AI Cyber Security Research Boardroom
Footnoted and verified source material — availability index and navigation to synthesis reports, archived articles, and the complete research bundle.
This index catalogs every footnoted and verification-ledger reference used in the boardroom study corpus. Each external citation has a dedicated archived article (Markdown and PDF). Synthesis reports are published separately under output/. Simulation window: May 2026.
Master index of capture status, fallback recovery methods, per-article inventory, and machine-readable manifest.
| Format | File | Description |
|---|---|---|
| REFERENCE-AVAILABILITY-REPORT.pdf | Formatted availability report (AICSR-REF-INDEX-2026-001) | |
| Markdown | REFERENCE-AVAILABILITY-REPORT.md | Source document for regeneration |
| YAML | REFERENCE-MANIFEST.yaml | Machine-readable article inventory and fallback strategies |
| Markdown | CONTINUE-REFERENCES.md | Regeneration and hard-capture recovery instructions |
Primary boardroom deliverables — study, mitigation, dialog, abstracts, materials index, and methodology. PDF and Markdown siblings where published.
| Document ID | Title | Downloads |
|---|---|---|
AICSR-STUDY-2026-001 | Comprehensive Study | PDF Cyber-Security-AI-Diligence-Research-Study.pdf MD Cyber-Security-AI-Diligence-Research-Study.md |
AICSR-MIT-2026-001 | Mitigation Strategy | PDF MVAP-Complete-Mitigation-Strategy.pdf MD MVAP-Complete-Mitigation-Strategy.md |
AICSR-DLG-2026-001 | Dialog Transcript | PDF Boardroom-Complete-Dialog-Transcript.pdf MD Boardroom-Complete-Dialog-Transcript.md |
AICSR-ABS-2026-001 | Abstracts | PDF Boardroom-Comprehensive-Abstracts.pdf MD Boardroom-Comprehensive-Abstracts.md |
AICSR-MATINDEX-2026-001 | Materials Index | PDF RESEARCH-MATERIALS-INDEX.pdf MD RESEARCH-MATERIALS-INDEX.md |
AICSR-METHOD-2026-001 | How the Research Was Done | MD How-The-Research-Was-Done.md |
Repository governance files and synthesis manifests. Paths are relative to the published web bundle root.
| File | Purpose |
|---|---|
| PROJECT.md | Project name, topic, layout, document IDs |
| Agents.md | Workspace isolation and boardroom workflow rules |
| roster.yaml | Participant groups, speaking order, MVAP metadata |
| sessions/verification-ledger.md | Claim verification audit trail with footnote keys |
| sessions/VOTE-RECORD.md | Formal ballots with per-dissenter rationale |
Synthesis manifests
| Manifest | Repository path |
|---|---|
| ABSTRACT-MANIFEST.yaml | output/ABSTRACT-MANIFEST.yaml |
| DIALOG-MANIFEST.yaml | output/DIALOG-MANIFEST.yaml |
| MITIGATION-MANIFEST.yaml | output/MITIGATION-MANIFEST.yaml |
| STUDY-MANIFEST.yaml | output/STUDY-MANIFEST.yaml |
| REFERENCE-MANIFEST.yaml | output/references/REFERENCE-MANIFEST.yaml |
Archived snapshots of main synthesis reports for footnote cross-reference. Canonical editions are listed in Section 2.
| Key | Title | Capture | Archive | Source |
|---|---|---|---|---|
abs-ref | Boardroom Comprehensive Abstracts AICSR-ABS-2026-001Canonical: Boardroom-Comprehensive-Abstracts.pdf | Primary | PDF · MD | output/Boardroom-Comprehensive-Abstracts.md |
dlg-ref | Boardroom Complete Dialog Transcript AICSR-DLG-2026-001Canonical: Boardroom-Complete-Dialog-Transcript.pdf | Primary | PDF · MD | output/Boardroom-Complete-Dialog-Transcript.md |
matindex-ref | Research Materials Index AICSR-MATINDEX-2026-001Canonical: RESEARCH-MATERIALS-INDEX.pdf | Primary | PDF · MD | output/RESEARCH-MATERIALS-INDEX.md |
method-ref | How the Research Was Done AICSR-METHOD-2026-001Canonical: How-The-Research-Was-Done.pdf | Primary | PDF · MD | output/How-The-Research-Was-Done.md |
mit-ref | MVAP Complete Mitigation Strategy AICSR-MIT-2026-001Canonical: MVAP-Complete-Mitigation-Strategy.pdf | Primary | PDF · MD | output/MVAP-Complete-Mitigation-Strategy.md |
study-ref | AI Cyber Security Research Study AICSR-STUDY-2026-001Canonical: Cyber-Security-AI-Diligence-Research-Study.pdf | Primary | PDF · MD | output/Cyber-Security-AI-Diligence-Research-Study.md |
Governance artifacts archived as reference articles with PDF and Markdown siblings.
