Skip to content
Open access

Trustworthy AI: Operationalizing Responsibility in Lifecycle-Aware AI Threat Modeling through RACI

2026 · International Conference on Software and Data Technologies · pp. 315-326 · 0 citations · 41 references
Computer Science

Abstract

: Artificial Intelligence (AI) is a key driver of digital transformation across sectors. However, its rapid adoption introduces significant challenges in governance, security, and accountability. Modern AI systems, particularly generative and adaptive models, exhibit non-deterministic behavior, evolving data dependencies, and distributed ownership. These characteristics limit the effectiveness of traditional threat modeling approaches. At the same time, existing governance frameworks treat accountability primarily as a managerial concern and do not integrate it into technical threat modeling processes. This disconnect leads to fragmented oversight, unclear role ownership, and increased security and compliance risks across the AI lifecycle. To address this gap, this paper proposes a lifecycle-aware threat modeling framework for Secure and Trustworthy AI that embeds RACI (Responsible, Accountable, Consulted, Informed) roles into each stage of the threat modeling process. By linking technical threat analysis with explicit accountability, the framework transforms governance into an operational security mechanism. It enables systematic identification of AI-specific risks while ensuring trace-able decision-making and clear risk ownership. The framework further extends to distributed AI ecosystems (RACI+X) by incorporating external actors into the accountability structure. Overall, the approach strengthens resilience against evolving risks and supports secure, transparent, and accountable AI deployment.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.