<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Llm-Security on CuraSec</title><link>https://curasec.metacog.co.kr/tags/llm-security/</link><description>Recent content in Llm-Security on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 01 Sep 2026 15:28:52 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/llm-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Malicious Free LLM Endpoints Silently Harvesting Coding-Agent Context</title><link>https://curasec.metacog.co.kr/insights/2026-09-01-the-coding-agent-trap-when-a-free-llm-endpoint-is-the-advers/</link><pubDate>Tue, 01 Sep 2026 15:28:52 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-01-the-coding-agent-trap-when-a-free-llm-endpoint-is-the-advers/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Honeypot research shows that untrusted &amp;lsquo;free&amp;rsquo; LLM backends receive full coding-agent context — filesystem paths, conversation history, tool manifests — before any response is sent. Audit every LLM endpoint configured in your coding agents and ensure all traffic goes to verified, first-party providers.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Demonstrates a passive exfiltration path: coding agents silently send working paths and tool manifests to whatever endpoint they&amp;rsquo;re pointed at. No IOCs or active campaign here, but useful context for future detections around unexpected outbound HTTPS from dev tools to novel LLM API hosts.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Employees using unofficial &amp;lsquo;free&amp;rsquo; AI coding tools may be routing sensitive codebase context and filesystem details to unverified third parties; establish or enforce an approved-LLM-provider policy for coding agents this quarter before an incident forces a reactive response.&lt;/li>
&lt;/ul></description></item><item><title>DP Bounds on LLM Memorization vs. Extraction Are Not Interchangeable</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-memorization-is-not-extraction-tight-differential-privacy-bo/</link><pubDate>Mon, 31 Aug 2026 19:07:02 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-memorization-is-not-extraction-tight-differential-privacy-bo/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> If you rely on DP guarantees to protect training data in ML pipelines, this research shows that controlling memorization and controlling extraction are formally separate — a model can be memorized yet unextractable, or vice versa. Revisit your threat model assumptions, but no system change is required today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>FISGuard: Defense Against Membership Inference in Federated LLMs</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-fisguard-defending-against-membership-inference-via-fixed-in/</link><pubDate>Mon, 31 Aug 2026 19:07:02 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-fisguard-defending-against-membership-inference-via-fixed-in/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel defense technique for federated fine-tuning pipelines; relevant if you run distributed LLM training with sensitive data, but no patch or configuration action needed today — research-stage only.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Mechanistic Interpretability Study Maps LLM Jailbreak Circuits</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-circuit-discovery-helps-detect-llm-jailbreaking-a-mechanisti/</link><pubDate>Mon, 31 Aug 2026 19:07:02 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-circuit-discovery-helps-detect-llm-jailbreaking-a-mechanisti/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research identifies internal attention heads and MLP pathways responsible for safety bypass in LLaMA-2-7B — useful context when evaluating LLM safeguard architectures, but no operational change needed today and findings are on one specific model.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Findings suggest current LLM safety alignment has exploitable structural weaknesses; relevant context when assessing risk posture of internally deployed LLM products, but no immediate action required.&lt;/li>
&lt;/ul></description></item><item><title>Meta-Adaptive Jailbreaking Achieves 80%+ ASR Against Frontier VLMs</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-fully-unleashing-the-multimodal-attacker-meta-adaptive-jailb/</link><pubDate>Mon, 31 Aug 2026 19:07:02 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-fully-unleashing-the-multimodal-attacker-meta-adaptive-jailb/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> If your product integrates GPT-4o, Gemini, or similar multimodal models, this research shows existing content-safety wrappers are brittle against adaptive attackers; no patch exists yet, but it motivates evaluating your VLM endpoints against adaptive prompt-injection test suites.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Research demonstrating high-success jailbreaks against GPT-4o and Gemini is useful framing for board-level AI risk discussions and for questioning AI vendor safety assurance claims when procuring or expanding VLM-based tooling.&lt;/li>