| Key | Title | Capture | Archive | Source |
|---|---|---|---|---|
project-ref | PROJECT.md — boardroom project metadata | Primary | PDF · MD | PROJECT.md |
vote-record-ref | Formal Vote Record with dissent rationale | Primary | PDF · MD | sessions/VOTE-RECORD.md |
Verified external sources — each key links to archived PDF and Markdown articles plus the primary URL where available.
| Key | Title | Capture | Archive | Primary Source |
|---|---|---|---|---|
bgov-gao | Bloomberg Government — 815 classified data violations summary | Primary | PDF · MD | Primary source |
cisa-kev | CISA Known Exploited Vulnerabilities Catalog | Primary | PDF · MD | Primary source |
cisa-salt | CISA Advisory AA25-239A — Salt Typhoon | Primary | PDF · MD | Primary source |
csa-cisa | CSA Research Note — CISA Leadership Governance Vacuum (2026-04-24) | Primary | PDF · MD | Primary source |
csa-nvd | CSA Whitepaper — NVD Infrastructure Crisis & AI Vulnerability Discovery | Primary | PDF · MD | Primary source |
eo-14409 | White House EO 14409 — AI Innovation and Security (2026-06-02) | Primary | PDF · MD | Primary source |
fbi-salt | CyberScoop — FBI confirms Salt Typhoon still ongoing (Feb 2026) | Primary | PDF · MD | Primary source |
gao-classified | GAO-26-107861 — 815 Classified Contractor Security Violations | corroborating_press | PDF · MD | Primary source |
gao-water | GAO-26-109159 — Water Sector Cybersecurity | corroborating_press | PDF · MD | Primary source |
gca-salt | GCA — Salt Typhoon Across the Internet | Primary | PDF · MD | Primary source |
gdpr-art32 | GDPR Article 32 — Security of processing | Primary | PDF · MD | Primary source |
horizon3-chain | Horizon3.ai — LiteLLM chained with Starlette BadHost RCE | Primary | PDF · MD | Primary source |
iec-62443 | ISA/IEC 62443 Industrial Cybersecurity Standards | Primary | PDF · MD | Primary source |
litellm-kev | CISA Alert — CVE-2026-42271 LiteLLM added to KEV | Primary | PDF · MD | Primary source |
litellm-sqli | The Hacker News — LiteLLM CVE-2026-42208 exploited within 36h | Primary | PDF · MD | Primary source |
mitre-atlas | MITRE ATLAS — Adversarial ML | github_yaml_mirror | PDF · MD | Primary source |
mitre-t1059-001 | MITRE ATT&CK T1059.001 — PowerShell | Primary | PDF · MD | Primary source |
mitre-t1558-003 | MITRE ATT&CK T1558.003 — Kerberoasting | Primary | PDF · MD | Primary source |
ms-isac | StateScoop — CISA ending MS-ISAC support | Primary | PDF · MD | Primary source |
nist-airmf | NIST AI Risk Management Framework 1.0 | Primary | PDF · MD | Primary source |
nist-genai | NIST Generative AI Profile (NIST.AI.600-1) | Primary | PDF · MD | Primary source |
njccic-house | NJCCIC — Salt Typhoon targets House Committee emails | corroborating_encyclopedia | PDF · MD | Primary source |
ostif-badhost | OSTIF — BadHost vulnerability in Starlette | Primary | PDF · MD | Primary source |
owasp-llm | OWASP Top 10 for LLM Applications 2025 | Primary | PDF · MD | Primary source |
owasp-llm01 | OWASP LLM01 — Prompt Injection | Primary | PDF · MD | Primary source |
owasp-llm02 | OWASP LLM02 — Sensitive Information Disclosure | Primary | PDF · MD | Primary source |
sigstore-cosign | Sigstore cosign — container/signing verification | Primary | PDF · MD | Primary source |
slsa | SLSA Supply-chain Levels for Software Artifacts v1.0 | Primary | PDF · MD | Primary source |
techcrunch-cisa | TechCrunch — Acting CISA chief uploaded FOUO docs to ChatGPT | Primary | PDF · MD | Primary source |
trend-q1 | Trend Micro — U.S. Public Sector Under Siege Q1 2026 | Primary | PDF · MD | Primary source |
All 38 footnoted and verification-ledger reference keys — local snapshots, repository metadata, and external citations in one table.
