Paper Type
Complete
Abstract
The rapid adoption of large language models (LLMs) across industries has introduced significant security and governance challenges that extend beyond traditional IT vulnerabilities. This study conducts a systematic literature review following PRISMA 2020 guidelines to synthesize current evidence on LLM-related threats, organizational security risks, and mitigation strategies. A total of 45 peer-reviewed journal articles were analyzed from an initial dataset of 396 records. Findings reveal that LLM threats span the entire lifecycle, including data poisoning, prompt injection, privacy leakage, model extraction, and ecosystem-level vulnerabilities. When integrated into enterprise environments, these threats escalate into regulatory, operational, reputational, and compliance risks. Existing mitigation strategies emphasize defense-in-depth approaches across data, model, interaction, and ecosystem layers; however, governance frameworks remain fragmented. This study develops an integrative framework linking LLM-specific threats, enterprise risk exposure, and layered countermeasures. The findings contribute to Information Systems theory and provide actionable insights for responsible AI cybersecurity management.
Paper Number
1930
Recommended Citation
Diaz Parra, Raul, "Security Risks of Large Language Models: A Systematic Literature Review" (2026). AMCIS 2026 Proceedings. 45.
https://aisel.aisnet.org/amcis2026/sig_sec/sig_sec/45
Security Risks of Large Language Models: A Systematic Literature Review
The rapid adoption of large language models (LLMs) across industries has introduced significant security and governance challenges that extend beyond traditional IT vulnerabilities. This study conducts a systematic literature review following PRISMA 2020 guidelines to synthesize current evidence on LLM-related threats, organizational security risks, and mitigation strategies. A total of 45 peer-reviewed journal articles were analyzed from an initial dataset of 396 records. Findings reveal that LLM threats span the entire lifecycle, including data poisoning, prompt injection, privacy leakage, model extraction, and ecosystem-level vulnerabilities. When integrated into enterprise environments, these threats escalate into regulatory, operational, reputational, and compliance risks. Existing mitigation strategies emphasize defense-in-depth approaches across data, model, interaction, and ecosystem layers; however, governance frameworks remain fragmented. This study develops an integrative framework linking LLM-specific threats, enterprise risk exposure, and layered countermeasures. The findings contribute to Information Systems theory and provide actionable insights for responsible AI cybersecurity management.
When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.
Comments
SIG SEC