For technical and nontechnical users to understand and prioritize risks inherent to AI models and implement practical solutions to buy down risk across the AI model lifecycle.
Guide Navigator
You are a .
You are a . You want to .
Review your customized guide using the navigation menu.
What This Guide Is
This guide uses a risk-based approach to AI security, helping you assess the risks that your AI systems face and apply prioritized, practical security controls to mitigate those risks across the AI lifecycle. No prior security expertise is required—each section is designed to help you first understand relevant risks inherent to AI models and then prioritize and implement practical solutions to buy down risk across the AI model lifecycle.
We combine industry best practices with subject matter expert insights to
Identify common threats and vulnerabilities in AI models.
Provide targeted risk mitigations, including prioritized security controls and implementation considerations you can apply in your environment.
Highlight additional safeguards for high-risk models or specialized AI systems, including models used in the pharmaceutical or biotechnology sectors.
Who This Guide Is For
Whether you are a . . .
developer integrating security into your development or deployment process
researcher releasing models or datasets
security professional tasked with defending AI infrastructure
policymaker shaping AI governance
. . . you’ll find guidance that scales to the risk and complexity of your AI system, from baseline controls for any AI model to architecture-specific and high-risk model-specific security controls.
Note: The controls in this guide are a prioritized set—a starting point for buying down AI security risk. They do not represent every possible security measure, and additional controls may be needed based on your system’s architecture, threat exposure, and operational environment.
How To Use This Guide
You do not need to read the guide from start to finish. Use the Navigation Tool to jump directly to the sections that matter most to you. You may also start by identifying your system’s risk profile using the accompanying Risk Assessment and Security Control Prioritization tool. Then, navigate to the sections detailing the controls that best address your specific threats, vulnerabilities, and operational context.
Each section of this guide
stands on its own so you can focus on what’s most relevant to you
links to related topics for deeper exploration
uses icons to signal guidance for specific roles.
Note: This guide is not a substitute for professional cybersecurity expertise in high-risk environments. But it will help you take the first steps toward protecting the confidentiality, integrity, and availability of your AI systems. Security is one part of a broader responsible AI posture; organizations should pair these safeguards with governance, ethical review, and operational oversight to ensure that AI remains secure, reliable, and trustworthy.