AI Security · Chapter 04

AI Governance: NIST AI RMF, ISO/IEC 42001 & EU AI Act

AI Governance Frameworks — NIST / ISO / EU Regulatory Landscape

Khung quản trị AI toàn cầu: NIST AI RMF 1.0, ISO/IEC 42001:2023, EU AI Act 2024, và AI Bill of Rights. Triển khai kiểm toán thuật toán và đánh giá công bằng thực tế với SHAP, LIME, Fairlearn.

Mục tiêu chương / Learning objectives

1. NIST AI Risk Management Framework 1.0

NIST AI RMF 1.0 (tháng 1/2023) là khung tự nguyện giúp tổ chức quản lý rủi ro AI một cách có hệ thống. Không phải tiêu chuẩn bắt buộc nhưng được DOD, CISA, và nhiều tập đoàn Fortune 500 áp dụng làm baseline.

GOVERN — Quản trị

Thiết lập chính sách, quy trình, trách nhiệm và văn hóa tổ chức về AI risk. Bao gồm: AI risk tolerance definition, stakeholder engagement, workforce training, governance structure (AI ethics board, CISO, DPO phối hợp).

GV-1.1 đến GV-6.2 (29 subcategories)

MAP — Ánh xạ

Xác định và phân loại context, stakeholder impacts, và AI risks. Bao gồm: use case categorization, impact assessment, bias identification, data provenance documentation, third-party AI risk mapping.

MP-1.1 đến MP-5.2 (22 subcategories)

MEASURE — Đo lường

Phân tích, đánh giá và theo dõi AI risks sử dụng metrics định lượng. Bao gồm: fairness metrics (disparate impact, equalized odds), robustness testing, privacy metrics (differential privacy epsilon), explainability scoring (SHAP values).

MS-1.1 đến MS-4.1 (24 subcategories)

MANAGE — Quản lý

Ưu tiên và xử lý AI risks, bao gồm response và recovery. Bao gồm: risk prioritization matrix, incident response plan, model decommission criteria, continuous monitoring dashboard, stakeholder communication protocol.

MG-1.1 đến MG-4.2 (18 subcategories)

NIST AI RMF Trustworthy AI Characteristics

Accountable & Transparent Explainable & Interpretable Fair with Managed Bias Privacy Enhanced Reliable & Robust Safe Secure & Resilient

2. ISO/IEC 42001:2023 — Hệ Thống Quản Lý AI

ISO/IEC 42001:2023 là tiêu chuẩn quản lý hệ thống AI đầu tiên trên thế giới, được ban hành tháng 12/2023. Có cấu trúc Annex SL tương tự ISO 27001, cho phép tích hợp (integrated management system).

Điều khoản Nội dung Tương đồng ISO 27001
4Context of the organization — AI use context, stakeholders, external/internal issuesClause 4
5Leadership — Top management commitment, AI policy, roles and responsibilitiesClause 5
6Planning — AI risk assessment, AI impact assessment, AI objectives and planningClause 6
8Operation — AI system development lifecycle, data management, human oversight mechanismsClause 8
9Performance evaluation — Monitoring AI system, internal audit, management reviewClause 9
10Improvement — Nonconformity, corrective action, continual improvementClause 10
Annex AControls: 38 controls trong 9 domains (AI policy, data quality, explainability, human oversight...)Annex A (93 controls)

3. EU AI Act 2024 — Luật AI Châu Âu

EU AI Act được thông qua tháng 3/2024, có hiệu lực từ 8/2024, áp dụng đầy đủ từ 2026. Là luật AI toàn diện đầu tiên trên thế giới với hệ thống phân loại rủi ro 4 cấp độ.

Không chấp nhận

Prohibited AI (Bị cấm hoàn toàn)

Hệ thống social scoring của chính phủ, biometric surveillance thời gian thực ở không gian công cộng (ngoại trừ law enforcement có warrant), emotional recognition tại nơi làm việc/trường học, subliminal manipulation. Phạt: lên đến €35M hoặc 7% doanh thu toàn cầu.

