A way for security leaders to think about AI security risk.
James Shank · Author · Published by Expel ·↗ expel.com
The publication
James developed a framework for thinking about AI security risk, and Expel published it as A guide to thinking about AI security risk. The full framework is in that guide.
Overview
The framework gives a security leader a structure for securing an enterprise in the age of AI. It maps AI risk, assigns each mitigation to the department that should own it, and reports business impact to the board.
The framework has two halves. Ten risk domains show where risk appears, and six control planes show where an organization keeps or loses control. Each domain has one primary control plane and, in most cases, some secondary planes, as Figure 1 shows.
Figure 1. The ten risk domains as rows, against the six control planes as columns. A filled circle marks the primary plane of a domain and an open circle marks a secondary plane. Domain 10 covers all six planes. Adapted from Expel, 2026.