Ask an AppSec team whether its AI features are secured and the answer is usually yes, since a guardrail product sits in front of the chat box. Ask which systems call which tools on which credentials, which corpora accept writes from outside, and who last tried to break any of it, and the room goes quiet. This instrument settles the question with artefacts. Twenty controls, four domains, one hundred points, and a row scores only when a test result or a document is on the table.
Attack surface knowledge carries 30 points, architectural controls 30, adversarial assurance 20, detection and response 20. The three below are where a typical run bleeds, and each failed row gets a name, a weight and a date it can be closed by.
Thirty points for knowing what exists: a single register of AI systems including the unapproved ones, every tool a system can call with its credential and scope, retrieval corpora listed with their write paths, models pinned by digest rather than tag, and non-human identities with a named owner and a rotation date that has passed at least once.
Twenty points, and the domain that most often reads zero. An external test against the OWASP Top 10 for LLM Applications inside twelve months, an evaluation suite in CI that can fail a build, findings tracked to a retest rather than a ticket closure, scope that reached the tools and the corpora, and testers who do not report to the people who built it.
measured not estimated
Twenty points for detection and response, where the expensive row is the drill. Full request traces held in storage you control, an AI incident playbook that is not the outage runbook, cost breakers tripped on purpose, and a dated record of how many minutes passed from the first anomalous trace to the component being isolated.
Pick an AI feature already serving traffic and bring whoever drew it. Take the whole weight on a row or none of it, and write down every artefact that turns out not to exist.
Architecture usually scores best and buys nothing you can prove, while adversarial assurance reads near zero. A high total with an empty Domain C means the design has never met a hostile caller.
Two inventories built from configuration files that already exist, a playbook written from the incident classes, and one half-day drill moved a real score from 46 to 67 inside a quarter.
One drill took the path from 212 hours to 68, and the 144 hours removed are worth about $158,400 against a build cost near $42,000. That is a funding case, not an assurance.
An artefact on the table or a test result you can point at, there and then. A roadmap item scores zero. So does a supplier assurance nobody has verified, and so does a control that holds on the flagship application but not on the other eight, since an attacker picks the eight.
Forty-six out of a hundred is the figure a worked example reached: a B2B software company with nine AI features in production, a capable platform team and a guardrail product in front of two of them. Architecture scored 17 of 30. Adversarial assurance scored 7 of 20.
The register and the credential map, in that order, and both are built from configuration files you already hold. Under 55 puts you with the 92% whose AI-related breach met no real access control, so the first job is knowing what exists and what each thing is allowed to reach.
No. Self-scoring maps exposure and orders the work, and it cannot call a system safe, because that verdict belongs to whoever tries hardest to break it. Above 80 the useful move is to hand an enterprise customer a test report instead of a policy, then widen coverage to the AI inside software you bought.
Weight follows what decides an engagement, and the first two domains decide more of it. An untested control still bounds damage; an untested system with no inventory and shared credentials does not. Scoring 55 to 79 almost always means the architecture is sound and the assurance is thin, and the external test is the next cheque to write.
This one scores what you already run. AI Security: What Buyers Should Ask turns the same ground on a supplier before you sign. The AI Security Report takes the 2026 cost curve to a board. Score yourself with this, interrogate vendors with that, and fund the work with the third.
Drop your details and we'll send Benchmarking AI Security straight to your inbox - no spam, unsubscribe anytime.
Two hours with our engineering leads, your architecture on the table, and a ranked list of the four fixes that take the most time off your containment clock for the least outlay. SECTION 7 - FAQ - 5 to 8 questions
Book a scoring session