Rủi ro cao

High-Risk AI (Yêu cầu tuân thủ nghiêm ngặt)

AI trong: cơ sở hạ tầng quan trọng, giáo dục/đào tạo nghề, tuyển dụng/quản lý nhân sự, dịch vụ thiết yếu (tín dụng, bảo hiểm), thực thi pháp luật, quản lý biên giới, tư pháp. Yêu cầu: conformity assessment, CE marking, đăng ký EU AI database, human oversight, risk management system. Phạt: lên đến €15M hoặc 3% doanh thu.

Rủi ro hạn chế

Limited Risk (Transparency Obligation)

Chatbot, deepfake content generation, emotion recognition. Yêu cầu: Phải thông báo rõ ràng người dùng đang tương tác với AI (không được giả vờ là người thật). Deepfake phải được gán nhãn rõ ràng. Phạt: lên đến €7.5M hoặc 1.5%.

Rủi ro tối thiểu

Minimal Risk (Tự nguyện code of conduct)

Phần lớn AI applications: spam filter, AI trong game, AI recommender system không thuộc high-risk domains. Khuyến khích nhưng không bắt buộc áp dụng voluntary code of conduct và EU AI Pact.

General Purpose AI (GPAI) — Quy định riêng

GPAI models (Foundation Models như GPT-4, Claude, Gemini) có quy định riêng biệt trong EU AI Act. GPAI với systemic risk (trên 10^25 FLOP training compute) phải: adversarial testing, serious incident reporting, cybersecurity measures. Tất cả GPAI: copyright transparency, technical documentation.

4. AI Bill of Rights (Mỹ) & PDPA/Luật An Ninh Mạng (Việt Nam)

AI Bill of Rights — White House 2022

  • Safe & Effective Systems: Testing, monitoring, opt-out provisions
  • Algorithmic Discrimination Protections: Fairness, non-discrimination by design
  • Data Privacy: Consent, minimal data collection, right to deletion
  • Notice & Explanation: Disclosure when AI is used, plain-language explanation
  • Human Alternatives: Escalation pathway, human override capability

Không phải luật pháp — guidelines tự nguyện, nhưng ảnh hưởng đến federal procurement.

Việt Nam: Khung Pháp Lý AI (2024-2026)

  • Nghị định 13/2023/NĐ-CP: Bảo vệ dữ liệu cá nhân — áp dụng cho AI xử lý PII
  • Luật An Ninh Mạng 2018: Yêu cầu localization data, kiểm soát nội dung AI sinh
  • Chiến lược AI Quốc gia 2021-2030: Ưu tiên phát triển AI có trách nhiệm
  • Nghị quyết 52-NQ/TW: Chủ động tham gia cách mạng công nghiệp 4.0
  • EU Adequacy Decision (đang đàm phán): Tác động xuất khẩu AI/data sang EU

LAB: Thực Hành / Hands-on Labs

01

Lab 1 — SHAP Explainability cho Loan Approval Model

Nền tảngUbuntu 22.04
ToolsPython, shap, scikit-learn
Thời gian30 phút
pip install shap scikit-learn pandas numpy import numpy as np, pandas as pd, shap from sklearn.ensemble import GradientBoostingClassifier from sklearn.model_selection import train_test_split np.random.seed(42) n = 1000 df = pd.DataFrame({ 'income': np.random.normal(50000, 20000, n).clip(10000, 200000), 'credit_score': np.random.normal(650, 80, n).clip(300, 850), 'debt_ratio': np.random.uniform(0.1, 0.8, n), 'employment_years': np.random.exponential(5, n).clip(0, 30), }) df['approved'] = ((df.credit_score > 620) & (df.debt_ratio < 0.5) & (df.income > 30000)).astype(int) X = df.drop('approved', axis=1) y = df['approved'] X_train, X_test, y_train, y_test = train_test_split(X, y, test_size=0.2, random_state=42) model = GradientBoostingClassifier(n_estimators=100, random_state=42) model.fit(X_train, y_train) print(f"Accuracy: {model.score(X_test, y_test):.3f}") explainer = shap.TreeExplainer(model) shap_values = explainer.shap_values(X_test) mean_shap = np.abs(shap_values).mean(axis=0) importance_df = pd.DataFrame({'feature': X.columns, 'shap': mean_shap}).sort_values('shap', ascending=False) print("\nFeature importance (SHAP):") print(importance_df.to_string(index=False))

