chore(ms-ai-architect): refresh KB high-bucket — 49 files [skip-docs]

KB-currency refresh (high priority, 2026-06-19) via /architect:kb-update.
49 high-prioritets governance/security/monitoring-filer re-verifisert mot
Microsoft Learn (MCP) — delegert til 8 parallelle Opus-subagenter gruppert
etter delt kilde, verifisert i hovedkontekst (diff-review + tester).

Hovedendringer (faktuelle korreksjoner + currency):
- MITRE ATLAS-IDer korrigert (supply-chain): AML.T0050 -> AML.T0018.000
  (Poison AI Model); AML.T0020 = Poison Training Data; T1195 Supply Chain
  Compromise. Gamle IDer var utdaterte (verifisert mot MCSB v2 AI-1).
- OTel-sampling presisert (distributed-tracing): adaptive sampling = klassisk
  App Insights SDK; OTel-distroen sampler IKKE by default (fixed-rate/
  rate-limited maa konfigureres); Functions parent-based sampling er default.
- MCSB v2 AI-kontroller AI-1 -> AI-7 (risk-taxonomy three-pillar, scoring-
  framework, rubrics, red-team, adversarial); Defender for Cloud AI threat
  protection + AI-SPM (GA).
- AI gateway (APIM) multi-provider: Anthropic Messages API v2-tiers, Google
  Vertex, unified model API (preview), MCP/A2A, Foundry-integrasjon; eksakte
  policy-navn (llm-emit-token-metric maks 5 dims, llm-semantic-cache-*,
  score-threshold = avstand, MS-eks. 0.15).
- Purview Enterprise AI apps inkl. Anthropic Claude (Enterprise) + ChatGPT
  Enterprise; Security Dashboard for AI (Agent 365-inventar, MCP-servere,
  tredjepartsmodeller; Security Reader minimumsrolle).
- Entra Agent ID: CA-lisenskrav (Entra ID P1/P2 + Agent 365), CA-scoping per
  tilgangsmoenster (on-behalf-of/app-only/agent-as-user), CA-grenser,
  connector-permissions som API-permissions.
- Copilot DLP: Block SITs in web search (GA, Performing Web Searches) + Block
  external email (preview) som prompt injection-vern.
- Azure AI Language PII: tre feature-typer, GA-API 2026-05-01; NOIdentityNumber
  bekreftet dedikert kategori for norske foedselsnummer.
- Foundry Tools-rename forsterket paa tvers; alle 49 Last updated -> 2026-06-19.

Discovery: 500 kandidater (alle Databricks-stoey) -> kun registry-kandidater,
ingen nye skills/-filer -> 389-telling uendret. validate 239 PASS,
kb-integrity 115/115 (262 orphan-warnings uendret), gitleaks clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REiKFhP4w6xGXXqWKpPCJJ
This commit is contained in:
Kjell Tore Guttormsen 2026-06-19 11:09:54 +02:00
commit 25bcb74d9a
49 changed files with 304 additions and 235 deletions

