ABSTRACT The rapid expansion of generative AI—particularly large language models (LLMs)—into mission‐critical domains has underscored the urgent need for unified frameworks that embed trust, risk and security management (TRiSM) throughout the AI lifecycle. In this work, we present a comprehensive review and synthesis of AI TRiSM, uniting five foundational pillars: explainability with real‐time drift monitoring, ModelOps governance, application‐level security, data protection and privacy, and adversarial resilience. We introduce three aligned taxonomies for trust dimensions (e.g., fairness, transparency, accountability, inclusiveness, ethical alignment), risk categories (e.g., model, data, legal, operational, societal, cognitive, emergent, third‐party) and security controls (e.g., access management, infrastructure hardening, runtime enforcement, privacy‐enhancing techniques). Building on these, we develop a detailed toxicity taxonomy for generative AI—covering hate, violence, self‐harm, misinformation, bias, jailbreak attacks, multimodal harms, and more—each mapped to specific TRiSM safeguards. Through cross‐domain case studies in finance, healthcare, autonomous vehicles, public sector, cybersecurity, and beyond, we illustrate practical integration patterns and governance workflows. We also identify key adoption challenges—fragmented tooling, late‐stage governance, scalability constraints, evolving threats and regulations—and chart a forward‐looking roadmap toward adaptive, AI‐driven policy engines, causal explainability, privacy‐by‐design pipelines, continuous real‐time assurance, federated governance, quantum‐safe architectures, and sustainable “green AI” practices. This article aims to guide researchers and practitioners in designing, evaluating and scaling resilient, ethical, and compliant AI systems at enterprise scale.
Partha Pratim Ray (Fri,) studied this question.