The Rise of AI TRiSM and How it Works

Picture of Fallon Equis

Fallon Equis

AI’s rapid adoption has brought new forms of risk that legacy controls were never built to address. While traditional systems are effective at handling structured data risks (Habbal, 2024), many organizations now deploy models, copilots, and agents that process unstructured information, PDFs, Word documents, media files, emails, and other formats that make up most enterprise data. These deployments often occur without proper oversight, meaning organizations lack visibility into where AI is operating, how it behaves, and which data sources it depends on. As a result, they cannot reliably inventory their AI systems or trace their data flows (Palo Alto Networks, 2026).

According to Gartner, “Through 2026, at least 80% of unauthorized AI transactions will be caused by internal violations of enterprise policies concerning information oversharing, unacceptable use or misguided AI behavior rather than malicious attacks.”

In essence, AI TRiSM was developed because organizations require a single, cohesive framework capable of identifying their AI systems, assessing the risks they pose, and managing their behavior as they operate in real time.

Currently AI TRiSM encompasses a blooming market which is expected to reach 10.3 billion dollars by 2034 (SNS Insider, 2025)

How does AI TRiSM work?

According to the framework, AI TRiSM brings together four interconnected layers:

  • At the top, AI governance creates a complete inventory of all models, apps, and agents, documents how they work, assigns risk levels, and maintains model cards and AI bills of materials, all tied into approval workflows and continuous assurance, so oversight stays current after deployment.
  • AI runtime inspection and enforcement is the real‑time control layer, where every AI interaction is evaluated through policy engines that score risks such as data exposure or misuse, combine those scores into a single risk rating, and decide whether to allow, block, or escalate outputs, supported by anomaly detection and system‑specific safeguards.
  • Beneath that, information governance defines which data AI systems can access by classifying sensitive content, enforcing entitlements, and using DSPM, DLP, and IAM tools to prevent oversharing, since runtime controls can only enforce what the data layer makes explicit.
  • At the foundation, infrastructure and stack provide the secure technical environment, trusted execution, isolation, API gateways, audit logs, telemetry, and CI/CD integration, ensuring AI workloads run in protected, observable, policy‑aligned environments that support all higher TRiSM controls (Habbal, 2024).

How is AI TRiSM implemented?

  • Ideally, AI TRiSM should be implemented gradually, beginning with a strong data foundation before expanding into more advanced controls. Organizations should start by tightening information governance, improving data classification, cleaning up access, and reducing oversharing, because runtime controls can’t function if permissions are flawed.
  • Next, they inventory all existing AI models, apps, and agents, document their behavior, and assign baseline risk scores, which feed into an AI catalog that defines ownership, data dependencies, and what “normal” looks like.
  • With this context in place, teams introduce runtime inspection for the highest‑risk systems, especially those handling sensitive data or external AI services, allowing blended risk scoring and targeted enforcement without slowing operations.
  • Finally, clear responsibility pathways are established across security, governance, compliance, legal, engineering, and business teams so escalations flow smoothly. In short: strengthen the data layer, catalog AI assets, apply runtime controls where risk is highest, and align teams early to scale TRiSM safely and sustainably (Palo Alto Networks, 2026).

    

An Example of an AI TRiSM system in action:

An employee asks an enterprise AI assistant to summarize a sensitive M&A document, triggering the full end‑to‑end control flow. The system first performs discovery, identifying the assistant, its model, its risk level, and approved use cases. It then applies information governance, checking whether the employee is authorized to access the document and whether the file is stored and classified correctly, blocking the request immediately if access rules are violated. If the data checks pass, runtime inspection evaluates the request, the document context, and the model’s output through multiple policy engines that score risks such as data leakage, hallucinations, or policy violations. These scores are combined into a single risk rating that determines whether the output is blocked, quarantined for review, or safely returned to the user. Finally, the system logs the entire interaction for continuous assurance, giving governance teams real-world evidence to refine policies and controls (Palo Alto Networks, 2026).

AI TRISM POTENTIAL

Related videos

Habbal, A., Ali, M. K., & Abuzaraida, M. A. (2024). Artificial Intelligence Trust, Risk and Security Management (AI TRiSM): Frameworks, applications, challenges and future research directions. Expert Systems with Applications, 240, 122442. https://doi.org/10.1016/j.eswa.2023.122442

Palo Alto Networks. (n.d.). A guide to AI TRiSM: Trust, risk, and security management. https://www.paloaltonetworks.com/cyberpedia/ai-trism Accessed 2026.

SNS Insider. (2025, May). AI trust, risk and security management (AI TRiSM) market: Size, share & segmentation, global forecast 2024–2031 (Report Code: SNS/ICT/4175). https://www.snsinsider.com/reports/ai-trust-risk-and-security-management-market-4175 Accessed 2026.

Keep reading

Related Articles

Author's Disclaimer

The views shared in this blog are solely my own and do not represent or intend to influence Profonanpe’s image or reputation. The perspectives discussed form part of an academic technology research assessment in which I am required, as a student, to adopt the role of a professional consultant for the organisation where I am currently completing my internship.