The AI Security Checklist
Twelve practical controls for shipping LLM and agent systems you can actually trust — the essentials, in priority order, that separate a demo from a defensible deployment.
Distilled from the work of Steve Wilson (OWASP Gen AI Security), Andrej Karpathy, Simon Willison, and Nicholas Carlini, and mapped to the OWASP LLM Top 10, NIST AI RMF, Google SAIF, and MITRE ATLAS. Tick items off as you go — your progress is saved in this browser.
Who this is built on.
Author of The Developer's Playbook for Large Language Model Security; a foremost voice on practical, defense-in-depth security for LLM applications and agents.
Frames LLMs as a new computing substrate and has repeatedly flagged prompt injection and untrusted model output as core, unsolved security challenges of the era.
Coined the term “prompt injection” and the “lethal trifecta” framing, and popularised patterns like the dual-LLM design for handling untrusted content safely.
Leading work on data poisoning, model extraction, and the practical limits of ML robustness — the research underpinning the supply-chain and extraction controls above.
Want us to run the checklist for you?
We assess your AI systems against every control here — red-teaming, remediation, and audit-ready evidence, mapped to the frameworks that matter.