AI risk surface
Threats change. Defensive principles remain.
Use the filters to explore human, data, application, agent and supply-chain risks. Each card explains the failure mode and the first defensive move.
PEOPLE / 01High believability
AI-enabled phishing and impersonation
Generated text, cloned voices and synthetic video can reproduce tone, context and authority.
First controlVerify consequential requests through an independently trusted channel.
Open verification guide ↗
DATA / 02Disclosure
Sensitive information in prompts and connectors
Uploads, chat history, retrieval stores and connected workspaces can reveal more than intended.
First controlClassify, minimise and approve data before it enters an AI service.
Open data guide ↗
APP / 03Instruction conflict
Direct and indirect prompt injection
Hostile instructions in webpages, documents or messages can redirect model behaviour and tool use.
First controlKeep authorisation outside the model and treat retrieved content as untrusted.
Open application guide ↗
AGENT / 04Excessive agency
Autonomy beyond control
An agent that can email, alter files or call systems can turn a wrong decision into a real-world event.
First controlUse minimum permissions, bounded actions and approval at the point of consequence.
Open agentic AI guide ↗
APP / 05Unsafe execution
Improper output handling
Model output may contain unsafe code, commands, links or structured data that downstream systems trust.
First controlValidate and encode output before display, storage, execution or tool use.
Review OWASP GenAI risks ↗
SUPPLY / 06Dependency risk
Models, datasets, plugins and components
Third-party models, libraries and data pipelines can change, become compromised or inherit unknown risk.
First controlMaintain component provenance, version control, assurance and an exit path.
Open supplier guide ↗
PEOPLE / 07Overreliance
Confident output, weak evidence
Fluent answers can be incomplete, fabricated or unsuitable for the actual context.
First controlRequire source checks and qualified human review for consequential decisions.
Browse verification guides ↗
OPS / 08Unknown exposure
Shadow AI and unmanaged accounts
Useful tools may enter the organisation without known owners, contracts, controls or offboarding.
First controlDiscover use transparently and offer a safe approved pathway.
Open shadow AI guide ↗