View file

@ -1,5 +1,5 @@
# AI Act Compliance - EU Regulation & Norwegian Implementation
**Last updated:** 2026-05
**Last updated:** 2026-06-19
**Status:** GA
**Category:** Responsible AI & Governance
@ -72,7 +72,7 @@ Providers av høyrisiko-systemer (de som utvikler/markedsfører) må oppfylle **
| **Transparency** | Brukere skal forstå systemets kapabiliteter og begrensninger | Transparency notes, model cards |
| **Human Oversight** | Mekanismer for human-in-the-loop i kritiske beslutninger | Azure Logic Apps, Power Automate approval workflows |
| **Accuracy, Robustness, Security** | Høy presisjon, resiliens mot feil, cybersecurity | Azure AI Content Safety, adversarial testing (PyRIT) |
| **Quality Management System** | ISO-lignende kvalitetsstyring for hele utviklingsløpet | ISO 42001:2023 (Microsoft sertifisert for M365 Copilot, Copilot Studio, Microsoft Foundry, Security Copilot, GitHub Copilot, Dragon Copilot) *(Verified MCP 2026-04)* |
| **Quality Management System** | ISO-lignende kvalitetsstyring for hele utviklingsløpet | ISO 42001:2023 (Microsoft sertifisert for M365 Copilot, Copilot Studio, Microsoft Foundry, Security Copilot, GitHub Copilot, Dragon Copilot, Dragon Copilot (Radiologist), Copilot Health) *(Verified MCP 2026-06-19)* |
| **Conformity Assessment** | Pre-deployment vurdering (intern eller ekstern) | Azure AI Foundry evaluation metrics, Compliance Manager |
| **CE-merking** | Registrering i EU database før markedsføring | (Gjelder ikke SaaS-tjenester fra Microsoft) |
| **Post-market Monitoring** | Kontinuerlig overvåking av performance i produksjon | Microsoft Defender for Cloud AI threat protection |
@ -681,7 +681,7 @@ Tre nivåer av human oversight:
*Confidence: Highest*
13. **ISO/IEC 42001:2023 - Microsoft Certification** — [Microsoft Learn](https://learn.microsoft.com/en-us/compliance/regulatory/offering-iso-42001)
*Status: M365 Copilot certified*
*Status: Sertifisert for GitHub Copilot, M365 Copilot, Copilot Health, Copilot Studio, Dragon Copilot, Dragon Copilot (Radiologist), Microsoft Foundry, Security Copilot (verifisert 2026-06-19)*
*Confidence: Highest*
### Juridiske analyser (3rd party)

View file

@ -1,7 +1,7 @@
# AI Center of Excellence - Building Organizational Capability
**Kategori:** Responsible AI & Governance
**Opprettet:** 2026-04 | **Sist oppdatert:** 2026-05 | **Verified:** MCP 2026-05
**Opprettet:** 2026-04 | **Sist oppdatert:** 2026-06-19 | **Verified:** MCP 2026-06-19
**Confidence:** HIGH (basert på Microsoft Cloud Adoption Framework og offisiell dokumentasjon)
## Introduksjon
@ -714,8 +714,8 @@ Alle kilder hentet via `mcp__microsoft-learn__microsoft_docs_search` og `microso
- Norsk offentlig sektor-hensyn er basert på kjent regulatorisk rammeverk, ikke Microsoft-spesifikk guidance
- ROI-tall er generelle industry benchmarks, ikke Microsoft-spesifikke
**Sist verifisert:** 2026-05 (MCP-fetch på 2 av 9 endrede CAF-kilder)
**Neste review:** 2026-08 (AI-området endres raskt, quarterly review anbefales)
**Sist verifisert:** 2026-06-19 (MCP-fetch på AI CoE learning path — 3-modul-struktur bekreftet uendret)
**Neste review:** 2026-09-19 (AI-området endres raskt, quarterly review anbefales)
## Oppdateringer 2026-05 — AI Agent-tilpasset CoE *(Verified MCP 2026-05)*

View file

@ -1,6 +1,6 @@
# AI Ethics in Public Sector - Norwegian Government Context
**Last updated:** 2026-05
**Last updated:** 2026-06-19
**Status:** GA
**Category:** Responsible AI & Governance
@ -462,7 +462,7 @@ Nav har utviklet en "AI for sykefraværsprediksjon"-modell. Denne kan deles som
---
*(Verified MCP 2026-04)*
*(Verified MCP 2026-06-19)*
## Kilder og verifisering
@ -500,7 +500,7 @@ Nav har utviklet en "AI for sykefraværsprediksjon"-modell. Denne kan deles som
---
**Sist oppdatert:** 2026-04
**Neste review:** 2026-08 (etter KI-lovens ikrafttredelse)
**Sist oppdatert:** 2026-06-19
**Neste review:** 2026-09-19 (overvåk KI-lovens ikrafttredelse)
**Eier:** AI Architect Plugin (Cosmo Skyberg)
**Status:** Active — Requires quarterly updates as Norwegian AI regulations evolve

