World Model Readiness
Engraved technology instrument

For your company

Technology & Risk

Module · The attack surface you just installed

The AI Security & Misuse Check

Every AI feature you ship is a new attack surface, and most of it is invisible to a traditional security review. Models follow instructions hidden in the data they read, leak through channels nobody mapped, and hand attackers a friendly interface to your systems. This module checks the five pieces that matter: prompt injection, data leakage, model access control, adversarial testing, and data-loss controls on the AI tools your staff already use.

Question 1 of 5 · Prompt injection tested

Have you tested whether untrusted input can hijack your AI features?

Any model that reads external content, emails, documents, web pages, tickets, can be instructed by that content. Prompt injection turns your helpful assistant into someone else's tool. If you have never tried to do it yourself, assume it already works.

Question 2 of 5 · Leakage paths mapped

Do you know every path by which an AI feature could expose data it should not?

LLM features leak in quiet ways: a chatbot answering about another customer's records, a summariser pulling in documents beyond the user's permissions, logs capturing prompts full of secrets. Map the paths yourself, or an outsider will map them for you.

Question 3 of 5 · Model access controlled

Is access to your models and their keys governed like any other production credential?

API keys pasted into shared chat channels, one service account behind every feature, no rate limits, no record of who called what. Model access is often the least-governed credential in the building and among the most expensive to abuse.

Question 4 of 5 · Someone red-teams it

Does anyone deliberately try to break your AI systems before attackers do?

Standard penetration testing does not cover jailbreaks, prompt injection or model misuse; it was written for a different threat. If nobody is adversarially probing your AI features, your first red team will be a real one, and it will not send you a report.

Question 5 of 5 · DLP on AI endpoints

Can you detect and stop sensitive data flowing into the AI tools your staff use?

Employee-facing AI is an exfiltration channel with a friendly face. Without data-loss controls on those endpoints, source code, customer lists and contract drafts leave silently, one paste at a time, and you learn about it in the breach notification.

For the statistics · one click each

Three questions for the public picture

These do not affect your score. They feed the anonymised, aggregated statistics; groups under 8 respondents are never shown.

Has your company ever adversarially tested an AI system?

Never
Planned
Once
Regularly
No AI in production

Have you had a security incident involving an AI feature?

Not that we know of
A near-miss, caught in time
Yes, minor
Yes, serious
We could not tell

Do you have data-loss controls on the AI tools employees use?

None
Policy only
Partial coverage
Full coverage
We do not know

Your context

Used to calibrate the report. Company size and sector remain in the anonymized dataset; your email does not.

What the five levels look like

Every dimension in this assessment is scored 1 to 5. This is what the levels mean, dimension by dimension. The graded report diagnoses where your own answers land and what to do about it.

Prompt injection tested

  1. 1Never heard of it
  2. 2Aware, untested
  3. 3Tested once
  4. 4Tested, some controls
  5. 5Tested and monitored

At the low end: Prompt injection is the SQL injection of the AI era, and it is trivial to attempt. Spend an afternoon trying to hijack your own feature with hidden instructions; the result will set your priorities. What good looks like: Tested defences with monitoring is where you want to be. Keep probing as features change; every new data source your model reads is a new injection path.

Leakage paths mapped

  1. 1No idea
  2. 2Never mapped
  3. 3Partially mapped
  4. 4Mostly mapped
  5. 5Mapped and controlled

At the low end: Data you cannot see leaving is data you cannot protect. List every AI feature and, for each, what data it can reach and where its inputs and outputs are stored. What good looks like: A mapped and controlled data flow is exactly what an auditor and an attacker both probe first. Keep it current as features and integrations grow.

Model access controlled

  1. 1Keys everywhere
  2. 2One shared account
  3. 3Basic controls
  4. 4Scoped and logged
  5. 5Least-privilege, rotated

At the low end: Loose model keys are a breach waiting for an audience. Inventory where the keys live this week, kill the ones in shared channels, and put every call behind an account you can trace. What good looks like: Least-privilege, rotated model access puts you ahead of most teams shipping AI. Keep the logs reviewed; an unwatched log is a credential nobody is guarding.

Someone red-teams it

  1. 1Never
  2. 2Ad hoc curiosity
  3. 3One-off exercise
  4. 4Periodic red-teaming
  5. 5Continuous adversarial testing

At the low end: Untested AI is a promise you have not checked. Run one structured adversarial session against your highest-stakes feature; even a half-day surfaces the obvious holes. What good looks like: Continuous adversarial testing is the standard the risk deserves. Feed every finding back into the controls so the same break does not work twice.

DLP on AI endpoints

  1. 1No controls
  2. 2Policy only
  3. 3Some monitoring
  4. 4DLP on main endpoints
  5. 5DLP across all endpoints

At the low end: A written rule does not stop a paste. Start with monitoring on the AI endpoints staff actually reach for, so you can see the outbound flow before you try to control it. What good looks like: Data-loss controls across your AI endpoints close the channel most companies leave wide open. Pair enforcement with a sanctioned tool good enough that staff do not route around it.