The thinking behind AI security review.
Threat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.
New posts in your inbox,
when they publish.
Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.
LLM Excessive Agency — Scope Permissions Down (OWASP)
Excessive agency: an LLM has more capability than its task requires, and a manipulated model can exercise the excess. Least-privilege is the fix.
Re-assessment triggers — the field most dispositions skip
A disposition without re-assessment triggers never expires. Triggers keep decisions honest as AI systems evolve. How to define them.
Design-time vs runtime AI security — where review belongs
Runtime tools watch production anomalies. Design-time review decides if the system should ship. Conflating them creates gaps.
When to re-assess an AI vendor
AI vendor assessments expire. Model updates, new features, changed terms, incidents, and expanding use cases all trigger a fresh review.
The ISO 42001 evidence checklist for security reviews
Every evidence artefact an ISO 42001 audit will request, mapped by control domain and aligned to what AI security reviews already produce.
Prompt-context injection through MCP tools
MCP tools return data injected into model context. When that data contains instructions, the tool becomes an injection vector. Controls that prevent it.
EU AI Act obligations for deployers (not just providers)
Deployers -- not just providers -- carry significant EU AI Act obligations. What organisations using AI systems for their own purposes must do.
Vector Database Security — RAG Pipeline Checklist
Vector databases inherit standard data-store security requirements plus RAG-specific ones. The full security checklist for production pipelines.
Human-in-the-loop boundaries that actually hold
HITL is the most common agentic control and the most often specified in ways that don't hold. What a robust boundary requires — and the failure modes.
Model denial of service and cost-exhaustion attacks
LLM DoS doesn't require crashing the service — just making it expensive. Cost-exhaustion attacks are under-defended in most assessed AI systems.
Who runs the AI security review — roles and hand-offs
AI security reviews span architects, security engineers, governance leads, and DPOs. Map the hand-offs to avoid dropped gates.
The anatomy of an AI evidence pack
The complete artefact set a governance committee needs for a defensible AI decision. What goes in, and why order and labelling matter.
Free resources
Practical templates for every framework covered here.
AI Security Review Template
Full review pack with threat model, controls, and evidence grading.
OWASP Agentic Top 10 Controls
Each risk mapped to required controls and lifecycle gates.
AI Risk Disposition Memo
Clearance decision template with rationale and sign-off log.
AI Go-Live Security Checklist
Production gate checklist for security architects and CISOs.