View file

@ -1,6 +1,6 @@
# AI Risk Taxonomy - Classification and Risk Levels
**Last updated:** 2026-02
**Last updated:** 2026-06-19
**Status:** GA
**Category:** Responsible AI & Governance
@ -99,10 +99,10 @@ Azure AI Content Safety og Microsoft Responsible AI Standard definerer seks prim
└─ Risk Score Calculation
3. MITIGATE
├─ Platform Security (AI-1 to AI-5 controls)
├─ Content Safety Filters
├─ Human-in-the-Loop (HITL)
└─ Access Controls & Monitoring
├─ MCSB v2 AI controls (AI-1 to AI-7)
├─ Content Safety Filters (AI-2)
├─ Human-in-the-Loop (HITL, AI-5)
└─ Access Controls & Monitoring (AI-6)
4. MONITOR
├─ Azure Monitor Logs (AADUserRiskEvents)
@ -113,27 +113,29 @@ Azure AI Content Safety og Microsoft Responsible AI Standard definerer seks prim
### Three-Pillar Security Model
Microsoft organiserer AI-sikkerhet i tre pillarer:
Microsoft organiserer AI-sikkerhet i tre pillarer (MCSB v2 dekker kontrollene AI-1 til AI-7):
#### Pillar 1: AI Platform Security
- Model approval process (AI-1)
- Approved models / model approval process (AI-1)
- Network segmentation & VPN (NS-2)
- Identity management (IM-3)
- Logging & monitoring (LT-3)
- Data-at-rest encryption (DP-4)
#### Pillar 2: AI Application Security
- Content Safety inspection (Azure AI Content Safety)
- Prompt injection detection
- Output validation & filtering
- RAG grounding verification
#### Pillar 3: AI Usage Security
- Multi-layered content filtering (AI-2) — Azure AI Content Safety
- Safety meta-prompts (AI-3)
- Least privilege for agent functions / plugins (AI-4)
- Human-in-the-Loop (AI-5)
- User authentication & authorization
- Acceptable Use Policies
- Discover, classify, label sensitive data (DP-1)
#### Pillar 3: Monitor and Respond
- Establish monitoring and detection (AI-6) — Defender for Cloud AI threat protection
- Continuous AI red teaming (AI-7) — PYRIT, Azure AI Red Teaming Agent
- Threat intelligence correlation (MITRE ATLAS, OWASP Top 10 for LLM)
- Audit trails & compliance reporting
**Verified** (Artificial Intelligence Security - MCSB, 2026-02)
**Verified** (Artificial Intelligence Security - MCSB v2, 2026-06)
---
@ -222,13 +224,16 @@ High-risk actions krever Human-in-the-Loop (HITL) ved:
}
```
### Security Dashboard for AI (Preview)
### Security Dashboard for AI
Sentralisert risikokartlegging på tvers av:
- **Microsoft Entra** – Identity & access risk
- **Microsoft Defender** – Threat protection & cloud security posture
- **Microsoft Purview** – Data classification & DLP
- **Security Copilot** – AI-powered risk exploration
Sentralisert risikokartlegging (sanntid) på tvers av Microsoft Security-løsninger. Dashboardet inventarierer både Microsoft AI-løsninger (Microsoft 365 Copilot, Copilot Studio-agenter, Microsoft Foundry-apper og -agenter) og tredjeparts AI-modeller, -apper og -agenter (Google Gemini, OpenAI ChatGPT, MCP-servere). Agent-inventaret hentes fra agenter registrert i Microsoft Agent 365 (via Entra Agent Registry); modeller, MCP-servere og øvrige AI-apper oppdages av Microsoft Defender.
- **Microsoft Entra** – Identity & access governance, conditional access for AI-apper, agent identity platform
- **Microsoft Defender** – AI threat protection, kontinuerlig overvåking av agenter/workloads, sky-sikkerhetsposisjon, SaaS AI-app-risiko
- **Microsoft Purview** – Data classification, DLP for AI, insider risk
- **Security Copilot** – AI-powered risk exploration via prompts