&lt;/ul></description></item><item><title>zk-SNARK Adversarial Probes Detect Post-Deployment LLM Tampering</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-not-to-break-but-to-attest-adversarial-probes-for-privacy-pr/</link><pubDate>Mon, 31 Aug 2026 19:07:02 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-not-to-break-but-to-attest-adversarial-probes-for-privacy-pr/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Academic framework for detecting model drift after deployment using privacy-preserving proofs; no running systems to patch today, but the black-box token-probe approach is worth tracking as LLM supply-chain integrity tooling matures.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Offers a governance-relevant framing: proprietary LLMs can be silently altered post-approval, and cryptographic audit frameworks are emerging to address that gap — useful context for AI risk discussions with the board or auditors.&lt;/li>
&lt;/ul></description></item><item><title>Research: LLM Safety Refusals Are Fragile and Easily Bypassed</title><link>https://curasec.metacog.co.kr/insights/2026-08-29-perturbation-probing-a-new-diagnostic-for-the-fragility-of-l/</link><pubDate>Sat, 29 Aug 2026 15:36:18 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-29-perturbation-probing-a-new-diagnostic-for-the-fragility-of-l/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Reinforces the design principle that LLM safety filters alone are insufficient; architecture decisions should place external guardrails (input/output validation, prompt firewalls) outside the model layer rather than trusting built-in refusals.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Supports the case for defense-in-depth policy around AI deployments: if safety refusals are fragile by design, any AI system handling sensitive data needs external controls beyond the model&amp;rsquo;s built-in guardrails — useful framing for board or audit conversations about AI risk.&lt;/li>
&lt;/ul></description></item><item><title>aiXamine: Cross-dimensional LLM safety/security/privacy evaluation study</title><link>https://curasec.metacog.co.kr/insights/2026-08-24-aixamine-unified-black-box-evaluation-of-cross-dimensional-t/</link><pubDate>Mon, 24 Aug 2026 13:10:29 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-24-aixamine-unified-black-box-evaluation-of-cross-dimensional-t/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The findings — that safety alignment increases over-refusal (safety tax), privacy is near-orthogonal to other trustworthiness dimensions, and distillation degrades robustness — are useful mental models for engineers selecting or evaluating LLMs in their stack, though no immediate system changes are required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The finding that strong alignment does not protect privacy, and that distilled models suffer robustness collapse, provides empirical grounding for AI governance decisions and risk conversations with leadership about LLM adoption — useful for future board decks but no same-week action needed.&lt;/li>
&lt;/ul></description></item><item><title>CyberLLM: Multi-Agent LLM Framework for Automotive SDV Security</title><link>https://curasec.metacog.co.kr/insights/2026-08-10-cyberllm-a-multi-agent-llm-framework-for-autonomous-detectio/</link><pubDate>Mon, 10 Aug 2026 13:39:41 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-10-cyberllm-a-multi-agent-llm-framework-for-autonomous-detectio/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The hybrid deterministic-plus-LLM pipeline (regex/AST/topology plus LLM refinement) that roughly doubles vulnerability coverage over static rules alone is worth tracking as a design pattern for AppSec tooling, though the automotive ECU focus makes it directly applicable only in that niche.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>LoRAScan: Runtime detection of backdoored LoRA adapters via activation spikes</title><link>https://curasec.metacog.co.kr/insights/2026-08-10-lorascan-detecting-backdoor-prompts-in-low-rank-adapters-for/</link><pubDate>Mon, 10 Aug 2026 13:39:41 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-10-lorascan-detecting-backdoor-prompts-in-low-rank-adapters-for/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Identifies a real supply-chain risk for teams consuming third-party LoRA adapters: a backdoored adapter can alter model output on hidden triggers without modifying base model weights. LoRAScan&amp;rsquo;s inference-time monitoring approach is worth evaluating if your ML pipelines pull adapters from untrusted registries or Hugging Face.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No active exploitation, IOCs, or ATT&amp;amp;CK-mappable TTPs to act on; this is foundational research on a threat class. Worth filing as context if your org is building detections around AI/ML pipeline integrity, but no hunt or rule work warranted today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Surfaces an emerging supply-chain risk category for AI workloads—untrusted fine-tuned adapters as a malware vector—useful background for shaping AI vendor-risk policy before it becomes a control requirement.&lt;/li>
