The thinking behind AI security review.
Threat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.
New posts in your inbox,
when they publish.
Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.
Insecure output handling — the LLM risk teams underrate
Teams harden LLM inputs and ignore outputs. Insecure output handling turns prompt injection into code execution, data exfiltration, or stored attacks.
When to run an AI security review — the four trigger points
Four trigger points that should initiate an AI security review: initial deployment, model change, scope expansion, incident.
Assessing the AI feature inside SaaS you already bought
Vendors are adding AI to SaaS you already trust. Those features introduce risks the original assessment missed. The supplemental review defined.
AI risk acceptance — who actually signs
Risk acceptance attributed to a committee means no one is accountable. Who should sign for AI systems and what that signature requires.
ISO 42001 vs ISO 27001 — what is new for AI
Already hold ISO 27001? Here's what ISO 42001 adds for AI -- new requirements vs. controls you can extend from your existing ISMS.
Tool poisoning in MCP servers
MCP tool poisoning uses malicious tool descriptions to manipulate models into unintended invocations or data disclosure. Descriptions are untrusted.
Building an EU AI Act system inventory
The EU AI Act requires knowing every AI system you deploy and its tier. Here's how to build that inventory when AI hides in SaaS and vendor products.
Data poisoning in RAG knowledge bases
RAG knowledge base poisoning inserts malicious content not to corrupt the index, but to influence model outputs when poisoned documents are retrieved.
Mapping the agentic AI attack surface
Five layers of the agentic AI attack surface — prompt channel, tool surface, memory, orchestration boundary, output channel — mapped with controls.
Prompt injection, explained for security reviewers
What prompt injection actually is, how its variants work, how it differs from SQL injection, and which controls reduce the risk in practice.
The AI security review checklist, by lifecycle gate
A lifecycle-gate checklist for AI security reviews: intake through production, with gate-specific questions and evidence needs.
The AI section your vendor security questionnaire is missing
The AI vendor risk assessment questionnaire your procurement process is missing — model governance, re-assessment triggers, incident notification.
Free resources
Practical templates for every framework covered here.
AI Security Review Template
Full review pack with threat model, controls, and evidence grading.
OWASP Agentic Top 10 Controls
Each risk mapped to required controls and lifecycle gates.
AI Risk Disposition Memo
Clearance decision template with rationale and sign-off log.
AI Go-Live Security Checklist
Production gate checklist for security architects and CISOs.