Start with the deployed boundary
An AI security assessment is only meaningful when the assessed system is explicit: model and version, retrieval sources, tools, identities, data flows, external services, downstream actions, operators, and environments. AITBM uses architecture-specific weights and deployment tiers so a standalone model is not treated like an autonomous production agent.
Evaluate three independent layers
The Intrinsic Vulnerability Profile measures Robustness, Fairness, Transparency, Privacy, and Containment through 23 sub-metrics. Operational Risk Posture measures how autonomy, attacker exposure, graph-derived cascade potential, and remediation difficulty amplify the consequence of weakness. Assurance Confidence records whether the assessment evidence is trustworthy and fresh.
Minimum Viability Thresholds remain independent of the composite score. This prevents a severe failure in a critical axis from being averaged away by unrelated strengths.
Produce an evidence-ready result
A defensible result includes rubric placements, test artifacts, architecture and tier, unknown and not-applicable decisions, MVT findings, ORP inputs, ACI components, the ERS calculation, and reassessment triggers. The public case library demonstrates this trace from source evidence to an indicative scenario without presenting retrospective articles as assessments of record.
A practical next step
Choose one system boundary, document the architecture and deployment tier, and test the evidence required by the applicable sub-metrics. Record unknown evidence explicitly instead of treating it as a passing control.