Safeguard
Concepts & Glossary
AI Security

AI-SPM (AI Security Posture Management)

Continuous inventory and risk assessment of every model, agent and AI service in the estate.

Browse all concepts
◈ the lookup — ai security — the posture layer
Definition

What is AI Security Posture Management?

AI-SPM is continuous discovery and risk assessment for the AI layer: every model in use, every agent that can act, every MCP server exposed, every API key pointed at a model provider, and the data each of them can reach. It is the same idea as cloud posture management, applied to a layer that most organisations cannot currently enumerate.

The distinguishing property is that the estate is not declarative. Cloud resources exist in an account and can be listed. An AI estate is a mixture of hosted APIs, self-hosted weights, notebooks, agent frameworks and browser extensions, and much of it was adopted by individuals rather than provisioned centrally. Discovery is the hard half of the problem.

Mechanism

How it works

Three loops, run continuously rather than as an audit:

  1. 01

    Discover

    Enumerate hosted model endpoints, self-hosted weights, agent frameworks, MCP servers and the credentials pointed at each. This is where shadow AI surfaces — usage nobody registered.

  2. 02

    Assess

    For each one: what data can it reach, what actions can it take, whose credentials does it hold, is it exposed to untrusted input, and what is its provenance. An AI-BOM is the durable form of this inventory.

  3. 03

    Monitor for drift

    Model versions change, scopes widen, tools get added. Drift detection is what keeps the assessment true a month after it was made.

Stakes

Why it matters

You cannot govern what you cannot list. Most organisations adopted AI faster than they inventoried it, and the resulting estate contains agents holding production credentials that no security review ever saw. The first AI-SPM run is usually the first complete list anyone has had.

The exposures are also unfamiliar. A model endpoint with an over-broad key, an agent with shell access and no scoping, an MCP server pulled from a public registry — none of these look like a CVE, none appear in a vulnerability scan, and all of them are reachable by prompt injection from any document the model reads.

Regulation is arriving on the same timeline. The EU AI Act and the emerging ISO/IEC 42001 audits both start from an inventory of AI systems and their risk classification, which is exactly what AI-SPM produces as a by-product.

Value

What value it adds

An actual list

Every model, agent, MCP server and provider key in one place, discovered rather than self-reported.

Shadow AI surfaced

The usage nobody registered is precisely the usage nobody reviewed.

Blast radius per agent

What each agent can read and do, which is the number that matters when one is compromised.

Drift you can see

A scope that widened or a model version that changed is an event, not something discovered during an incident.

Evidence for AI governance

The EU AI Act and ISO/IEC 42001 both begin with an inventory. This is that inventory.

In the product

How Safeguard uses it

Safeguard discovers models, agents and MCP servers across the estate, records each one's data reach and permissions, and tracks change over time. See OSM and the AI governance workflow.

Get the list first.

Safeguard discovers every model, agent and MCP server in the estate, and what each one can reach.

Browse all concepts

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.