SHADOWAI-RISK Enterprise AI Governance & Risk Intelligence
Academic Research Prototype

Project Prototype: Next-Gen Autonomous AI Threat Mitigation Dashboard

Lead Researcher: Audrey Rah | ECE, University of Houston

Live NVD/NIST Evidence Updated: Data Unavailable
GETTING STARTED
Settings / Setup Profile

Organization Profile Not Saved

Short setup reminder: save your organization profile, AI inventory, and current security controls before refreshing intelligence.

No saved settings
Executive summary

Assessment Snapshot

High-level status for the current organization profile and latest refresh. Detailed findings, validation, and reports stay in their dedicated workspaces.

Organization
Not saved
Open Edit Settings to save the profile.
Selected AI technologies
0
No inventory selected.
Live CVE findings
0
Refresh Intelligence to load NVD evidence.
Highest severity
Not determined
Critical / High counts appear after refresh.
Evidence coverage
n/a
Share of selected technologies with verified intelligence. Not accuracy.
Validation progress
0 / 0
Human review is optional and lives in Validation & Metrics.
Setup required. Save your profile and refresh intelligence to retrieve live NVD/NIST records.
Executive report

Generate Executive Risk Report

Executive assessment is unavailable until Refresh Intelligence completes.

Authoritative source coverage

Selected-Inventory Intelligence Sources

Source types that cannot be retrieved or verified in this standalone file remain Data Unavailable.

Organization-specific footprint

Selected AI Footprint Intelligence Status

Every selected technology remains visible after refresh. Verified records are linked to NVD/NIST; unavailable source findings are not replaced with generic AI threats.

No AI technologies selected yet. Use Setup Profile, then refresh intelligence.
Simple next steps

What Should We Do Next?

Simple actions based on the evidence shown above.

Select AI tools to see simple next steps.
Live situation awareness

Risk Signal Summary

These numbers are calculated only from the current live security database response. Missing values are not replaced.

Live review priority

Start Here: Which Known Security Issue Needs Review?

This section uses only live security evidence for the selected AI technologies and highlights items that may need review first.

0

Critical Security Problems Reported

Source: NVD severity score. Critical means the highest reported risk level.

No Issues

Highest Risk Level Found

Source: NVD severity score.

Not refreshed

Latest modified date

Source: NVD cve.lastModified.

Decision Pathway

Known Security Issue -> Affected Evidence -> Risk Level -> What To Do

The pathway follows only live database fields or shows Data Unavailable.

Known Security Issue

Issue ID, description, published date, and modified date.

Affected Evidence

Affected product or setup evidence when available.

Risk Level

Reported seriousness score and level when available.

What To Do

Review the item, check whether it affects your company, and apply vendor fixes when available.

Live operational evidence table

Known Security Issues Mapped to Executive Decisions

Filter by risk level. Table records appear only when returned by the live security database.

No known security issues loaded yet. Save settings and refresh intelligence to start the review workflow.
CVE Validation / Human Review

Optional human review for each CVE-to-technology match. System classification is generated automatically from NVD evidence. Human validation is stored separately and does not replace the system classification.

Reviewed 0 / 0
Refresh intelligence to review CVE-to-technology matches.
Assessment Performance & Validation

Automatic evaluation metrics for each completed intelligence refresh. Evidence Coverage and retrieval counts are measured directly from NVD results. Validated Precision requires human review. Recall and F1 require an independent ground-truth dataset. These metrics are not interchangeable and retrieval success is never reported as accuracy.

Complete Refresh Intelligence to generate an assessment evaluation matrix.
Refresh intelligence to generate assessment metrics for the selected AI inventory.
AI Governance Assessment

NIST AI RMF Practice Assessment

Organizational AI governance practices against NIST AI RMF 1.0 functions GOVERN, MAP, MEASURE, and MANAGE. This is not live NVD cybersecurity intelligence.

Security Intelligence = live NVD vulnerability evidence.  AI Governance Assessment = organizational governance practices evaluated against NIST AI RMF. Governance gaps are not CVEs and are not vulnerabilities.

How to complete this assessment Review each governance practice and select the option that best describes your organization's current situation. Answer based on what your organization actually has in place today. If you are unsure, do not assume the practice is implemented.
  • Implemented — This practice is established and currently used.
  • Partially Implemented — Some parts exist, but the practice is incomplete.
  • Not Implemented — This practice is not currently in place.
  • Not Applicable — This practice does not apply to this organization's AI environment.
Governance Assessment: Not Completed. Select a status for every practice, then save.