Review the system around the model
Models do not create consequence by themselves. Agents, tools, APIs, identities, data stores, cloud services, and operators determine what the AI system can reach and what happens when it fails or is manipulated.
Begin by mapping those relationships, trust boundaries, privileges, external providers, approval points, and recovery paths.
Follow credible attack and failure paths
- Prompt injection and untrusted instructions reaching consequential tools.
- Excessive agency, weak approval boundaries, and identity or tenant confusion.
- Sensitive-data exposure through retrieval, memory, logging, or external providers.
- Model, software-supply-chain, infrastructure, and recovery weaknesses that combine with AI behavior.
End with action
Rank findings by consequence and connect each one to a design change, operating control, focused test, accountable owner, and verification criterion.
This guide provides general security information. It is not a certification, legal opinion, compliance determination, or guarantee of security.