# The AI Security Playbook - aisecurity.zone - [Start here](https://aisecurity.zone/) - [By risk ID](https://aisecurity.zone/reference/by-id/) - [Cheat sheet](https://aisecurity.zone/reference/cheat-sheet/) - [Tooling roster](https://aisecurity.zone/reference/tooling/) - [Glossary](https://aisecurity.zone/reference/glossary/) - [Orientation & how to use this](https://aisecurity.zone/orientation/) - [One system, end to end](https://aisecurity.zone/walkthrough/) - [Overview - all 7 chapters](https://aisecurity.zone/model/) - [I.1 · How a model works](https://aisecurity.zone/model/how-a-model-works/) - [I.2 · Shaping a model - training, tuning, alignment](https://aisecurity.zone/model/shaping-a-model/) - [I.3 · Training data - extraction and poisoning](https://aisecurity.zone/model/training-data/) - [I.4 · Adversarial machine learning](https://aisecurity.zone/model/adversarial-ml/) - [I.5 · The model artifact & its supply chain](https://aisecurity.zone/model/supply-chain/) - [I.6 · Protecting weights in use - TEEs & attestation](https://aisecurity.zone/model/protecting-weights/) - [I.7 · Frontier capability & the if-then frameworks](https://aisecurity.zone/model/frontier-capability/) - [Overview - all 5 chapters](https://aisecurity.zone/context/) - [II.1 · How LLMs work - tokens, attention, context](https://aisecurity.zone/context/how-llms-work/) - [II.2 · Prompt injection & the LLM attack surface](https://aisecurity.zone/context/prompt-injection/) - [II.3 · Jailbreaks & guardrail bypasses](https://aisecurity.zone/context/jailbreaks/) - [II.4 · Multimodal - what a text filter cannot see](https://aisecurity.zone/context/multimodal/) - [II.5 · Guardrails - what holds, and how to prove it](https://aisecurity.zone/context/guardrails/) - [Overview - all 5 chapters](https://aisecurity.zone/loop/) - [III.1 · Anatomy of an agent - model, tools, memory, loop](https://aisecurity.zone/loop/anatomy-of-an-agent/) - [III.2 · Coding agents & Codex security](https://aisecurity.zone/loop/coding-agents/) - [III.3 · Browser & computer-use agents](https://aisecurity.zone/loop/browser-and-computer-use/) - [III.4 · Persistence & propagation - memory poisoning, worms](https://aisecurity.zone/loop/persistence-and-propagation/) - [III.5 · Consent & containment - sandboxes, approvals, blast radius](https://aisecurity.zone/loop/consent-and-containment/) - [Overview - all 6 chapters](https://aisecurity.zone/protocol/) - [IV.1 · Model APIs & the tool-use loop](https://aisecurity.zone/protocol/model-apis/) - [IV.2 · Model Context Protocol (MCP)](https://aisecurity.zone/protocol/mcp/) - [IV.3 · The MCP assessment runbook](https://aisecurity.zone/protocol/mcp-runbook/) - [IV.4 · Multi-agent systems, A2A & the seams](https://aisecurity.zone/protocol/multi-agent/) - [IV.5 · Hardening MCP - gateways, allowlists, runtime defense](https://aisecurity.zone/protocol/hardening-mcp/) - [IV.6 · Agent identity & access (NHI)](https://aisecurity.zone/protocol/agent-identity/) - [Overview - all 3 chapters](https://aisecurity.zone/infra/) - [V.1 · Where AI runs - the cloud, from scratch](https://aisecurity.zone/infra/cloud/) - [V.2 · Cloud security & red-teaming - AWS, Azure, GCP](https://aisecurity.zone/infra/cloud-red-teaming/) - [V.3 · The data layer - stores & retrieval entitlement](https://aisecurity.zone/infra/data-layer/) - [Overview - all 6 chapters](https://aisecurity.zone/method/) - [VI.1 · Security, safety & who is actually attacking you](https://aisecurity.zone/method/security-and-adversaries/) - [VI.2 · The five boundaries](https://aisecurity.zone/method/five-boundaries/) - [VI.3 · Threat modeling for AI systems](https://aisecurity.zone/method/threat-modeling/) - [VI.4 · The AI red-team playbook](https://aisecurity.zone/method/red-team-playbook/) - [VI.5 · Running the engagement](https://aisecurity.zone/method/engagement/) - [VI.6 · Capability & assurance evaluation](https://aisecurity.zone/method/capability-and-assurance/) - [Overview - all 5 chapters](https://aisecurity.zone/program/) - [VII.1 · The secure AI SDLC](https://aisecurity.zone/program/build-lifecycle/) - [VII.2 · The Agent Development Lifecycle (Agent DLC)](https://aisecurity.zone/program/agent-lifecycle/) - [VII.3 · Detection, IR & forensics for AI](https://aisecurity.zone/program/detection-and-ir/) - [VII.4 · Finding the AI you do not know about](https://aisecurity.zone/program/shadow-ai/) - [VII.5 · Retirement & decommissioning](https://aisecurity.zone/program/retirement/) - [Overview - all 6 chapters](https://aisecurity.zone/govern/) - [VIII.1 · Frameworks & standards - four altitudes](https://aisecurity.zone/govern/frameworks/) - [VIII.2 · Google SAIF - the controls layer](https://aisecurity.zone/govern/saif/) - [VIII.3 · NIST AI RMF - the risk process](https://aisecurity.zone/govern/nist-ai-rmf/) - [VIII.4 · ISO/IEC 42001, verification & maturity](https://aisecurity.zone/govern/iso-42001-and-maturity/) - [VIII.5 · Jurisdictions - Singapore, the EU, the US & UK](https://aisecurity.zone/govern/jurisdictions/) - [VIII.6 · The advisor's playbook](https://aisecurity.zone/govern/advisors-playbook/) - [The 2026 incident board](https://aisecurity.zone/reference/incidents/) - [Templates & checklists](https://aisecurity.zone/reference/templates/) - [Reference library](https://aisecurity.zone/reference/reference-library/) - [What's new](https://aisecurity.zone/reference/changelog/) - [About this document](https://aisecurity.zone/reference/about/) - [How to contribute](https://aisecurity.zone/reference/contributing/)