AI systems introduce unique cyber risks, yet practitioners lack security-specific evaluation frameworks for AI. This talk will cover a novel AI Risk Scanning (AIRS) Framework, that extends AI Bill of Materials (AIBOM) practices, pairing threat modeling with automated, auditable evidence generation, providing a foundation for standardized, trustworthy, and machine-verifiable AI risk documentation.