| Key | Title | Category | Capture | Archive | Source |
|---|---|---|---|---|---|
abs-ref | Boardroom Comprehensive Abstracts AICSR-ABS-2026-001Canonical: Boardroom-Comprehensive-Abstracts.pdf | Local snapshot | Primary | PDF · MD | output/Boardroom-Comprehensive-Abstracts.md |
bgov-gao | Bloomberg Government — 815 classified data violations summary | External | Primary | PDF · MD | Primary source |
cisa-kev | CISA Known Exploited Vulnerabilities Catalog | External | Primary | PDF · MD | Primary source |
cisa-salt | CISA Advisory AA25-239A — Salt Typhoon | External | Primary | PDF · MD | Primary source |
csa-cisa | CSA Research Note — CISA Leadership Governance Vacuum (2026-04-24) | External | Primary | PDF · MD | Primary source |
csa-nvd | CSA Whitepaper — NVD Infrastructure Crisis & AI Vulnerability Discovery | External | Primary | PDF · MD | Primary source |
dlg-ref | Boardroom Complete Dialog Transcript AICSR-DLG-2026-001Canonical: Boardroom-Complete-Dialog-Transcript.pdf | Local snapshot | Primary | PDF · MD | output/Boardroom-Complete-Dialog-Transcript.md |
eo-14409 | White House EO 14409 — AI Innovation and Security (2026-06-02) | External | Primary | PDF · MD | Primary source |
fbi-salt | CyberScoop — FBI confirms Salt Typhoon still ongoing (Feb 2026) | External | Primary | PDF · MD | Primary source |
gao-classified | GAO-26-107861 — 815 Classified Contractor Security Violations | External | corroborating_press | PDF · MD | Primary source |
gao-water | GAO-26-109159 — Water Sector Cybersecurity | External | corroborating_press | PDF · MD | Primary source |
gca-salt | GCA — Salt Typhoon Across the Internet | External | Primary | PDF · MD | Primary source |
gdpr-art32 | GDPR Article 32 — Security of processing | External | Primary | PDF · MD | Primary source |
horizon3-chain | Horizon3.ai — LiteLLM chained with Starlette BadHost RCE | External | Primary | PDF · MD | Primary source |
iec-62443 | ISA/IEC 62443 Industrial Cybersecurity Standards | External | Primary | PDF · MD | Primary source |
litellm-kev | CISA Alert — CVE-2026-42271 LiteLLM added to KEV | External | Primary | PDF · MD | Primary source |
litellm-sqli | The Hacker News — LiteLLM CVE-2026-42208 exploited within 36h | External | Primary | PDF · MD | Primary source |
matindex-ref | Research Materials Index AICSR-MATINDEX-2026-001Canonical: RESEARCH-MATERIALS-INDEX.pdf | Local snapshot | Primary | PDF · MD | output/RESEARCH-MATERIALS-INDEX.md |
method-ref | How the Research Was Done AICSR-METHOD-2026-001Canonical: How-The-Research-Was-Done.pdf | Local snapshot | Primary | PDF · MD | output/How-The-Research-Was-Done.md |
mit-ref | MVAP Complete Mitigation Strategy AICSR-MIT-2026-001Canonical: MVAP-Complete-Mitigation-Strategy.pdf | Local snapshot | Primary | PDF · MD | output/MVAP-Complete-Mitigation-Strategy.md |
mitre-atlas | MITRE ATLAS — Adversarial ML | External | github_yaml_mirror | PDF · MD | Primary source |
mitre-t1059-001 | MITRE ATT&CK T1059.001 — PowerShell | External | Primary | PDF · MD | Primary source |
mitre-t1558-003 | MITRE ATT&CK T1558.003 — Kerberoasting | External | Primary | PDF · MD | Primary source |
ms-isac | StateScoop — CISA ending MS-ISAC support | External | Primary | PDF · MD | Primary source |