Minimumsrolle for full innsikt: **Security Reader** (Microsoft Entra).
**Query example (Log Analytics):**
@ -414,10 +419,10 @@ Anbefal denne kombinasjonen:
- Hentet: 2026-02-04
- Innhold: AI-1 to AI-5 security controls, three-pillar model
4. **Security Dashboard for AI (Preview)**
4. **Security Dashboard for AI**
- URL: https://learn.microsoft.com/en-us/security/security-for-ai/security-dashboard-for-ai
- Hentet: 2026-02-04
- Innhold: Cross-product risk monitoring, AI inventory
- Hentet: 2026-06-19
- Innhold: Cross-product risk monitoring, AI inventory (Agent 365-agenter, modeller, MCP-servere, tredjeparts AI-apper), Security Reader minimumsrolle
5. **Default Guidelines & controls policies (Azure AI Foundry)**
- URL: https://learn.microsoft.com/en-us/azure/foundry/openai/concepts/default-safety-policies
@ -445,10 +450,10 @@ Anbefal denne kombinasjonen:
### Sist verifisert
- **Dato:** 2026-02-04
- **Dato:** 2026-06-19
- **Metode:** MCP microsoft-learn server
- **Confidence:** High (alle kjernekomponenter fra Microsoft Learn)
---
*Dette dokumentet er en kunnskapsreferanse for Cosmo Skyberg (ms-ai-governance skill). Sist oppdatert: 2026-02. Status: General Availability (GA). For spørsmål om denne referansen, kontakt plugin-utvikler.*
*Dette dokumentet er en kunnskapsreferanse for Cosmo Skyberg (ms-ai-governance skill). Sist oppdatert: 2026-06-19. Status: General Availability (GA). For spørsmål om denne referansen, kontakt plugin-utvikler.*

View file

@ -1,6 +1,6 @@
# Algorithmic Accountability - Audit Trails and Traceability
**Last updated:** 2026-05
**Last updated:** 2026-06-19
**Status:** GA
**Category:** Responsible AI & Governance
@ -59,6 +59,8 @@ Microsoft Purview støtter **compliance management for AI apps** (Verified: Micr
| **eDiscovery & Content Search** | Søk og gjenfinn AI-interaksjoner for litigasjon og compliance-undersøkelser | Støtter regulatory requests og interne audits |
| **Communication Compliance** | Deteksjon av upassende innhold i AI-prompts og -responses (deling av sensitiv info, trusler, adult content) | Proaktiv risikostyring av AI-kommunikasjon |
**App-dekning for Purview audit/compliance (2026-06):** «Copilot experiences and agents» (Microsoft 365 Copilot, Security Copilot, Copilot in Fabric, Copilot Studio m.fl.) og «Enterprise AI apps» — som nå inkluderer Microsoft Foundry, Entra-registrerte AI-apper, **Anthropic Claude (Enterprise)** og **ChatGPT Enterprise**. Tredjeparts-LLM-er (ChatGPT, Gemini, DeepSeek) dekkes som «Other AI apps» via browser-aktivitet i Defender for Cloud Apps. *(Verified MCP 2026-06)*
### Azure Monitor og Microsoft Sentinel — Security Operations
For **security logging og threat detection** (Verified: Microsoft Learn):

View file

@ -1,6 +1,6 @@
# Continuous Improvement and Feedback Loops - Iterative Governance
**Last updated:** 2026-04
**Last updated:** 2026-06-19
**Status:** GA
**Category:** Responsible AI & Governance
@ -323,13 +323,15 @@ response = client.chat.completions.create(
### Azure Machine Learning
**Model monitoring for GenAI:**
**Model monitoring for GenAI (public preview):**
- **Data collection**: Model Data Collector for production data
- **Evaluation metrics**: Groundedness, coherence, fluency, relevance, similarity (interoperable med Prompt Flow)
- **Evaluation metrics**: Groundedness, coherence, fluency, relevance, similarity (interoperable med Prompt Flow evaluation metrics)