&lt;/ul></description></item><item><title>Policy-Masked Private Experts: Access Control in Sparse MoE LLMs</title><link>https://curasec.metacog.co.kr/insights/2026-08-10-policy-masked-private-experts-auditable-and-reversible-capab/</link><pubDate>Mon, 10 Aug 2026 13:39:41 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-10-policy-masked-private-experts-auditable-and-reversible-capab/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel architecture for parameter-level capability gating in MoE models (tested on Qwen3-30B and DeepSeek-V2-Lite); worth tracking if your team deploys or fine-tunes MoE-based models and needs verifiable separation between capability tiers — no production tooling yet.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Prompt Injection via 'Ask AI' Deep Links Silently Poisons LLM Memory</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-ai-recommendation-poisoning-how-ask-ai-buttons-silently-alte/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-ai-recommendation-poisoning-how-ask-ai-buttons-silently-alte/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel attack class: hidden payloads in pre-filled AI deep links can alter LLM memory without user awareness. No exploitation signals or PoC, but engineers building AI-integrated features should audit any &amp;lsquo;Ask AI&amp;rsquo; button implementations for unsanitized prompt passthrough.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, ATT&amp;amp;CK mapping, or active campaign indicators are present. Worth tracking as AI assistant adoption grows, but there is no detection surface or hunt query to act on today.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> This attack class is relevant to any enterprise deploying AI assistants with memory or context features; factor it into AI acceptable-use policy and vendor evaluation criteria before broader rollout.&lt;/li>
&lt;/ul></description></item><item><title>GUI Agent Guardrails Erode Under Multi-Turn User Persuasion</title><link>https://curasec.metacog.co.kr/insights/2026-08-03-alignment-is-local-a-paired-diagnostic-for-gui-agents-under/</link><pubDate>Mon, 03 Aug 2026 15:12:30 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-03-alignment-is-local-a-paired-diagnostic-for-gui-agents-under/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research shows that single-turn ASR benchmarks overstate real-world robustness of GUI agent guardrails, with 4-turn escalation chains recovering ~20 points of attack success across all tested models. Teams building or deploying GUI agents should treat static prompt-level alignment as insufficient and evaluate multi-turn threat scenarios in their safety testing.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> If your organization is piloting or deploying AI GUI agents, this research illustrates that current safety guardrails are weaker than benchmark numbers suggest under realistic multi-turn user interaction — useful context for AI deployment policies and vendor capability reviews, but no immediate action required.&lt;/li>
&lt;/ul></description></item><item><title>ADSD Attack Collapses Speculative Decoding Acceptance, Slows LLM Inference 62%</title><link>https://curasec.metacog.co.kr/insights/2026-07-27-adversarial-prompts-for-acceptance-collapse-in-speculative-d/</link><pubDate>Mon, 27 Jul 2026 15:10:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-27-adversarial-prompts-for-acceptance-collapse-in-speculative-d/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel prompt-suffix attack degrades speculative decoding throughput without corrupting outputs, affecting any deployment using draft-target inference acceleration (vLLM, TGI, etc.). No patch or mitigation exists yet; file this when designing LLM serving infrastructure to justify input validation and rate controls at the prompt layer.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>LLM + Code Slicing for NFT Smart Contract Vulnerability Detection</title><link>https://curasec.metacog.co.kr/insights/2026-07-27-ethereum-nft-smart-contracts-knowledge-guided-vulnerability/</link><pubDate>Mon, 27 Jul 2026 15:10:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-27-ethereum-nft-smart-contracts-knowledge-guided-vulnerability/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Interesting research combining code slicing with LLM analysis to detect reentrancy and overflow in ERC-721 contracts, but no tooling release or actionable change to running systems today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Prompt syntax shapes secure code output in open LLMs</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-the-language-of-security-how-prompt-syntax-shapes-secure-cod/</link><pubDate>Mon, 20 Jul 2026 14:31:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-the-language-of-security-how-prompt-syntax-shapes-secure-cod/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research shows specific syntactic elements (constraints, guards, conditions) placed in prompts consistently reduce insecure code generation from open LLMs — useful input for teams building internal coding assistants or prompt templates for developer tooling.