Open-Source AI tools are strong on security, but Governance remains human
A new study maps 21 open-source AI risk tools against 32 risk categories, including Promptfoo, Garak, PyRIT, NeMo Guardrails and Langfuse.
The ecosystem performs particularly well in AI testing, red teaming, content safety, data governance and post-deployment monitoring. But major gaps remain in board oversight, regulatory compliance, legal remedies and financial/market controls, areas software alone cannot solve.
The researchers therefore propose a four-layer architecture: technical controls → observability & operations → organizational governance → regulatory & market controls.
Open-source AI security tooling is therefore powerful, but responsible AI still requires governance and human oversight.

