Framework · 24 September 2026

AI Security Risk Framework

A way for security leaders to think about AI security risk.

James Shank · Author · Published by Expel ·↗ expel.com

The publication

James developed a framework for thinking about AI security risk, and Expel published it as A guide to thinking about AI security risk. The full framework is in that guide.

Overview

The framework gives a security leader a structure for securing an enterprise in the age of AI. It maps AI risk, assigns each mitigation to the department that should own it, and reports business impact to the board.

The framework has two halves. Ten risk domains show where risk appears, and six control planes show where an organization keeps or loses control. Each domain has one primary control plane and, in most cases, some secondary planes, as Figure 1 shows.

Figure 1. The ten risk domains against the six control planes. A grid. The rows are the ten risk domains of the framework. The columns are the six control planes: Data, Identity, Execution, Human, External AI and service, and Observability. A filled circle marks the primary plane of each domain. An open circle marks a secondary plane. Domain 1, Data exposure: primary Data; secondary External AI and service, Observability. Domain 2, Identity degradation: primary Identity; secondary Execution, Observability. Domain 3, Instruction manipulation: primary Execution; secondary Data, Human, External AI and service, Observability. Domain 4, Vulnerability and exploit acceleration: primary Execution; secondary Data, External AI and service. Domain 5, Attack chain compression: primary Execution; secondary Identity, Data, Observability. Domain 6, Post-compromise amplification: primary Data; secondary Execution, Observability. Domain 7, Human trust exploitation: primary Human; secondary Identity, Execution, External AI and service. Domain 8, Defender disruption: primary Execution; secondary Human, Observability. Domain 9, External control loss: primary External AI and service; secondary Data, Execution, Observability. Domain 10, Observability collapse: primary Observability, and it covers all six planes. A bar in the accent color marks domain 10 across the full row. Data Identity Execution Human External AI and service Observability 1 Data exposure 2 Identity degradation 3 Instruction manipulation 4 Vulnerability and exploit acceleration 5 Attack chain compression 6 Post-compromise amplification 7 Human trust exploitation 8 Defender disruption 9 External control loss 10 Observability collapse Primary plane Secondary plane Covers all six planes
Figure 1. The ten risk domains as rows, against the six control planes as columns. A filled circle marks the primary plane of a domain and an open circle marks a secondary plane. Domain 10 covers all six planes. Adapted from Expel, 2026.

Where James presented it

What comes next

James will add to the framework here as it develops: supporting material, notes on implementation, related writing, and each revision.