CSO Shield

✅ AI security posture check

10 areas, 30 questions, about 10 minutes. Answer for your organisation as it is today — “Not sure” is a valid answer and shows up as something to find out. You get a level from L0 to L5, a score per area and the five fixes that matter most.

No account needed. Sign in afterwards to keep your history.

AI security posture

0/30 answered · step 1 of 10

AI inventory & shadow AI

Do you know which AI is in use, by whom, with what data?

1.We keep an inventory of AI systems and AI features in use, each with an owner.
Why we ask

Every other control depends on knowing what exists.

2.We actively discover shadow AI (network/SaaS logs, browser extensions, OAuth grants, spend).
Why we ask

Most AI enters through people and updates, not projects.

3.Production AI systems have an AI-BOM (models, datasets, prompts, tools, versions).
Why we ask

When a component is compromised you need to know where it is used.

Answer all 3 to continue — “Not sure” is a valid answer.

Educational content for security leaders. Attacks are explained conceptually — no working exploits. Check the linked sources before you rely on a detail. Last content review: 2026-10-01.

Shared governance topics: AI Command Office · Laws and deadlines: Compliance Wise

Privacy · Terms ·