What can our AI do?
How would we stop misuse?
Start with one important workflow. Name an accountable owner for each area it touches, ask for a realistic control test, and record what the test leaves uncovered.
Show one sensitive-data test from warning to resolution, and list the apps and devices that are outside coverage.
Test attempts to reach an unapproved system, show the enforced block, and explain the test’s limits. Demonstrate how you revoke the agent’s access.
Trace a test credential from initial use to detection and revocation. Explain which connected systems remain reachable.
Take one real finding through a tested fix into the running application. Show the evidence that the flaw is resolved and how to roll back.
Run a realistic exercise. Measure time to a correct decision and containment, alongside false alarms and unintended disruption.
Inventory → accountable owner → policy → test evidence → documented gaps → review.
Leave with a decision.
A qualitative discussion guide, not a security score or a compliance assessment. Relevant controls reduce or detect risk; none guarantee prevention. Guidance: NIST AI RMF 1.0, NIST CSF 2.0, NIST SSDF 1.1, OWASP, and NCSC/CISA secure AI guidance. Sources and incident examples: Faultlines / AI security framework. Reviewed September 2026.