AI application assessment
Examine the model integration, retrieval flow and application permissions against relevant misuse scenarios.
Service portfolio / 07
Understand the new trust boundaries created when models, tools and business data are connected.
Explore the scopeService scope
AI systems introduce decisions about what a model can see, which tools it can use and who checks its output. Assess those boundaries in the context of the actual application and its intended use.
Examine the model integration, retrieval flow and application permissions against relevant misuse scenarios.
Review untrusted input handling, sensitive-data exposure and the permissions granted to connected tools.
Define ownership, evaluation criteria and review points for model and provider changes.
Plan access boundaries, human approval points and operational logging for new AI-enabled workflows.
When this is useful
Deliverables to define in your scope
AI system boundary and risk assessment
Prioritised architecture and application controls
Evaluation scenarios and governance recommendations
Connected expertise
Connect this engagement to the other parts of your security programme when the scope calls for it.
Scope the work around your business.