Case Study: Add GenAI Risks and Controls to the Worksheet
Explore how to add GenAI-specific risks and controls to an AI RMF worksheet for a secure pilot environment. Understand the importance of clearly defining trust boundaries, retrieval limitations, and escalation triggers to ensure auditable and enforceable AI controls. Learn to document provenance, residual risks, and authorization requirements to maintain safe use of generative AI in Department of Defense workflows.
We'll cover the following...
The control stack is only defensible if it shows its limits in writing, because a reviewer cannot enforce what was never recorded. In the Secure GenAI Decision Packet case, the team is about to add retrieval to the pilot, but CP-05 AI RMF Worksheet does not yet contain a GenAI-specific entry that ties the new capability to concrete boundaries. The mistake here is subtle and common, because the team feels like it already did the hard part by choosing controls, when the hard part is making those controls auditable and stoppable.
The current conditional-go pilot stance is still the same one carried forward from the earlier packet, meaning non-NSS use only and public or synthetic inputs only, while the NSS boundary question stays open with Security/CIO and ISSM/ISSO. The team wants retrieval over curated public advisories now, and it wants the option to retrieve internal incident reports later if the environment becomes authorized. That plan can be safe enough to pilot, but only if the worksheet states what changes when retrieval is turned on and who stops it when evidence is missing.
Where the worksheet needs a GenAI entry
The update, CP-06, belongs inside the existing worksheet as an added entry, not in a new standalone note, because reviewers already use secure_genai_decision_packet/ai_rmf_worksheet.md as ...