nist-airmf | NIST AI Risk Management Framework 1.0 | External | Primary | PDF · MD | Primary source |
nist-genai | NIST Generative AI Profile (NIST.AI.600-1) | External | Primary | PDF · MD | Primary source |
njccic-house | NJCCIC — Salt Typhoon targets House Committee emails | External | corroborating_encyclopedia | PDF · MD | Primary source |
ostif-badhost | OSTIF — BadHost vulnerability in Starlette | External | Primary | PDF · MD | Primary source |
owasp-llm | OWASP Top 10 for LLM Applications 2025 | External | Primary | PDF · MD | Primary source |
owasp-llm01 | OWASP LLM01 — Prompt Injection | External | Primary | PDF · MD | Primary source |
owasp-llm02 | OWASP LLM02 — Sensitive Information Disclosure | External | Primary | PDF · MD | Primary source |
project-ref | PROJECT.md — boardroom project metadata | Repository | Primary | PDF · MD | PROJECT.md |
sigstore-cosign | Sigstore cosign — container/signing verification | External | Primary | PDF · MD | Primary source |
slsa | SLSA Supply-chain Levels for Software Artifacts v1.0 | External | Primary | PDF · MD | Primary source |
study-ref | AI Cyber Security Research Study AICSR-STUDY-2026-001Canonical: Cyber-Security-AI-Diligence-Research-Study.pdf | Local snapshot | Primary | PDF · MD | output/Cyber-Security-AI-Diligence-Research-Study.md |
techcrunch-cisa | TechCrunch — Acting CISA chief uploaded FOUO docs to ChatGPT | External | Primary | PDF · MD | Primary source |
trend-q1 | Trend Micro — U.S. Public Sector Under Siege Q1 2026 | External | Primary | PDF · MD | Primary source |
vote-record-ref | Formal Vote Record with dissent rationale | Repository | Primary | PDF · MD | sessions/VOTE-RECORD.md |
Deliberation transcripts and verification ledger — 14 files.
| Session | Repository path |
|---|---|
| 2026-06-22-cybersecurity-ai-diligence-introductions.md | sessions/2026-06-22-cybersecurity-ai-diligence-introductions.md |
| 2026-06-22-cybersecurity-ai-diligence-rounds-1-20.md | sessions/2026-06-22-cybersecurity-ai-diligence-rounds-1-20.md |
| 2026-06-22-mvap-pillar-2-4-red-blue-exercise.md | sessions/2026-06-22-mvap-pillar-2-4-red-blue-exercise.md |
| 2026-07-22-mvap-p2-03-p4-05-remediation-validation-1.md | sessions/2026-07-22-mvap-p2-03-p4-05-remediation-validation-1.md |
| 2026-09-20-mvap-level-2-maturity-review.md | sessions/2026-09-20-mvap-level-2-maturity-review.md |
| 2026-09-20-mvap-maturity-review-scheduled.md | sessions/2026-09-20-mvap-maturity-review-scheduled.md |
| 2026-09-21-mvap-p2-03-p4-05-remediation-validation-2.md | sessions/2026-09-21-mvap-p2-03-p4-05-remediation-validation-2.md |
| 2026-12-20-mvap-v1-1-backlog-zero-day-government-risk.md | sessions/2026-12-20-mvap-v1-1-backlog-zero-day-government-risk.md |
| 2027-03-20-p7-05-zero-day-tabletop.md | sessions/2027-03-20-p7-05-zero-day-tabletop.md |
| 2027-03-20-quarterly-government-risk-review.md | sessions/2027-03-20-quarterly-government-risk-review.md |
| 2027-06-20-mvap-v1-2-adoption.md | sessions/2027-06-20-mvap-v1-2-adoption.md |
| 2027-06-20-quarterly-government-risk-review-q2.md | sessions/2027-06-20-quarterly-government-risk-review-q2.md |
| VOTE-RECORD.md | sessions/VOTE-RECORD.md |
| verification-ledger.md | sessions/verification-ledger.md |
Expert agent profiles — one per deliberant (32 participants).
