RiskRubric v2 Concept Paper
Released: 06/04/2026
This CSA concept paper introduces RiskRubric v2, an evidence-based risk assessment framework designed to evaluate AI services across six pillars of trust, security, and operational integrity.
The paper examines:
- How AI risk assessment must expand beyond models to include MCP servers and AI agents
- Why independent, multi-scanner evaluations improve transparency, confidence, and trust in AI risk ratings
- How RiskRubric v2 introduces updated scoring methodologies, confidence indices, and governance structures for AI risk assessment
The paper also explores the evolution of RiskRubric from a single-evaluator model to an open ecosystem of independent assessment partners, while introducing a new Excessive Agency pillar to address emerging risks associated with autonomous AI systems.
Download this Resource
Prefer to access this resource without an account? Download it now.



