Principle Security Principle Security.

AI security

Is your AI governed, or just adopted?

Six questions on whether your AI and LLM use is defensible — aligned to the NIST AI Risk Management Framework. For teams deploying AI faster than they can govern it.

6 questions ~2 minutes No signup Runs in your browser

Most organizations are already using more AI than their policies cover. This scorecard shows where the governance gaps are and which to close first.

1
Do you have an inventory of the AI/LLM tools and features in use across the business?
2
Is there a policy on what data can and cannot go into AI tools?
3
Do you review the security and data terms of AI vendors before adoption?
4
Is there a named owner accountable for AI risk and governance?
5
If you use AI agents/automations, are their permissions and actions scoped and logged?
6
Can you give your board a clear, current picture of AI risk?

Why this matters

The risk isn't the model — it's the data going into it and the actions coming out

AI adoption almost always outruns AI governance. Employees paste sensitive data into tools nobody reviewed; agents get more access than any single user should have; and when the board, an auditor, or an insurer asks for a current picture of AI risk, there isn't one. None of that requires exotic controls — it requires an inventory, a data policy that's actually enforced, and a named owner. The NIST AI RMF exists precisely to make this manageable.

1 in 3
employees have pasted confidential data into a public AI tool
Directional industry figure; shadow-AI is the norm, not the exception.

How this is scored

Six weighted questions mapped to the NIST AI Risk Management Framework functions — Govern, Map, Measure, Manage — covering inventory, data policy, vendor review, ownership, agent controls, and board reporting. Each scores 0–3; the total maps to a band, and gaps surface as prioritized fixes.

Questions

We're small — do we really need AI governance?

Yes, and it's lighter than you think. The minimum is an inventory of what's in use, a written (and enforced) rule on what data can go into AI tools, and one accountable owner. That alone closes most of the real exposure.

What is the NIST AI RMF?

The NIST AI Risk Management Framework is the emerging standard for governing AI risk. It organizes the work into Govern, Map, Measure and Manage — a practical structure regulators and insurers increasingly expect you to follow.

What makes AI agents riskier than a chatbot?

Agents take actions, not just answer questions. An over-permissioned agent is a new attack surface — prompt injection and data-exfiltration can turn it into an insider with more access than it should have. Scope permissions and log actions.

Deploying AI faster than you can govern it?

Our AI Security Assessment gives you a board-ready view of AI risk aligned to the NIST AI RMF and CSF 2.0, with a practical roadmap.