Signal A Security-Oriented Lifecycle Model for Large Language Model Systems
Summary
Eleftherios Batzolis, George Drosatos, Vassilis Katsouros and Konstantinos Rantos address the gap between the rapid integration of large language models into critical infrastructure and enterprise workflows and the lifecycle frameworks meant to manage them, which are designed for operational efficiency rather than security analysis. The authors note that security-relevant activities such as data provenance verification, artifact signing, agentic permission control and decommissioning are often left implicit in current frameworks. They propose a lifecycle model organized around security-relevant boundaries rather than workflow optimization, comprising 32 stages across four core layers, Data, Model, Distribution and Application, plus a 12-stage LLMOps pillar and a nine-category governance pillar, introducing 13 stages as newly distinct units because existing frameworks fail to separate them clearly. A governance mapping that synthesizes the NIST AI Risk Management Framework, the EU AI Act and ISO/IEC 42001 exposes a structural skew in the current regulatory landscape. Governance evidence clusters at deployment stages visible to regulators, while the most consequential decisions, such as data selection, alignment strategy and capability boundaries, are made at development stages where regulatory visibility is lowest.
Classification
Evidence 1
- A Security-Oriented Lifecycle Model for Large Language Model Systems arXiv (cs.CY) 2026-08-04 accessed 2026-08-05T02:34:16+00:00
Part of trends 0
No objects.
Directly linked issues 0
No objects.
Public id: fm-5dfcf87d1a6a
