The thinking behind AI security review.
Threat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.
New posts in your inbox,
when they publish.
Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.
The EU AI Act timeline and what to prepare first
EU AI Act provisions apply in phases. Which obligations hit when, and the preparation steps that deliver value first.
Running RAG over regulated data — the review checklist
RAG over GDPR, HIPAA, or financial data needs controls at data, retrieval, and output layers. Checklist mapped by data class with evidence requirements.
The OWASP Agentic Top 10, explained for security reviewers
OWASP Agentic Top 10 explained for practitioners: each threat category with actionable controls and evidence requirements a security reviewer can use.
System prompt leakage and why it matters for security
System prompts encode trust assumptions, scoping rules, and sometimes credentials. When they leak, the system's entire trust model is exposed.
A lightweight AI security review for fast-moving teams
Minimum-viable AI security review for fast-moving teams: three questions, three artefacts, one decision record.
What makes an AI decision record defensible
A defensible decision record lets a regulator understand what was decided and why -- without the people who made it. The required standard.
Reviewing how an AI vendor handles your data
Is your data used for training? Who accesses it? Where is it stored? The DPA rarely answers these. The data-handling review for AI vendors.
NIST AI RMF vs ISO 42001 — Which Framework to Choose
NIST AI RMF vs ISO 42001: the two leading AI governance frameworks compared across structure, certification, and evidence.
Securing an internal MCP server exposed to agents
Internal MCP servers exposing tools, databases, or APIs to agents have different security requirements than public ones. The review checklist.
General-purpose AI obligations under the EU AI Act
GPAI provisions create obligations for foundation model providers. What they mean and what deployers of GPAI-powered systems need to know.
Evaluating a RAG pipeline for security, not just relevance
RAG evaluation frameworks measure relevance. Security evaluation asks: what boundaries are crossed, what can be extracted, and what enforces the scope?
Agentic AI Privilege Escalation — 5 Attack Paths
Agentic privilege escalation needs no kernel exploit — just a model convinced to invoke unintended tools. Maps escalation paths and blocking controls.
Free resources
Practical templates for every framework covered here.
AI Security Review Template
Full review pack with threat model, controls, and evidence grading.
OWASP Agentic Top 10 Controls
Each risk mapped to required controls and lifecycle gates.
AI Risk Disposition Memo
Clearance decision template with rationale and sign-off log.
AI Go-Live Security Checklist
Production gate checklist for security architects and CISOs.