Research seriesL2paper
Most AI systems ship with no security floor at all — no agreed minimum set of controls you must have before going to production. This series builds that floor from the ground up: why a baseline is the highest-leverage security investment an AI team can make and what it costs to have none, the minimum control set every AI system must have mapped to the OWASP LLM and Agentic guidance and the NIST AI RMF, the non-negotiable runtime guardrails on inputs, retrieval, and tools, the governance floor of identity, logging, and human-in-the-loop, and how to adopt the baseline through a maturity ladder, a checklist, and a continuous-integration gate. Grounded in the OWASP Top 10 for LLM Applications and Agentic Security Initiative, the NIST AI Risk Management Framework, the NIST Cybersecurity Framework and Zero Trust guidance, MITRE ATLAS, and ISO/IEC 42001.
Most AI systems ship with no agreed minimum set of security controls at all — and a small, boring baseline prevents more harm than any advanced defense you might build later.
A short, opinionated list of controls — drawn from where OWASP, NIST, and ISO already agree — that no AI system should reach production without.
Three boundaries — around what enters the model, what it reads, and what it can do — form the runtime floor no AI system should operate without.
Three governance controls — attributable identity, reconstructable logging, and a human gate on irreversible actions — turn a runtime-guarded system into an accountable one.
A baseline that lives in a document changes nothing; adoption means a checklist teams can run, a ladder to climb, and a gate that blocks release when the floor is not met.