Signal A Security-Oriented Lifecycle Model for Large Language Model Systems
Summary
Eleftherios Batzolis, George Drosatos, Vassilis Katsouros, and Konstantinos Rantos published a paper on arXiv (cs.CY) on August 4, 2026, addressing the gap between the rapid integration of large language models into critical infrastructure and enterprise workflows and lifecycle frameworks designed for operational efficiency rather than security analysis. The authors note that security-relevant activities such as data provenance verification, artifact signing, agentic permission control, and decommissioning are often left implicit in current frameworks. They propose a lifecycle model structured around security-relevant boundaries rather than workflow optimization, comprising 32 stages across four core pipeline layers (Data, Model, Distribution, Application), supported by a 12-stage LLMOps pillar and a 9-category governance pillar, with 13 stages introduced as newly distinct units because they expose security concerns existing frameworks do not clearly separate. A governance mapping synthesizing the NIST AI Risk Management Framework, the EU AI Act, and ISO/IEC 42001 reveals a structural property of the current regulatory landscape: governance evidence concentrates at deployment-facing stages where systems are visible to regulators, while the most consequential decisions, including data selection, alignment strategy, and capability boundaries, are made at development-facing stages where regulatory visibility is lowest.
Classification
Evidence 1
- arXiv (cs.CY) 2026-08-04 accessed 2026-08-05T02:34:16+00:00
Part of trends 0
No objects.
Directly linked issues 0
No objects.
Public id: fm-5dfcf87d1a6a