AI Security Integration Framework · White paper v1.1 · 2026

Integration,
not adoption.

Seven AI security frameworks exist. The incidents keep happening in the seams between them. AISIF is a five-layer architecture that integrates them — with two open instruments: assess your programme's maturity, and gate every AI system before it ships.

FREE · VERSIONED · CC BY 4.0 · MAPS TO ISO 27001 / NIST AI RMF / ISO 42001 / OWASP / ATLAS / CSA AICM

feedback loop

// tap a layer — each question is asked verbatim by the assessment instruments below

The seam runs in both directions

The incident record made the argument empirical

Illustrative case studies show AI-specific failures that traditional frameworks miss. The disclosed record shows the inverse: conventional failures that AI-specific frameworks miss — amplified by AI-scale data gravity.

Minutes

How long it took outside researchers to find an AI provider's unauthenticated database — over one million log lines of plaintext chat history and API secrets on public ports. No ATLAS technique. No OWASP category. ISO 27001 fundamentals would have prevented it.

CASE STUDY D · DEEPSEEK · JAN 2025
~165

Data-platform tenants compromised with infostealer-harvested customer credentials — some stolen years earlier, never rotated, no MFA. The technique is ATT&CK Valid Accounts, not ATLAS. A control that is available but unmandated is, for risk purposes, absent.

CASE STUDY E · SNOWFLAKE CAMPAIGN · 2024

The frameworks exist. The incidents keep happening in the seams between them.

One framework · two assessments

Assess the programme. Gate every system.

The same five-layer architecture drives both instruments — released openly, with provisional scoring pending practitioner validation.

Programme-level · run annually

Maturity Self-Assessment

How mature is our AI security programme?

  • 26 evidence-based questions across the five layers
  • Scored per layer and per estate — own infrastructure vs SaaS data estate
  • Five proposed Level 2 floor questions gate the Controlled level
  • Word instrument + formula-driven Excel workbook with dashboard

rule: a qualified answer is a No — evidence, not intent

System-level · run every time

New AI System Assessment

May this system go live?

  • Inherent risk tier from a six-factor system profile
  • 30 control checks — 17 mandatory; any gap blocks deployment
  • Approval bar rises to 90% for High and Critical tier systems
  • Dashboard recommendation + governance sign-off record

rule: Planned does not count — a gate separates implemented from intended

The hinge: the maturity instrument asks whether a pre-production gate exists. The system assessment is that gate.
Case study series A–E

Five failures, mapped through the layers

Three illustrative composites and two empirical analyses of disclosed incidents — each in a structured card format: attack vector, layers implicated, failure mode, mitigation, standards activated.

A · Prompt InjectionIllustrative
Adversarial instructions in uploaded healthcare documents override a RAG chatbot's system prompt. Indirect injection defeats input-only defences — the fix spans Application and Data layers.
APPLICATION → DATA · OWASP LLM01
B · Data PoisoningIllustrative
Crafted records drift a fraud model's decision boundary over three retraining cycles. Documented risk, covered access control — and no operational pipeline anomaly detection anywhere.
DATA → MODEL · ATLAS-INFORMED VALIDATION
C · Model InversionIllustrative
Systematic queries reconstruct customer financial profiles from a fine-tuned LLM. A Model-layer design decision creates an Operations-layer blind spot.
MODEL → OPERATIONS · DIFFERENTIAL PRIVACY
D · Infrastructure ExposureEmpirical · 2025
DeepSeek's unauthenticated ClickHouse database: a million log lines of chat history and secrets, found in minutes. In an AI system, the telemetry is the user data.
OPERATIONS + DATA + GOVERNANCE · ISO 27001
E · Identity CompromiseEmpirical · 2024
~165 Snowflake customer tenants breached with stale, single-factor credentials — the AI data estate compromised upstream of every model trained on it.
GOVERNANCE + OPERATIONS + DATA · ATT&CK T1078
The maturity model

Four levels, scored where it matters

L1

Ad Hoc

Reactive and person-dependent. Cannot pass the five floor questions.

L2

Controlled

Floor met: inventory, governance body, live accountability, identity trust, AI observability.

L3

Integrated

Architecture substantively in place; findings reach governance on a schedule.

L4

Adaptive

The feedback loop has authority; posture evolves continuously, per estate.

Report the per-layer profile, not an average — high capability in one layer can coexist with Ad Hoc indicators in another. Your weakest layer is your programme's real level.

The toolkit · free download

Everything, openly released

Versioned drafts with provisional scoring. Use them, break them, and tell us what the thresholds should be — anonymised practitioner results are the validation path. Every download asks for your email once — it's how we send updated versions and invite you into the validation cohort. One email unlocks the entire toolkit.

AISIF Practitioner White Paper v1.1

DOCX

The full framework: architecture, control domains, standards crosswalks, maturity model, case studies A–E, and both instruments as appendices.

Download the white paper →EMAIL REQUIRED · JOINS THE VALIDATION COHORT

Maturity Self-Assessment (Instrument)

DOCX

The 26-question instrument with rationale and maturity linkage for every question, assessment instructions, and the provisional scoring note.

Download the instrument →EMAIL REQUIRED · JOINS THE VALIDATION COHORT

Maturity Self-Assessment (Workbook)

XLSX

Formula-driven workbook: metadata capture, one tab per layer, per-estate answers, and a dashboard computing floor status and indicative levels.

Download the workbook →EMAIL REQUIRED · JOINS THE VALIDATION COHORT

New AI System Assessment (Workbook)

XLSX

The deployment gate: system profile and risk tier, 30 control checks with evidence columns, recommendation logic, and the governance sign-off block.

Download the workbook →EMAIL REQUIRED · JOINS THE VALIDATION COHORT

Case Study D — DeepSeek (Empirical)

DOCX

Full analysis of the January 2025 ClickHouse exposure: layer tables, control crosswalk, maturity indicators, mitigations, and sources.

Download Case Study D →EMAIL REQUIRED · JOINS THE VALIDATION COHORT

Case Study E — Snowflake (Empirical)

DOCX

Full analysis of the 2024 identity campaign: the shared-responsibility failure, per-estate maturity argument, and the ATT&CK-not-ATLAS finding.

Download Case Study E →EMAIL REQUIRED · JOINS THE VALIDATION COHORT

Conference Deck — BSides Edmonton 2026

PPTX

24 slides with speaker notes: the architecture, the empirical cases, and both instruments. Reuse internally for briefings.

Download the deck →EMAIL REQUIRED · JOINS THE VALIDATION COHORT

Conference Deck — SecTor 2026

PPTX

The SecTor edition of the same talk. The three-actions slide doubles as a 30-60-90 day starting plan.

Download the deck →EMAIL REQUIRED · JOINS THE VALIDATION COHORT

LICENSED CC BY 4.0 — FREE TO USE, SHARE, AND ADAPT WITH ATTRIBUTION · creativecommons.org/licenses/by/4.0

Community & validation

Help validate the instruments

The maturity thresholds, floor questions, and gate criteria are labelled provisional for a reason: they are hypotheses awaiting practitioner data. If you run either assessment, sharing anonymised results — even just your per-layer profile and sector — directly shapes the next version.

Share feedback or results

AISIF is maintained by Ola Lawal, a Canadian Cyber Security Professional based in Calgary, Alberta, Canada.

See AISIF presented