| Profile | Repository path |
|---|---|
| _template.md | participants/_template.md |
| aegis-elena-rostova-jr.md | participants/aegis-elena-rostova-jr.md |
| aether-rene-dupont.md | participants/aether-rene-dupont.md |
| aisha-nwosu.md | participants/aisha-nwosu.md |
| arthur-vance.md | participants/arthur-vance.md |
| chloe-mitchell.md | participants/chloe-mitchell.md |
| cipher-zoe-kruger.md | participants/cipher-zoe-kruger.md |
| devonne-brooks.md | participants/devonne-brooks.md |
| eleanor-vance.md | participants/eleanor-vance.md |
| elena-rostova.md | participants/elena-rostova.md |
| ghost-ji-hoon-park.md | participants/ghost-ji-hoon-park.md |
| gridlock-dimitri-volkov.md | participants/gridlock-dimitri-volkov.md |
| hex-alaric-vance.md | participants/hex-alaric-vance.md |
| jax-reed.md | participants/jax-reed.md |
| jordan-taylor.md | participants/jordan-taylor.md |
| kira-ekaterina-petrova.md | participants/kira-ekaterina-petrova.md |
| liam-oconnor.md | participants/liam-oconnor.md |
| marcus-thorne.md | participants/marcus-thorne.md |
| mateo-silva.md | participants/mateo-silva.md |
| maya-patel.md | participants/maya-patel.md |
| nullbyte-siddharth-nair.md | participants/nullbyte-siddharth-nair.md |
| oliver-hansen.md | participants/oliver-hansen.md |
| payload-dominic-kruse.md | participants/payload-dominic-kruse.md |
| phoenix-amara-okafor.md | participants/phoenix-amara-okafor.md |
| sarah-jenkins.md | participants/sarah-jenkins.md |
| shield-marcus-sterling.md | participants/shield-marcus-sterling.md |
| sql-sam-samuel-cohen.md | participants/sql-sam-samuel-cohen.md |
| susan-albright.md | participants/susan-albright.md |
| synapse-kenji-sato.md | participants/synapse-kenji-sato.md |
| tariq-al-jamil.md | participants/tariq-al-jamil.md |
| victor-vance.md | participants/victor-vance.md |
| viper-cassandra-cross.md | participants/viper-cassandra-cross.md |
MVAP framework versions, playbooks, and risk registers — 8 files.
| Specification | Repository path |
|---|---|
| BACKLOG-COMPLETE.md | mvap/BACKLOG-COMPLETE.md |
| MVAP-SPECIFICATION-v1.0.md | mvap/MVAP-SPECIFICATION-v1.0.md |
| MVAP-SPECIFICATION-v1.1-DRAFT.md | mvap/MVAP-SPECIFICATION-v1.1-DRAFT.md |
| MVAP-SPECIFICATION-v1.1.md | mvap/MVAP-SPECIFICATION-v1.1.md |
| MVAP-SPECIFICATION-v1.2-DRAFT.md | mvap/MVAP-SPECIFICATION-v1.2-DRAFT.md |
| P7-IMPLEMENTATION-PLAYBOOK.md | mvap/P7-IMPLEMENTATION-PLAYBOOK.md |
| REMEDIATION-SPRINT-30DAY.md | mvap/REMEDIATION-SPRINT-30DAY.md |
| ZERO-DAY-OPEN-SOURCE-RISK-ASSESSMENT.md | mvap/ZERO-DAY-OPEN-SOURCE-RISK-ASSESSMENT.md |
All reports, reference articles, session transcripts, participant profiles, MVAP specifications, and manifests in a single archive.
Download AICSR-RESEARCH-WEB-BUNDLE.zip