Search papers, labs, and topics across Lattice.
This paper introduces a comprehensive lifecycle model for large language model (LLM) systems that prioritizes security analysis over operational efficiency, addressing critical gaps in existing frameworks. By delineating 32 stages across four core pipeline layers鈥擠ata, Model, Distribution, and Application鈥攁longside governance and LLMOps pillars, the authors highlight distinct security concerns often overlooked in traditional models. The findings reveal a misalignment in regulatory focus, where significant decisions are made in less visible development stages, underscoring the need for enhanced governance throughout the LLM lifecycle.
Security concerns in LLM development are often neglected, with critical decisions made in stages that regulators can't see.
Large language models are being integrated into critical infrastructure and enterprise workflows at unprecedented scale,yet the lifecycle frameworks governing their development and operations were designed for operational efficiency rather than security analysis. As a result, security-relevant activities such as data provenance verification, artifact signing, agentic permission control, and decommissioning are often left implicit or assumed to receive due care. Governance frameworks, in turn, organise requirements around risk levels or management processes without clearly linking them to the lifecycle stages where they apply. This paper addresses both deficiencies. We propose a lifecycle model for LLM systems that supports security analysis by structuring it around security-relevant boundaries rather than workflow optimisation. The model comprises 32 stages across four core pipeline layers (Data, Model, Distribution, Application), supported by a 12-stage LLMOps pillar and a 9-category governance pillar. Thirteen stages are introduced here as separate units because they expose distinct security concerns that existing frameworks do not clearly distinguish. A governance mapping synthesising the NIST AI RMF, the EU AI Act, and ISO/IEC 42001 reveals a structural property of the current regulatory landscape: governance evidence concentrates at deployment-facing stages, where systems are visible to regulators, while the most consequential decisions, data selection, alignment strategy, and capability boundaries, are made at development-facing stages, where regulatory visibility is lowest.