Today I released a piece of work I've been developing over many months: the AI Guardrails Maturity Model. It's a free, open reference that guides engineers on effective AI security guardrails, and where to go next as a team levels up their controls.
https://lnkd.in/edEWJsJ9
I built it for two reasons.
First, my own work at Netlify developing agents for our Security Team. Building agentic systems in production surfaces security gaps quickly. It's essentially like handing access keys to an intern who just got back from happy hour. Any problem you have gets amplified fast.
Second, I've had a number of conversations through IANS with organizations working through every maturity level of AI security. Many of these discussions come back to the security controls around traditional and agentic systems: where to be now, and what comes next. There's excellent guidance out there from NIST, OWASP, MITRE, and CISA, but none of it gives you the sequence. Which controls come first, which can wait, and which only matter once you go agentic.
So I built the sequence: crawl, walk, run. 36 controls across 13 categories, each placed at the maturity level where it should first appear, from Basic through Leading Edge.
One thing I want to be clear about: this is not a bingo card. The goal is not to implement all 36 controls. Many will be irrelevant to your system, and that's expected. Scope it to your architecture first, build the basics, and level up from there.