The thinking behind AI security review.
Threat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.
New posts in your inbox,
when they publish.
Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.
Reviewing UiPath Agentic Automation — what the AI Trust Layer certifies, and what it doesn't
ISO 42001 and AIUC-1 certification, zero third-party data retention, and centralized real-time policy evaluation are real. What still depends on how an individual agent's access is actually configured.
Unbounded consumption in LLM applications — OWASP LLM Top 10 explained
OWASP reframed model-DoS as Unbounded Consumption, covering all uncontrolled resource drains. What reviews must now check.
Fyxer AI security review — full inbox access is the highest-risk AI category
Security review framework for Fyxer AI: OAuth scopes, email content exposure, unidentified LLM provider, and what procurement must verify.
Granola AI security review — meeting notes under the microscope
What a security team should assess before approving Granola: audio processing, sub-processor chain, PII exposure, and eight evidence gaps to close.
Claude AI security review — what a procurement team should assess
A security architect's framework for reviewing Claude before enterprise deployment: data handling, model governance, output safety, and evidence gaps.
Reviewing Microsoft Copilot Studio agents — three 2026 CVEs and the DLP gap they share
A patched prompt-injection vulnerability still exfiltrated data — because the exfiltration path ran through a legitimate, trusted action that DLP never questioned. What that teaches a review.
Reviewing Workday Illuminate agents — what the Agent System of Record actually governs
A dedicated governance system for first- and third-party HR and Finance agents is a real step forward. What a review still has to confirm before trusting it.
ISO 42001 certification — what the external audit actually checks
What an ISO 42001 external auditor samples at Stage 2, the nonconformity categories, and evidence gaps that recur most.
Reviewing Kiro — the steering-file CVE, and four more disclosures
AWS's agentic IDE keeps specs as the unit of work and reads persistent "steering files" on every interaction. The trust-boundary risk that raised was hypothetical when first flagged — CVE-2026-10591 confirmed it.
Reviewing Replit Agent — the lesson from a rogue production database deletion
An autonomous agent ignored an explicit "code freeze" instruction, deleted a production database, and then tried to cover it up. What was missing, and what a review has to require before an agent gets that kind of access.
Reviewing Devin deployments — shell, browser, and editor access with near-zero review window
Devin plans, codes, tests, and deploys with minimal supervision, holding shell, browser, and editor access simultaneously. What a review has to bound before that autonomy reaches production.
Multi-tenant RAG — the isolation boundary a security review must verify
Shared RAG serving multiple tenants creates a retrieval boundary user-level ACLs cannot cover. Verify it before sign-off.
Free resources
Practical templates for every framework covered here.
AI Security Review Template
Full review pack with threat model, controls, and evidence grading.
OWASP Agentic Top 10 Controls
Each risk mapped to required controls and lifecycle gates.
AI Risk Disposition Memo
Clearance decision template with rationale and sign-off log.
AI Go-Live Security Checklist
Production gate checklist for security architects and CISOs.