Achieving AI Model Weight Security Level 3 (SL3)

Jair Aguirre, Phillip Robertson, Steven F. Comer, Matthew J. Malone, Wesley Hurd

ResearchPublished Aug 25, 2026

RAND researchers propose Security Level 3 (SL3), a standardized framework of 262 security controls adapted from National Institute of Standards and Technology Special Publication 800-53 to protect artificial intelligence model weights against organized cybercrime and insider threats. The controls address 31 high-feasibility attack vectors and are designed for feasible, incremental implementation within six to 12 months.

Topics

Document Details

Citation

Chicago Manual of Style

Aguirre, Jair, Phillip Robertson, Steven F. Comer, Matthew J. Malone, and Wesley Hurd, Achieving AI Model Weight Security Level 3 (SL3). Santa Monica, CA: RAND Corporation, 2026. https://www.rand.org/pubs/research_reports/RRA4704-1.html.
BibTeX RIS

Research conducted by

This publication is part of the RAND research report series. Research reports present research findings and objective analysis that address the challenges facing the public and private sectors. All RAND research reports undergo rigorous peer review to ensure high standards for research quality and objectivity.

This document and trademark(s) contained herein are protected by law. This representation of RAND intellectual property is provided for noncommercial use only. Unauthorized posting of this publication online is prohibited; linking directly to this product page is encouraged. Permission is required from RAND to reproduce, or reuse in another form, any of its research documents for commercial purposes. For information on reprint and reuse permissions, please visit www.rand.org/pubs/permissions.

RAND is a nonprofit institution that helps improve policy and decisionmaking through research and analysis. RAND's publications do not necessarily reflect the opinions of its research clients and sponsors.