Secure AI Atlas mark Secure AI Atlas SECURITY & GOVERNANCE

Risk observation system

Secure AI Atlas

A technical map of operational risk in generative AI systems.

The focus is not the model in isolation. It is the point where language connects to data, identity, tools, permissions, and decisions—and where useful capability can acquire operational authority.

Each entry turns that surface into something reviewable: a failure mode, a control boundary, or a governance question supported by evidence.

A reading method for AI systems

AI Operational Risk Stack

For each AI use case, ATLAS maps what the system can do, what it can reach, what constrains it, and who has accepted the remaining risk.

Governance Layer

Who has accepted the remaining risk?

Defines what is allowed, who is accountable, what evidence is required, and which risks remain unacceptable.

Control Layer

What constrains it?

Applies identity, permissions, validation, logging, approval, monitoring, sandboxing, and secure implementation.

Exposure Surface

What can it reach?

Maps data, tools, APIs, repositories, workflows, users, and decisions within reach of the system.

AI Capability

What can it do?

Identifies generation, retrieval, reasoning, transformation, tool invocation, recommendation, and action.

ATLAS reads the stack in both directions: from governance down to implementation, and from capability up to organizational risk.

Observation field

Enterprise copilots, RAG systems, AI Agents, and connected tools—especially when their output can affect data, access, or action.

Method

Start with a concrete failure mode, trace its exposure path, identify the control boundary, and ask what evidence would make the risk reviewable.

Coordinates

ATLAS links risks such as Shadow AI and Prompt Injection to practical controls, accountable owners, and governance decisions.

Featured research briefing

Shadow AI and the New Problem of Delegated Authority

A research briefing on the shift from unmanaged AI usage to agentic systems with delegated authority, and the controls needed to govern both risk domains.

Recent analysis

Short technical articles for understanding the exposure before selecting a control.

All articles

External intelligence

Atlas News Radar

Recent external signals on AI security, agentic systems and governance.

View all signals →

External signal

The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities (opens external site in a new tab)

arXiv Cryptography and Security

arXiv:2607.05743v1 Announce Type: new Abstract: AI coding agents now read repositories, call tools, and execute shell commands with limited human oversight, and a fast-growing body of work studies whether the execution layer around them is actually safe. That literature is…

llm appsec agents

External signal

Beyond the Leaderboard: A Synthesis of Tool-Use, Planning, and Reasoning Failures in Large Language Model Agents (opens external site in a new tab)

arXiv Artificial Intelligence

arXiv:2607.05775v1 Announce Type: new Abstract: Large language model (LLM) agents are increasingly evaluated on their ability to use tools, plan multi-step tasks, coordinate with other agents, and operate over extended horizons. Reported benchmark gains often obscure recurring…

llm appsec agents

External signal

Unicode TAG-Block Concealment of Tool-Metadata Payloads in the Model Context Protocol: An Approval-View Fidelity Gap Across Three Independent Server Implementations (opens external site in a new tab)

arXiv Cryptography and Security

arXiv:2607.05744v1 Announce Type: new Abstract: The Model Context Protocol (MCP) is the dominant way coding agents discover and invoke external tools. A server advertises each tool through a tools/list handshake that returns a name, a natural-language description, and a JSON…

llm appsec agents

External signal

Information Gain-based Rollout Policy Optimization: An Adaptive Tree-Structured Rollout Approach for Multi-Turn LLM Agents (opens external site in a new tab)

arXiv Artificial Intelligence

arXiv:2607.06223v1 Announce Type: new Abstract: Reinforcement learning has become a promising paradigm for improving large language model (LLM) agents on long-horizon search tasks, where the agent must make a sequence of intermediate decisions before receiving a final outcome.…

llm appsec agents

External signal

One Million Passports Leaked Online (opens external site in a new tab)

Schneier on Security

A database of almost a million passports from around the world was leaked online. Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value system that got…

identity permissions

External signal

Interesting Paper Exploring Prompt Injection (opens external site in a new tab)

Schneier on Security

This is a fascinating explotation of how LLMs fall for prompt injection attacks. It turns out that they learn to recognize the style of text in different role/instruction blocks, and not just the tags. Their conclusion: Role tags were a formatting trick that became the security…

llm appsec

Risk Catalogue

Failure modes that emerge when language crosses into data, identity, tools, permissions, and decision paths.

MCP Channel Trust

The trust channel between an MCP client and server can carry malicious content, intercepted requests, or manipulated trust dialog, allowing an attacker to control agent behavior through the communication channel.

Agentic Supply Chain Compromise

An attacker-controlled artifact reaches an AI coding agent through plugin resolution, symlink paths, model cache, or CI trigger, and executes with the agent's privileges.

Excessive Agency

An AI system can take actions that exceed its reliability, authorization, or oversight model.

Controls Catalogue

Operational boundaries that make AI capability observable, constrained, reviewable, and accountable.

Approved AI Tool Register

A maintained record of approved AI tools, allowed use cases, owners, data limits, account requirements, and review status.

A technical map, not a risk score

Use the catalogues to frame a review, then use Frameworks to connect findings to owners and evidence. Learning Log records how the map changes as the field develops.

Secure AI Atlas is built to make AI systems legible before capability becomes authority.