The thinking behind AI security review.
Threat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.
New posts in your inbox,
when they publish.
Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.
Scoping an AI security review without boiling the ocean
Scope an AI security review to the decision you need: the system, the deployment context, and the pass/fail threshold.
The restricted-pilot pattern for risky AI systems
A restricted pilot is a formal disposition: defined scope, named controls, explicit re-review triggers. How to write one that holds.
AI subprocessor risk in your vendor chain
When a vendor's AI runs on a third-party model provider, that provider is a subprocessor. Retention, training, and transfer risks your DPA missed.
AI risk assessment under ISO 42001
ISO 42001 requires a documented AI risk assessment. What it must cover, how it differs from IT risk assessments, and what complete looks like.
Transport security for MCP servers
MCP runs over HTTP/SSE or stdio — each with distinct security requirements. Covers TLS, mutual auth, and transport review questions.
Indirect prompt injection through retrieved documents
Indirect injection via retrieved documents is harder to detect than direct — the attacker is in the knowledge base, not the conversation.
The technical documentation the EU AI Act expects
Annex IV defines what technical documentation high-risk AI needs before market placement. What it requires, what it means, and the common gaps.
Agent memory as an attack surface
Agents with persistent memory carry forward context that can be poisoned. A past interaction plants instructions that execute in future sessions.
Sensitive information disclosure in LLM applications
LLMs leak data through three channels: training memorisation, system prompt leakage, and retrieval boundary failures. Each needs distinct controls.
AI security review vs penetration testing — different questions
A pentest asks if a system can be exploited. A security review asks if it should ship and under what conditions. Both needed.
Conditional approval for AI systems — making conditions stick
Conditional approval is the most common AI disposition. Most are written so the conditions can't be enforced. How to make them stick.
Model-change notification — the vendor clause procurement teams forget
Vendors swap models without notice, invalidating your security review. The contractual clause and review trigger that keeps assessments current.
Free resources
Practical templates for every framework covered here.
AI Security Review Template
Full evidence pack with threat model, controls, and evidence grading.
OWASP Agentic Top 10 Controls
Each risk mapped to required controls and lifecycle gates.
AI Risk Disposition Memo
Clearance decision template with rationale and sign-off log.
AI Go-Live Security Checklist
Production gate checklist for security architects and CISOs.