How the adaptive assessment selects questions, models exposure, and turns findings into a prioritized plan.
AI system type, autonomy, data, deployment, users, integrations, and guardrails determine which risks and security-practice questions apply.
Exposure combines a system-specific baseline, environment and guardrail modifiers, autonomy, and the maturity of the controls assessed for that scope.
Assessment state is kept in session storage. PDF and Word reports are generated locally in your browser and are not submitted to a report API.
Results are modeled estimates based on self-reported answers. Validate findings with evidence, testing, and qualified legal or risk advice before making material decisions.
A transparent prioritization model, not a probability forecast.
exposure = baseline × environment modifiers × guardrail factors × autonomy factor × maturity gap
Threat scores are capped to a 0–100 scale. Multi-system results can use the highest exposure per threat or an average where the primary system receives twice the weight. Recommended controls are ranked by the counterfactual change in overall modeled exposure when one assessed control reaches the target maturity level.
Mappings provide traceability; they do not imply endorsement or certification.
Use this check before sharing a workstation or starting over.
AI Security Assessment is an independent BarrySecure project. References to third-party standards and products are descriptive and do not imply affiliation, sponsorship, certification, or endorsement.