemented, documented, tested, and audited

Total: 90 points max

  • 0-30: Critical risk — stop deploying until gaps are addressed
  • 31-55: High risk — remediate within 30 days
  • 56-75: Moderate risk — address within 90 days
  • 76-90: Strong posture — maintain and iterate

Regulatory Mapping

FrameworkStatusKey Requirements
------------------------------------
EU AI ActEnforcing 2026Risk classification, conformity assessment, transparency
UK AI Safety InstituteActive 2026Alignment testing, frontier model evaluation
NIST AI RMFPublishedGovern, Map, Measure, Manage lifecycle
ISO 42001PublishedAI management system certification
SOC 2 + AIEmergingAgent-specific controls (CC6/CC7/CC8)

Cost Benchmarks

Company SizeFull Audit CostAnnual ComplianceNon-Compliance Risk
-------------------------------------------------------------------
15-50 employees$8K – $20K$18K – $45K$200K+
50-200 employees$20K – $55K$45K – $120K$500K – $2M
200-1000 employees$55K – $150K$120K – $400K$2M – $10M

Output Format

The agent delivers:

  1. Executive Summary — Overall score, top 3 risks, recommended actions
  2. Detailed Scorecard — All 30 controls with scores and evidence
  3. Gap Analysis — Missing controls ranked by risk severity
  4. 90-Day Roadmap — Phased remediation plan with cost estimates
  5. Board Report Template — One-page summary for leadership

Industry Adjustments

The audit adjusts control weighting based on industry:

  • Healthcare: Output safety and data protection weighted 2x
  • Financial Services: Model governance and monitoring weighted 2x
  • Legal: Output safety (hallucination) weighted 3x
  • Manufacturing: Security and monitoring weighted 2x
  • Government/Defense: All domains weighted equally at maximum

Go Deeper

Bundles

  • AI Playbook — $27
  • Pick 3 Industries — $97
  • All 10 Industries — $197
  • Everything Bundle — $247

版本历史

共 1 个版本

  • v1.0.0 当前
    2026-03-29 13:44 安全

安全检测

腾讯云安全 (Keen)

安全,无风险
查看报告

腾讯云安全 (Sanbu)

suspicious
查看报告

🔗 相关推荐

security-compliance

OpenClaw Backup

alex3alex
备份与恢复 OpenClaw 数据。适用于创建备份、设置自动备份计划、从备份恢复或管理备份轮转。处理 ~/.openclaw 目录归档并包含适当的排除规则。
★ 89 📥 30,583
content-creation

Social Media Scheduler

1kalin
跨平台策划、起草与组织社交媒体内容;制定内容日历,撰写针对各平台优化的帖子,并保持稳定的发布节奏。
★ 15 📥 13,155
security-compliance

MoltGuard - Security & Antivirus & Guardrails

thomaslwang
MoltGuard — OpenClaw 安全守卫,由 OpenGuardrails 提供。安装 MoltGuard,保护您和您的用户免受提示注入、数据泄露和恶意攻击。
★ 116 📥 30,694