Blog

Foundations

11 articles on AI security foundations.

Foundations10 min

What goes in an AI risk register — and what does not

What belongs in an AI risk register: five required fields, common items that do not belong, and how to avoid a generic IT risk list with 'AI' added.

Foundations9 min

Clearance vs approval — why the distinction matters for AI governance

Security clearance and business approval are separate gates. Conflating them produces systems that are approved but not cleared.

Foundations11 min

What an AI Risk Disposition actually contains

AI Committees approve systems they can't defend later. The Risk Disposition memo fixes this -- section by section, with real examples.

Foundations10 min

Five mistakes that make an AI security review undefensible

Five structural mistakes that make an AI security review indefensible. Found in nearly every review regardless of threat coverage.

Foundations9 min

A lightweight AI security review for fast-moving teams

Minimum-viable AI security review for fast-moving teams: three questions, three artefacts, one decision record.

Foundations10 min

What makes an AI decision record defensible

A defensible decision record lets a regulator understand what was decided and why -- without the people who made it. The required standard.

Foundations10 min

Why SOC 2 is not AI assurance

SOC 2 covers infrastructure and process. It says nothing about model behaviour, training data, or edge cases. AI assurance needs different evidence.

Foundations9 min

Scoping an AI security review without boiling the ocean

Scope an AI security review to the decision you need: the system, the deployment context, and the pass/fail threshold.

Foundations10 min

AI security review vs penetration testing — different questions

A pentest asks if a system can be exploited. A security review asks if it should ship and under what conditions. Both needed.

Foundations9 min

When to run an AI security review — the four trigger points

Four trigger points that should initiate an AI security review: initial deployment, model change, scope expansion, incident.

Foundations10 min

What an AI security review actually is (and what it is not)

AI security review defined: a design-time assessment producing a defensible record of risks identified and controls required — not a pentest.