Kết quả đầu ra mẫu

Accuracy: 0.940
Feature importance (SHAP):
feature shap
credit_score 0.284
debt_ratio 0.220
income 0.190
employment_years 0.039
→ SHAP cung cấp explanation kiểm toán được — đáp ứng "right to explanation" EU AI Act.
02

Lab 2 — Fairness Audit với Fairlearn (Disparate Impact)

Nền tảngUbuntu 22.04
Toolsfairlearn, scikit-learn
Thời gian25 phút
pip install fairlearn from fairlearn.metrics import MetricFrame, selection_rate from sklearn.metrics import accuracy_score import numpy as np gender = np.random.choice(['male', 'female'], size=len(X_test), p=[0.55, 0.45]) X_test_biased = X_test.copy() X_test_biased.loc[gender == 'female', 'income'] *= 0.85 y_pred = model.predict(X_test_biased) mf = MetricFrame(metrics={'accuracy': accuracy_score, 'selection_rate': selection_rate}, y_true=y_test, y_pred=y_pred, sensitive_features=gender) print(mf.by_group.round(4)) di = mf.by_group['selection_rate'].min() / mf.by_group['selection_rate'].max() print(f"Disparate Impact Ratio: {di:.4f}") if di < 0.8: print("BIAS DETECTED: Below EEOC 4/5ths rule threshold!")

Kết quả đầu ra mẫu

accuracy selection_rate
female 0.8920 0.6124
male 0.9412 0.8043
Disparate Impact Ratio: 0.7614
BIAS DETECTED: Below EEOC 4/5ths rule threshold!
→ Gender bias phát hiện — vi phạm EU AI Act Art.10 (data quality) tiềm năng.
03

Lab 3 — AI Risk Register theo NIST AI RMF

Nền tảngPython
ToolsPython pandas, tabulate
Thời gian20 phút
pip install pandas tabulate import pandas as pd from tabulate import tabulate risks = [ {"ID": "AI-R-001", "Category": "Data Quality", "Risk": "Biased training data causing discriminatory decisions", "Likelihood": 4, "Impact": 5, "Owner": "ML Team"}, {"ID": "AI-R-002", "Category": "Security", "Risk": "Prompt injection in customer-facing LLM chatbot", "Likelihood": 5, "Impact": 4, "Owner": "Security Team"}, {"ID": "AI-R-003", "Category": "Compliance", "Risk": "EU AI Act non-compliance for HR screening tool", "Likelihood": 3, "Impact": 5, "Owner": "Legal/DPO"}, {"ID": "AI-R-004", "Category": "Privacy", "Risk": "Model memorization of PII in training data", "Likelihood": 3, "Impact": 4, "Owner": "Data Team"}, ] df = pd.DataFrame(risks) df["Score"] = df["Likelihood"] * df["Impact"] df["Priority"] = df["Score"].apply(lambda x: "CRITICAL" if x >= 20 else ("HIGH" if x >= 12 else "MEDIUM")) df = df.sort_values("Score", ascending=False) print(tabulate(df[["ID","Category","Score","Priority","Owner"]], headers="keys", tablefmt="grid", showindex=False))

Kết quả đầu ra mẫu

+----------+------------+-------+----------+---------------+
| ID | Category | Score | Priority | Owner |
+==========+============+=======+==========+===============+
| AI-R-001 | Data Qual | 20 | CRITICAL | ML Team |
| AI-R-002 | Security | 20 | CRITICAL | Security Team |
| AI-R-003 | Compliance | 15 | HIGH | Legal/DPO |
| AI-R-004 | Privacy | 12 | HIGH | Data Team |
+----------+------------+-------+----------+---------------+
04

