The thinking behind AI security review.
Threat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.
New posts in your inbox,
when they publish.
Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.
Writing an AI governance committee charter
A committee without a charter is a meeting with a name. Authority, composition, quorum, decision types, and escalation paths defined.
MCP security — the four attack surfaces of a Model Context Protocol server
MCP servers expose tools, resources, and prompts — each an attack surface. Defines the four surfaces and review questions for each.
ISO 42001, explained for security teams
ISO 42001 explained for security teams: what the AI management system standard requires, how it differs from 27001, and what auditors expect.
RAG security — the three boundaries that matter
RAG adds three security boundaries between user and model: data, retrieval, and context. Each has distinct failure modes a standard LLM review misses.
EU AI Act risk tiers, explained for engineers
Four risk tiers determine your EU AI Act obligations. How to classify your system and what each tier demands.
Agentic AI security — the surfaces deterministic software does not have
Agentic AI security covers four surfaces deterministic software lacks: hijackable reasoning, tool manifests, persistent memory, drifting goals.
The OWASP LLM Top 10, mapped to controls
OWASP LLM Top 10 mapped to specific controls, lifecycle gates, and verification evidence. From threat name to actionable review artefact.
What an AI security review actually is (and what it is not)
AI security review defined: a design-time assessment producing a defensible record of risks identified and controls required — not a pentest.
Free resources
Practical templates for every framework covered here.
AI Security Review Template
Full review pack with threat model, controls, and evidence grading.
OWASP Agentic Top 10 Controls
Each risk mapped to required controls and lifecycle gates.
AI Risk Disposition Memo
Clearance decision template with rationale and sign-off log.
AI Go-Live Security Checklist
Production gate checklist for security architects and CISOs.