Research

Watch · narrated whiteboard episodesL2

The Minimum Viable AI Security Baseline

Most AI systems ship with no security floor at all — no agreed minimum set of controls you must have before going to production. This series builds that floor from the ground up: why a baseline is the highest-leverage security investment an AI team can make and what it costs to have none, the minimum control set every AI system must have mapped to the OWASP LLM and Agentic guidance and the NIST AI RMF, the non-negotiable runtime guardrails on inputs, retrieval, and tools, the governance floor of identity, logging, and human-in-the-loop, and how to adopt the baseline through a maturity ladder, a checklist, and a continuous-integration gate. Grounded in the OWASP Top 10 for LLM Applications and Agentic Security Initiative, the NIST AI Risk Management Framework, the NIST Cybersecurity Framework and Zero Trust guidance, MITRE ATLAS, and ISO/IEC 42001.

Murali Chillakuru·5 episodes
  1. 8 min Episode 1Why a Baseline: The 80/20 of AI Security and the Cost of Having No FloorA moderator and a principal engineer make the case that a small, boring, mandatory security floor prevents more harm than any advanced defense.
  2. 8 min Episode 2The Baseline Control Set: The Minimum Controls Every AI System Must HaveA moderator and a principal engineer distill the six controls no AI system should ship without, drawn from where OWASP, NIST, and ISO already agree.
  3. 7 min Episode 3Input, Retrieval, and Tool Boundaries: The Non-Negotiable Runtime GuardrailsA moderator and a principal engineer specify the three runtime boundaries that close the surfaces where most real AI attacks land.
  4. 7 min Episode 4Identity, Logging, and Human-in-the-Loop: The Governance FloorA moderator and a principal engineer show how three governance controls turn a runtime-guarded AI system into an accountable one.
  5. 7 min Episode 5Adopting the Baseline: A Maturity Ladder, a Checklist, and a CI GateA moderator and a principal engineer show that a baseline only matters when a gate blocks a non-compliant release — and how to get there.