Lab 4 — EU AI Act Risk Classifier

Nền tảngPython
ToolsPython 3.11 stdlib
Thời gian15 phút
def classify_eu_ai(use_case: str, domain: str, affects_rights: bool) -> dict: prohibited = ["social scoring", "subliminal manipulation", "real-time biometric"] high_risk = ["employment", "credit", "healthcare", "education", "law enforcement"] limited = ["chatbot", "deepfake", "emotion recognition"] uc = use_case.lower() if any(k in uc for k in prohibited): return {"risk": "PROHIBITED", "action": "Do not deploy. Fine up to EUR 35M."} if domain in high_risk or affects_rights: return {"risk": "HIGH", "action": "Conformity assessment + CE marking required."} if any(k in uc for k in limited): return {"risk": "LIMITED", "action": "Disclose AI nature to users."} return {"risk": "MINIMAL", "action": "Voluntary code of conduct."} tests = [ ("HR candidate screening tool", "employment", True), ("Customer service chatbot", "retail", False), ("Loan approval decision support", "credit", True), ("Email spam filter", "general", False), ] for uc, domain, afr in tests: r = classify_eu_ai(uc, domain, afr) print(f"{uc[:45]}: [{r['risk']}] — {r['action']}")

Kết quả đầu ra mẫu

HR candidate screening tool: [HIGH] — Conformity assessment + CE marking required.
Customer service chatbot: [LIMITED] — Disclose AI nature to users.
Loan approval decision support: [HIGH] — Conformity assessment + CE marking required.
Email spam filter: [MINIMAL] — Voluntary code of conduct.

Business Scenario

VNG Corporation — Xuất khẩu AI content moderation sang EU market

VNG phát triển AI-powered content moderation platform và đang đàm phán hợp đồng với mạng xã hội Đức (EU market). Platform phân tích nội dung người dùng để phát hiện hate speech và misinformation.

EU AI Act phân loại: Content moderation ảnh hưởng đến fundamental rights (freedom of expression) = HIGH RISK theo Annex III. Đồng thời thuộc phạm vi EU DSA nếu >45M user EU.

Yêu cầu tuân thủ: (1) Conformity assessment bởi notified body, (2) Technical documentation Art.11, (3) Human oversight — appeal process khi nội dung bị flag sai, (4) Accuracy và robustness metrics, (5) Đăng ký EU AI database, (6) CE marking. Chi phí ước tính: €200K-500K cho SME bao gồm legal review, 3rd party audit, documentation.

Câu hỏi ôn tập / Quiz

  1. NIST AI RMF có 4 chức năng. Giải thích chức năng MAP khác gì so với MEASURE? Cho ví dụ một activity thuộc mỗi chức năng.
  2. ISO/IEC 42001:2023 Annex A có bao nhiêu controls? Kể 3 controls liên quan trực tiếp đến AI security.
  3. Startup Việt Nam xây dựng AI tool phân tích CV tự động và muốn bán cho công ty Pháp. Theo EU AI Act, hệ thống này thuộc risk level nào? Liệt kê 3 yêu cầu bắt buộc.
  4. Disparate Impact Ratio là gì? Theo EEOC 4/5ths rule, khi nào model được coi là có adverse impact?
  5. SHAP values giải thích predictions như thế nào? Tại sao SHAP quan trọng hơn feature importance truyền thống cho algorithmic auditing?
  6. EU AI Act yêu cầu gì đối với GPAI models với systemic risk (trên 10^25 FLOP)? Kể 3 yêu cầu cụ thể.

Thông tin chương

Thuộc lộ trìnhPhase 5 · AI Security
Quý phát hànhQ3/2026
Ngày cập nhật24/05/2026
Tác giảTrần Văn Hòa (MCT)
Phiên bảnv1.0
Chứng chỉ liên quanAIGP (IAPP), ISO 42001 Lead Auditor