Skip to content

Add Tool: AI PBOM - AI Privacy Posture & Data Map - #62

Open
k-nithin wants to merge 1 commit into
usnistgov:masterfrom
k-nithin:add-ai-pbom-tool
Open

Add Tool: AI PBOM - AI Privacy Posture & Data Map#62
k-nithin wants to merge 1 commit into
usnistgov:masterfrom
k-nithin:add-ai-pbom-tool

Conversation

@k-nithin

@k-nithin k-nithin commented Aug 8, 2026

Copy link
Copy Markdown
  • Add AI PBOM tool documentation to README and create project configuration files

Adds a tool entry for AI PBOM under tools/risk-assessment/, per the contribution template.

What it does

AI PBOM inventories AI-related data assets (tables, vector stores, prompt logs, training data, transcripts, files), detects PII/credentials/sensitive content, maps assets to the AI applications that consume them, and produces an explainable, additive risk score (0-100) with traceable drivers — output as a JSON PBOM plus a Markdown report.

Why it fits Privacy Risk Assessment

  • Purpose-built for AI-specific asset types (vector stores, prompt logs, training data) that general data-discovery tools don't model.
  • Risk scores are explainable/additive, not a black-box number
    — every score traces back to specific findings, which supports privacy office and governance review workflows. - Grounded in a published threat model (T1–T4) and gap analysis
    — see the linked SSRN paper.

- Add AI PBOM tool documentation to README and create project configuration files
@k-nithin
k-nithin marked this pull request as ready for review August 8, 2026 18:35
@k-nithin k-nithin changed the title Add AI PBOM - AI Privacy Posture & Data Map Add Tool: AI PBOM - AI Privacy Posture & Data Map Aug 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant