Site Logo
All articles
Commentary on News

Qualitative analysis of AI security: Workflow

Evidano7 min read

This post gives a step-by-step workflow and operational guidance to convert Lancaster University’s synthesis into reproducible qualitative research. Lancaster University’s thematic review (commissioned by the UK Department for Science, Innovation and Technology and published 10 July 2026) scanned 9, 109 peer-reviewed publications from January 2021 to January 2026 and grouped them into 12 themes while flagging five major research gaps. The Lancaster review is available as Thematic review and gap analysis on AI security. If your team needs to turn literature, policy papers, and interview transcripts into operational recommendations, this post gives a reproducible plan you can run in 2–4 weeks and explains how to operationalize it using Evidano to accelerate coding, cross-segment comparison, and visual evidence for stakeholders.

Key Takeaways

Evidano is an AI-powered qualitative data analysis platform that ingests large document corpora, automates thematic extraction, and provides reproducible audit trails for secure, traceable synthesis.

Use the Lancaster University review bounds and the 7-step workflow in this post to convert the 9, 109 peer-reviewed papers (Jan 2021–Jan 2026) into decision-ready themes in a 2–4 week pilot.

  • Replicate the report’s scope (Jan 2021–Jan 2026) and seed your codebook with the report’s 12 themes to speed initial coding and validation.
  • Combine AI-assisted auto-coding and human review to reduce initial coding time while preserving researcher control and reproducibility.
  • Produce cross-segment frequency and co-occurrence analyses to show where evidence is growing or lagging, and export quotations with source links and codebook versioning.
  • Ensure secure handling and an audit trail for sensitive work: the Lancaster report’s policy audience requires traceability and confidentiality.

Findings snapshot

Date / RangeMetricValueSourceNote / Implication
Jan 2021 – Jan 2026Corpus timeframe5 yearsLancaster University report (published 10 Jul 2026)Boundary for the review
Through Jan 2026Publications identified9, 109Lancaster UniversityLarge, diverse literature; need automated triage
Review outputThemes identified12Lancaster UniversityUseful starting taxonomy for coding
Review outputPrevalent gaps5Lancaster UniversityPriority areas for new research and synthesis
PublishedReport date10 July 2026Department for Science, Innovation and TechnologyPolicy audience and national security framing

What the review did (plain English)

Lancaster University performed a thematic review and gap analysis of peer-reviewed research on AI security covering Jan 2021–Jan 2026.

The study screened thousands of records and synthesized findings under 12 high-level themes, then highlighted five gaps where evidence is thin or inconsistent.

  • Scope: peer-reviewed literature only, 2021–2026.
  • Output: 12 themes and five priority gaps (areas needing more study or clearer methods).
  • Audience: government and cyber-security stakeholders seeking a research baseline.

So what for researchers and practitioners

For UX / research teams

UX and research teams should prioritize automated thematic extraction plus human validation to avoid manual synthesis bottlenecks.

The scale of the corpus (9, 109 documents) shows manual synthesis will bottleneck product and security decisions, so prioritize automated thematic extraction and human validation.

Map the report’s 12 themes to your product risk taxonomy to speed triage.

For policy & security analysts

Policy and security analysts should use the five identified gaps to fund directed studies, standardize threat models, and publish shared datasets.

The five gaps are actionable: fund directed studies, standardize threat models, and publish shared datasets.

Synthesize cross-study evidence to make defensible policy recommendations rather than citing single papers.

For qualitative methodologists

Qualitative methodologists should standardize codebooks and reporting templates to make literature syntheses reproducible across teams.

Standardize codebooks and reporting templates so literature syntheses are reproducible across teams.

Use mixed human and AI pipelines for reliability checks, including intercoder agreement measures and AI suggestion logging.

Do more, faster with Evidano

Ingest & harmonize large document corpora

Evidano ingests PDFs, HTML, and report batches and normalizes metadata so teams can filter by date, venue, or theme.

