PUBLIC RESEARCH METHOD

How the Secure AI Playbook is built

Mike Sobiegraj researches, authors, edits, and maintains the Playbook. Interviews, source material, frameworks, regulation, implementation examples, and feedback inform the research; final content and editorial decisions remain with the author.

THE RESEARCH LOOP

Every Playbook stage follows the same research loop

  1. Step 1
    Define the stage

    Set scope, expected output, and assumptions that need testing in the context of the overall Playbook architecture.

  2. Step 2
    Gather evidence

    Review regulatory guidance, standards, frameworks, public research, and implementation examples relevant to the stage.

  3. Step 3
    Draft the stage

    Synthesize the first usable structure while keeping known gaps and open questions visible.

  4. Step 4
    Review for coherence and usability

    Check the proposed guidance against the available evidence, the surrounding Playbook structure, and its usability in real operating environments.

  5. Step 5
    Compare organizational contexts

    Create stage variations based on differences in governance maturity, industry, regulation, architecture, and operating model.

  6. Step 6
    Publish and refine

    Publish the current guidance, explain what changed, and reopen it when new evidence emerges.

EDITORIAL DEVELOPMENT

Research inputs are synthesized through a single editorial process

Research inputs

Research may include:

  • Interviews with CISOs and other relevant professionals
  • Regulatory requirements and guidance
  • Industry standards and frameworks
  • Public research and implementation examples
  • Observed differences between organizational environments
  • Feedback on Draft elements of the Playbook

Editorial synthesis

The author:

  • Interprets the research inputs
  • Reconciles conflicting perspectives
  • Decides what is relevant to the Playbook
  • Writes and structures the published guidance
  • Maintains consistency across the complete Playbook
  • Publishes changes as Draft or a numbered version

PUBLICATION STATUS AND VERSIONING

How stable is the published guidance?

Draft
Actively developed guidance that may change materially as research and editorial work continue.
v1.0
The first stable published version of a Playbook element.
v1.x
Refinements, clarifications, additions, and compatible improvements.
v2.0
A material change to the structure, method, or intended use of the published guidance.

Version numbers communicate publication maturity and change history. They do not claim empirical effectiveness or universal applicability.

INDUSTRY STANDARD ALIGNMENT

Which established frameworks or standards does this element correspond to?

Specific activities, decisions, outputs, controls, or evidence are mapped to named provisions.

Mappings are source-backed and appear as pills beside the relevant Playbook element. Alignment describes correspondence, not proof of effectiveness.

Illustrative example Industry standard alignment:
  • NIST AI RMF
  • ISO/IEC 42001

RECURRING STRUCTURE

What every Playbook stage will contain

Recurring content in each Playbook stage
Element Purpose
Stage definition Stage title and concise description of what the stage does.
Input Independent triggers, records, decisions, or evidence required before the stage begins.
Main activities The minimum actions required to perform the stage and progress to the next decision.
Output and evidence The records, decisions, test results, and other evidence produced by the stage.
Tools and templates Forms, process templates, guides, product lists, and other execution resources supporting the stage.
Ownership and responsibilities The business, technical, security, legal, compliance, privacy, and control responsibilities relevant to the stage.
Common blockers Practical conditions that cause the stage to stall, fail, or become ineffective.
Known gaps and open questions Unresolved questions and areas where the Playbook's current guidance remains incomplete.
Publication status and version Draft or a numbered version indicating the maturity and change history of the published guidance.
Last reviewed The most recent date on which the stage content was materially reviewed.
Current focus The immediate research and development priority for that stage.
Industry standard alignment Source-backed mappings between specific stage elements and named regulatory, framework, or industry-standard provisions.
Sources and references The source material used to support the published guidance and its mappings.
Research acknowledgments, where applicable People who agreed to be named for interviews or Draft reviews that informed the research.

SHARE FEEDBACK

Test the Playbook against real operating environments

Here’s what would be useful to understand:

  • Which Playbook stage do you participate in, and what decision or output must it produce?
  • Where does the process stall, fail, or become unclear in your organization?
  • Which inputs, evidence, ownership decisions, or handoffs are required to move to the next stage in your organizational context?
  • How does your specific cybersecurity-program maturity, industry, regulation, architecture, or operating model align with the Playbook?

Share feedback over email or book a research interview.

Get in touch