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Transferable CoT Jailbreaks Bypass LLM Output Safeguards at Scale</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-hidden-in-thought-transferable-chain-of-thought-artifacts-in/</link><pubDate>Mon, 20 Jul 2026 14:31:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-hidden-in-thought-transferable-chain-of-thought-artifacts-in/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research shows output-only filters like Llama-Guard 3 are insufficient against reasoning-layer attacks; teams building AI applications should evaluate reasoning context, not just final outputs, when designing safety architectures.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Finding that reasoning-capable models are 2x+ more vulnerable and standard output safeguards regularly fail has implications for enterprise AI risk posture; useful context for AI usage policies and vendor safety attestation reviews.&lt;/li>
&lt;/ul></description></item><item><title>Malaika: LLM Multi-Agent Framework for Android Malware Behavior Analysis</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-malaika-understanding-malware-through-tri-grounded-agentic-r/</link><pubDate>Mon, 13 Jul 2026 14:30:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-malaika-understanding-malware-through-tri-grounded-agentic-r/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Academic research on grounded agentic reasoning for malware behavior reconstruction; no immediate engineering action, but the tri-grounding approach (domain, semantics, knowledge) is worth noting when evaluating LLM-assisted code-analysis tooling.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Malaika&amp;rsquo;s behavior-reconstruction framing — connecting sparse program evidence to auditable behavioral conclusions — could inform how teams structure LLM-assisted malware triage workflows, though no detection or hunt action is available from this paper alone.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>SeedSmith: LLM-Agentic Seed Synthesis for Directed Fuzzing</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-seedsmith-llm-driven-seed-synthesis-for-directed-fuzzing/</link><pubDate>Mon, 13 Jul 2026 14:30:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-seedsmith-llm-driven-seed-synthesis-for-directed-fuzzing/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel research showing an LLM-agentic pipeline that improves directed fuzzer crash-trigger rates by generating semantically aware seed corpora; worth evaluating if your team runs fuzzing campaigns against internal C/C++ codebases, but no immediate change to running systems is required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>SherAgent: LLM-Powered Provenance Graph Attack Investigation</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-sheragent-scaling-attack-investigation-in-the-wild-via-llm-e/</link><pubDate>Mon, 13 Jul 2026 14:30:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-sheragent-scaling-attack-investigation-in-the-wild-via-llm-e/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> SherAgent demonstrates a 31–64% improvement in automated attack investigation success rates using LLM-driven provenance graph backtracking — useful context for teams evaluating or building AI-assisted triage workflows, though no production tool or IOCs are released here.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Research from a real SOC environment shows LLM-assisted alert triage meaningfully reduces the manual investigation backlog; relevant background for leaders assessing AI tooling investments in detection and response.&lt;/li>
&lt;/ul></description></item><item><title>SLBench: LLM Agents Fail Skill Logical Constraints at 70% Rate</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-slbench-evaluating-how-llm-agents-follow-logical-relations-i/</link><pubDate>Mon, 13 Jul 2026 14:30:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-slbench-evaluating-how-llm-agents-follow-logical-relations-i/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> If you deploy LLM agents with skill files or tool orchestration, this research quantifies a real risk class: agents routinely violate preconditions and constraints, producing privacy leaks and unsafe config changes. No patch action today, but the SLGuard scaffold approach is worth evaluating if you build skill-guided agents.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Academic evidence that LLM agents fail safety constraints at high rates is useful background for AI governance discussions, but there is no immediate vendor exposure or regulatory trigger here — file for the next AI risk policy review.&lt;/li>
&lt;/ul></description></item></channel></rss>