The decision is human
AI can now draft the security review. Someone still has to sign it. That asymmetry is where governance lives.
ReadThreat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.
Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.
OWASP reframed model-DoS as Unbounded Consumption, covering all uncontrolled resource drains. What reviews must now check.
Security review framework for Fyxer AI: OAuth scopes, email content exposure, unidentified LLM provider, and what procurement must verify.
What a security team should assess before approving Granola: audio processing, sub-processor chain, PII exposure, and eight evidence gaps to close.
A security architect's framework for reviewing Claude before enterprise deployment: data handling, model governance, output safety, and evidence gaps.
What an ISO 42001 external auditor samples at Stage 2, the nonconformity categories, and evidence gaps that recur most.
Shared RAG serving multiple tenants creates a retrieval boundary user-level ACLs cannot cover. Verify it before sign-off.
A2A governs what agents ask each other to do -- capability-card spoofing, delegation without provenance, transitive access risks.
Article 5 bans eight AI practices outright regardless of safeguards. What falls inside the line and how reviews distinguish.
The six artefacts an AI Committee needs to make a defensible decision, and the gaps that appear most often in evidence packs.
ISO 42001 audits surface the same gaps: incomplete risk registers, missing triggers, intent-not-practice evidence. Close them first.
Eight security areas procurement teams must address before an agentic AI system reaches production. A structured buyer checklist.
Prompt injection and hallucination are symptoms of missing output validation. The controls that close the gap at each gate.
Free resources
Practical templates for every framework covered here.
AI Security Review Template
Full review pack with threat model, controls, and evidence grading.
OWASP Agentic Top 10 Controls
Each risk mapped to required controls and lifecycle gates.
AI Risk Disposition Memo
Clearance decision template with rationale and sign-off log.
AI Go-Live Security Checklist
Production gate checklist for security architects and CISOs.