The decision is human
AI can now draft the security review. Someone still has to sign it. That asymmetry is where governance lives.
ReadThreat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.
Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.
A biased underwriting model or an erratic advice chatbot becomes a headline before it becomes an incident ticket. Why monitoring catches it late, and the design-time review that catches it first.
Agents that write and run their own code have an unbounded tool surface. The security review checklist for that capability.
Misinformation isn't a quality bug when the output drives a decision or an automated action. OWASP LLM09 treats confidently wrong answers as a security category.
Training data poisoning plants a backdoor before the model ever ships. It's invisible in the weights and undetectable at the prompt layer -- review has to reach the data.
Agents that recognized they were breaking scope kept going anyway, driven by peer pressure and an organized scheme to cheat their own eval scorer. Six governance gaps, sourced to OpenAI's, Hugging Face's, and METR's independent reports.
A source-linked briefing on the dates, Article 5 additions, provider/deployer boundaries, and classification changes introduced by Regulation (EU) 2026/1744.
What isolation must guarantee for autonomous agents, and the failure modes when an architecture diagram's sandbox is fiction.
A critical path-traversal flaw worked even with auto-execution off and the vulnerable tool explicitly deny-listed. What that means for trusting a platform's own safety controls, and what changed when Cognition folded Windsurf into Devin.
Distinct from a Claude procurement review: this is Claude Code as a coding agent, its layered permission model, six-plus disclosed CVEs, and the containment guidance Anthropic pairs with its own "YOLO mode" warning.
No disclosed CVE here — the real finding is Databricks' own AI Security Framework v3.0 naming a confused-deputy problem: Unity Catalog governs data at rest, but an agent inherits whatever its tools can reach.
OWASP LLM08: embedding-space attacks that recover source text from vectors and poison the retrieval space itself.
A path-traversal CVE, a Black Hat-disclosed unauthenticated dev assistant, and a GitHub Action that let anyone with issue-comment access trigger privileged code execution. Three separate ADK findings, one shared root cause.
Free resources
Practical templates for every framework covered here.
AI Security Review Template
Full review pack with threat model, controls, and evidence grading.
OWASP Agentic Top 10 Controls
Each risk mapped to required controls and lifecycle gates.
AI Risk Disposition Memo
Clearance decision template with rationale and sign-off log.
AI Go-Live Security Checklist
Production gate checklist for security architects and CISOs.