The Hidden Data System Beneath AI
Drawing on internal-control practice and standards-oriented references including NIST AI RMF / NIST AI 600-1, ISO/IEC 42001, OWASP LLM and GenAI risk guidance, W3C PROV, W3C Trace Context, NIST SSDF, NIST Privacy Framework, NIST log-management guidance, NIST security and privacy controls, COSO internal-control concepts, and ICMJE authorship guidance, the paper proposes a control taxonomy for AI data events.