Import PDFs, HTML, and report batches directly; Evidano ingests thousands of documents and normalizes metadata so you can filter by date, venue, or theme.

Why it matters: the report’s 9, 109 items require scalable ingestion and deduplication before coding.

Automated thematic mapping + human validation

Evidano runs AI-assisted thematic extraction to surface candidate themes while preserving researcher control during validation.

Run AI-assisted thematic extraction to surface candidate themes, then import the report’s 12 themes as a starter codebook to align outputs.

Why it matters: reduces initial coding time and preserves researcher control during validation.

Cross-segment and frequency analysis

Evidano compares themes by year, venue, or threat class to replicate the review’s timeline and identify emerging clusters.

Compare themes by year, venue, or threat class (co-occurrence networks and frequency tables) to replicate the review’s timeline and identify emerging clusters.

Why it matters: lets policy teams show where evidence is growing or lagging, one of the report’s key outputs.

Transparent audit trail & secure data handling

Evidano logs AI suggestions and coder decisions and exports a reproducible audit trail while encrypting data in transit and at rest.

Evidano logs AI suggestions, coder decisions, and exports a reproducible audit trail; data is encrypted and never used to train third-party models.

Why it matters: government and security work demands traceability and confidentiality, which the Lancaster report’s audience will require.

7-step workflow: reproduce the report’s synthesis (2–4 weeks pilot)

This 7-step workflow reproduces the report’s synthesis in a 2–4 week pilot for a small research team (1–3 people).

  • 1) Define scope & collect: mirror the report’s bounds (Jan 2021–Jan 2026). Export metadata and PDFs.
  • 2) Deduplicate & sample: use automated near-duplicate detection; reserve a 200-document validation sample.
  • 3) Seed codebook: import the review’s 12 themes as initial codes in Evidano; add tags for the 5 identified gaps.
  • 4) Auto-code + human review: run AI coding, then have researchers validate and refine codes on the sample.
  • 5) Cross-segment analysis: run frequency and co-occurrence reports by year, venue, and theme.
  • 6) Visualize & synthesize: generate co-occurrence networks and hierarchical code maps for briefings.
  • 7) Audit & handoff: export reproducible outputs (quotations with source links, codebook versioning, and CSVs) for policy or product teams.

FAQ: qualitative analysis of AI security

What is the right unit of analysis for this literature?

Treat papers as the primary unit of analysis and extract arguments or findings at the claim or experiment level.

Treat papers as primary units and extract arguments/findings at the claim or experiment level; tag by method (empirical, simulation, theoretical).

How do I compare evidence across years?

Normalize by publication count per year and report both raw counts and proportional shares to avoid misleading trends.

Normalize by publication count per year and report both raw counts and proportional shares to avoid misleading trends.

Is it ethical to run AI on security research?

It is ethical to use AI for synthesis if sensitive data is handled with care and interpretations remain research-focused.

Yes for synthesis, but handle sensitive data with care. Use secure platforms, maintain consent where applicable, and interpret results as research-focused (non-diagnostic).

How secure is Evidano for sensitive corpora?

Evidano encrypts data at rest and in transit and does not use customer data to train third-party models, supporting compliance in security-sensitive projects.

Evidano encrypts data at rest and in transit and does not use customer data to train third-party models; this supports compliance needs in security-sensitive projects.

Wrapping up: two immediate moves

Immediate actions are to validate themes on a bounded subset of the corpus and to run an end-to-end Evidano pilot.

1) Replicate the Lancaster review’s bounds on a subset: pull 1, 000 papers from 2023–2025 and run the 7-step workflow to validate themes before scaling.

2) Try Evidano end-to-end: ingest documents, import the 12-theme codebook, run automated coding, and produce reproducible visuals and an audit trail for stakeholders, starting with Try Evidano for free.

Company
About
Newsletter

Product updates, research, and tips — straight to your inbox.

© Evidano, All Rights Reserved.