Research
32-Stage LLM Security Lifecycle Model Shows Regulatory Evidence Concentrates Where Systems Are Visible, Not Where Decisions Are Made
The model restructures the LLM lifecycle around security-relevant boundaries rather than workflow efficiency: 32 stages across Data, Model, Distribution, and Application layers, plus a 12-stage LLMOps pillar and a 9-category governance pillar, with 13 stages newly separated because they expose distinct security concerns. Mapping it against NIST AI RMF, the EU AI Act, and ISO/IEC 42001 surfaces a structural gap — governance evidence clusters at deployment-facing stages visible to regulators, while data selection, alignment strategy, and capability boundaries are decided at development-facing stages with the lowest regulatory visibility.
↳ Follow the thread