The decision is human
AI can now draft the security review. Someone still has to sign it. That asymmetry is where governance lives.
ReadThreat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.
Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.
Self-hosted open-weight vs vendor API: the category-by-category risk comparison a security review needs to make.
Vendor lock-in is a security problem: you cannot enforce controls on a vendor you cannot leave. How reviews account for it.
MCP sampling lets servers invoke the client LLM and query users directly, inverting trust. Review controls for that inversion.
GraphRAG adds a knowledge graph as a new attack surface: traversal exposure, relationship injection, and graph poisoning risks.
A biased underwriting model or an erratic advice chatbot becomes a headline before it becomes an incident ticket. Why monitoring catches it late, and the design-time review that catches it first.
Agents that write and run their own code have an unbounded tool surface. The security review checklist for that capability.
Misinformation isn't a quality bug when the output drives a decision or an automated action. OWASP LLM09 treats confidently wrong answers as a security category.
Training data poisoning plants a backdoor before the model ever ships. It's invisible in the weights and undetectable at the prompt layer -- review has to reach the data.
Agents that recognized they were breaking scope kept going anyway, driven by peer pressure and an organized scheme to cheat their own eval scorer. Six governance gaps, sourced to OpenAI's, Hugging Face's, and METR's independent reports.
A source-linked briefing on the dates, Article 5 additions, provider/deployer boundaries, and classification changes introduced by Regulation (EU) 2026/1744.
What isolation must guarantee for autonomous agents, and the failure modes when an architecture diagram's sandbox is fiction.
A critical path-traversal flaw worked even with auto-execution off and the vulnerable tool explicitly deny-listed. What that means for trusting a platform's own safety controls, and what changed when Cognition folded Windsurf into Devin.
Free resources
Practical templates for every framework covered here.
AI Security Review Template
Full evidence pack with threat model, controls, and evidence grading.
OWASP Agentic Top 10 Controls
Each risk mapped to required controls and lifecycle gates.
AI Risk Disposition Memo
Clearance decision template with rationale and sign-off log.
AI Go-Live Security Checklist
Production gate checklist for security architects and CISOs.