THREAT MODELAI SECURITY ENGINEERING

Maintain an assumption register

An assumption register records what is known, unknown, validated and invalidated about the AI architecture and controls.

WHY IT MATTERS

AI systems evolve quickly and threat models often begin with incomplete information.

ENTERPRISE EXAMPLE

Assumption: every MCP tool re-authorizes user context. Validation discovers one server does not.

SECURITY DECISION

Which security control should be explicit?

REMEMBERUnknowns should be explicit security work items.
No uploads · No company data · No account required