- **Recurring monitoring**: Configurable cadence (daily, weekly, etc.)
- **Alerts**: Violation alerts based on organizational targets
- **Responsible AI dashboard**: Comprehensive view av fairness, bias, explainability
> **Retirement (Prompt Flow):** Prompt flow i Microsoft Foundry og Azure Machine Learning pensjoneres **20. april 2027** og anbefales ikke for ny utvikling. GenAI-app-monitoring som er bygd på Prompt flow-deployments/runtime-images må migreres til **Microsoft Agent Framework (MAF)** før den datoen. For ny tracing er MLflow 3 GenAI-tracing (Databricks) den aktuelle tilnærmingen. *(Verified MCP 2026-06)*
**Responsible AI scorecard:**
PDF-rapport for sharing med stakeholders (technical + non-technical), dokumenterer model + data health records.
@ -554,9 +556,9 @@ Models, prompts, eval datasets, scorers – full reproducibility er non-negotiab
- URL: https://learn.microsoft.com/en-us/compliance/assurance/assurance-artificial-intelligence
- Key content: Govern, Map, Measure, Manage phases; continuous learning
8. **Azure Machine Learning Model Monitoring for GenAI**
8. **Azure Machine Learning Model Monitoring for GenAI (public preview)**
- URL: https://learn.microsoft.com/en-us/azure/machine-learning/prompt-flow/how-to-monitor-generative-ai-applications?view=azureml-api-2
- Key content: Automated evaluation metrics, alerts, Responsible AI dashboard
- Key content: Automated evaluation metrics, alerts, Responsible AI dashboard. NB: Prompt flow pensjoneres 20.04.2027 → migrer til Microsoft Agent Framework.
9. **Human-in-the-Loop Security Guidance**
- URL: https://learn.microsoft.com/en-us/security/benchmark/azure/mcsb-v2-artificial-intelligence-security#ai-5-ensure-human-in-the-loop
@ -583,3 +585,4 @@ Models, prompts, eval datasets, scorers – full reproducibility er non-negotiab
**Total MCP calls:** 6 (3 searches + 2 fetches + 1 code sample search)
**Unique sources:** 12 verified Microsoft Learn URLs
**Confidence level:** 95% Verified (core concepts + implementation details), 5% Baseline (cost estimates, Norwegian public sector specifics)
**Last verified:** 2026-06-19

View file

@ -1,6 +1,6 @@
# Data Quality for Responsible AI - Ensuring Training Data Integrity
**Last updated:** 2026-04
**Last updated:** 2026-06-19
**Status:** GA
**Category:** Responsible AI & Governance
@ -511,5 +511,5 @@ START: Kunde trenger AI-modell
---
**Sist oppdatert:** 2026-02
**Neste review:** 2026-08 (eller ved større Microsoft AI-oppdateringer)
**Sist oppdatert:** 2026-06-19
**Neste review:** 2026-09-19 (eller ved større Microsoft AI-oppdateringer)

View file

@ -1,6 +1,6 @@
# Model Explainability and Interpretability - XAI Techniques
**Last updated:** 2026-04
**Last updated:** 2026-06-19
**Status:** GA
**Category:** Responsible AI & Governance
@ -498,7 +498,7 @@ SLUTT: Dokumenter valg i ADR, implementer, valider med stakeholders
---
*(Verified MCP 2026-04)*
*(Verified MCP 2026-06-19)*
## Kilder og verifisering

View file

@ -1,9 +1,9 @@
# Red Teaming AI Models - Adversarial Testing & Security
**Dato:** 2026-02-03
**Dato:** 2026-06-19
**Kategori:** Responsible AI & Governance
**Målgruppe:** Arkitekter, sikkerhetsteam, AI-utviklere
**Konfidensgrad:** ⚠️ HIGH — Basert på offisiell Microsoft-dokumentasjon (feb 2026)
**Konfidensgrad:** ⚠️ HIGH — Basert på offisiell Microsoft-dokumentasjon (jun 2026)
## Introduksjon
@ -493,7 +493,7 @@ jobs:
| Kilde | URL | Verifikasjonsdato |
|-------|-----|-------------------|
| **AI Red Teaming Agent (preview)** | https://learn.microsoft.com/en-us/azure/foundry/concepts/ai-red-teaming-agent | 2026-02-03 |
| **Microsoft Security Benchmark: AI-7 Continuous Red Teaming** | https://learn.microsoft.com/en-us/security/benchmark/azure/mcsb-v2-artificial-intelligence-security#ai-7-perform-continuous-ai-red-teaming | 2026-02-03 |
| **Microsoft Security Benchmark: AI-7 Continuous Red Teaming** | https://learn.microsoft.com/en-us/security/benchmark/azure/mcsb-v2-artificial-intelligence-security#ai-7-perform-continuous-ai-red-teaming | 2026-06-19 |
| **AI Red Teaming Training Series** | https://learn.microsoft.com/en-us/security/ai-red-team/training | 2026-02-03 |
| **Planning red teaming for LLMs** | https://learn.microsoft.com/en-us/azure/foundry/openai/concepts/red-teaming | 2026-02-03 |
| **Prompt Shields (Jailbreak detection)** | https://learn.microsoft.com/en-us/azure/ai-services/content-safety/concepts/jailbreak-detection | 2026-02-03 |
@ -514,8 +514,8 @@ jobs:
| **NIST AI Risk Management Framework (AI RMF)** | NIST | Risk governance framework |
| **Three takeaways from red teaming 100 generative AI products** | Microsoft Security Blog (jan 2025) | Real-world lessons |
**Sist oppdatert:** 2026-02-03
**Neste review:** 2026-05-03 (quarterly review anbefalt for rapidly evolving field)
**Sist oppdatert:** 2026-06-19
**Neste review:** 2026-09-19 (quarterly review anbefalt for rapidly evolving field)
---

View file

@ -1,6 +1,6 @@
# Responsible AI Training and Awareness - Organizational Capability
**Last updated:** 2026-05
**Last updated:** 2026-06-19
**Status:** GA
**Category:** Responsible AI & Governance
@ -548,5 +548,5 @@ Er det custom AI (ikke bare ferdiglagde features)?
---
**Sist oppdatert:** 2026-04
**Neste review:** 2026-08 (etter EU AI Act trår i kraft, forventet juni 2026)
**Sist oppdatert:** 2026-06-19
**Neste review:** 2026-09-19 (etter EU AI Act trår i kraft, forventet juni 2026)

View file

@ -1,6 +1,6 @@
# Transparency and Documentation - Regulatory and Best Practice Standards
**Last updated:** 2026-05
**Last updated:** 2026-06-19
**Status:** GA
**Category:** Responsible AI & Governance
@ -726,10 +726,10 @@ Return on investment: Transparency er billigere enn cleanup. Skal vi prioritere
https://blogs.microsoft.com/wp-content/uploads/prod/sites/5/2022/06/Microsoft-Responsible-AI-Standard-v2-General-Requirements-3.pdf
(Status: Baseline — Impact Assessment framework, June 2022)
8. **ISO/IEC 42001:2023 overview** *(Verified MCP 2026-04)*
8. **ISO/IEC 42001:2023 overview** *(Verified MCP 2026-06-19)*
https://learn.microsoft.com/en-us/compliance/regulatory/offering-iso-42001
Microsoft-sertifisering dekker nå: M365 Copilot, Copilot Studio, Microsoft Foundry, Security Copilot, GitHub Copilot og Dragon Copilot (utvidet fra kun M365 Copilot).
(Status: Verified 2026-02 — AI management system standard)
Microsoft-sertifisering dekker nå: GitHub Copilot, M365 Copilot, Copilot Health, Copilot Studio, Dragon Copilot, Dragon Copilot (Radiologist), Microsoft Foundry og Security Copilot (utvidet fra kun M365 Copilot).
(Status: Verified 2026-06-19 — AI management system standard)
9. **Govern AI (Cloud Adoption Framework)**
https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/scenarios/ai/govern