Lesson 33 of 35AI-SPMAI-SPM

What is AI-SPM?AI Security Posture & Governance explained

Inventories AI models, applications, agents, data flows, and services; maps their ownership and risk; and helps teams govern AI use against policy and control frameworks.

By Reviewed

Verified Sources: nist.gov, cloudsecurityalliance.org, cisa.gov

The lesson

Finding and governing the AI you actually use

An organization cannot secure models, applications, agents, and AI services it does not know exist. This lesson shows how AI discovery becomes an owned inventory, a risk posture, and an enforceable governance program.

If it helps, think of it as… the aircraft register

An airline cannot maintain a safe fleet from expense reports alone. It needs a register of every aircraft, who operates it, where it flies, which parts it contains, and when it was last inspected. AI posture management builds the same operating picture for models, services, applications, data flows, and agents — including the unofficial ones employees adopted on their own.

Discover

Models, apps, services, agents, shadow AI

Assign ownership

Purpose, team, data, provider, lifecycle

Assess risk

Exposure, access, data, controls, impact

Apply policy

Approve, restrict, remediate, or retire

Monitor change

Catch new assets and posture drift

…then the loop starts again — this runs continuously, not once.

AI posture is maintained as a continuous loop because models, providers, prompts, data connections, and agent permissions change constantly.

Start with visibility

AI security programs often begin after a team has already adopted several kinds of AI: public assistants, model APIs, open-source models, internal applications, and experimental agents. Procurement records reveal some of them, but not the complete technical picture.

Discovery combines signals from the places AI is built and used. Depending on the environment, that can include cloud accounts, model platforms, code repositories, gateways, network traffic, browsers, and endpoints. The result should distinguish the model from the application that calls it and the agent from the tools it can operate.

Turn a list into an inventory

A useful inventory records why an AI asset exists, who owns it, where it runs, which provider or model it uses, what data it can access, and whether it is experimental or production. Those details determine the impact of a failure and who can fix it.

Lineage matters too. A model may come from an external repository, be fine-tuned internally, and then be embedded in several applications. Treating every deployment as an unrelated asset hides the shared supply-chain risk.

Assess posture

Posture findings describe conditions that raise risk: public exposure, excessive permissions, sensitive-data access, unapproved providers, missing evaluations, unknown model origin, or no runtime monitoring. The severity should reflect both exploitability and business impact.

No single posture score proves that an AI system is secure. A system can be configured correctly and still produce unsafe behavior. Posture is the operating map that tells testing and runtime teams where to focus.

Make governance enforceable

Policy should be specific enough to drive a decision. Examples include which providers may receive regulated data, which model sources are approved, when red teaming is required, which tools an agent may use, and who can authorize production deployment.

Frameworks such as the NIST AI RMF help organize responsibilities and outcomes. They do not replace an organization's own risk analysis, and a tool's framework mapping is not an audit or certification.

What good looks like

A mature program can answer: what AI do we run, who owns it, what data and authority does it have, how was it tested, which controls protect it, and what changed since the last review? Those answers should be backed by current technical evidence rather than a once-a-year questionnaire.

Terms you just met

Each links to its plain-language definition in the glossary.

The field guide

Evaluating this category

A second pass for buyers: market context, distinctions that matter, and what to weigh when tools in this category start looking alike.

AI security starts with a basic inventory question: which models, applications, agents, providers, data sources, and tools are actually in use? The answer is rarely contained in one cloud account or procurement list. Developers may call hosted models directly, business teams may adopt public assistants, and agents may connect to internal systems through APIs or tool protocols.

AI security posture and governance products build that operating picture. They discover AI assets, connect them to owners and data flows, identify missing controls, and help teams enforce policy across the lifecycle. This is commonly described as AI security posture management, or AI-SPM.

What this category covers

Discovery finds approved and unapproved AI services, model endpoints, applications, agents, and supporting infrastructure. Inventory adds context: who owns the system, what it does, which data it handles, where it runs, and whether it is in development or production.

Posture assessment then looks for risk. Examples include exposed model endpoints, over-permissioned agents, unapproved providers, sensitive-data paths, missing runtime controls, or models whose origin and integrity are unclear. Governance turns those findings into decisions and evidence: approve, restrict, remediate, monitor, or retire.

How it differs from ordinary GRC

Traditional GRC platforms manage controls, policies, risks, and audit evidence across an organization. AI governance uses those same disciplines but adds AI-specific technical context: model lineage, prompt and retrieval flows, agent tools, model providers, evaluation results, and lifecycle state.

The two categories complement each other. AI posture products can produce technical evidence and asset context; GRC systems can connect that evidence to broader enterprise risk and compliance programs.

What to compare

Start with discovery coverage. Confirm which clouds, repositories, model platforms, gateways, browsers, and endpoints the product can observe. Ask whether it distinguishes a foundation model from an application built on that model, and whether it can represent agents, tools, and data sources as separate assets.

Then examine ownership and policy. A useful inventory should support accountable owners, lifecycle status, data classification, and approved-use policy—not just a long list of endpoints. Framework mappings can help organize work, but a mapping is not proof that the organization or product is compliant.

Finally, test how posture changes become action. Findings should route into the team's existing ticketing, security operations, cloud, development, and risk workflows. A dashboard that cannot assign or verify remediation becomes another inventory to maintain.

Limits

Discovery is never absolute. Encrypted traffic, local models, new providers, isolated networks, and unmanaged devices can leave blind spots. Coverage also changes as teams adopt new model APIs and agent frameworks.

Posture management does not replace adversarial testing or runtime enforcement. It tells a team what exists and where risk may be concentrated; the adjacent testing and runtime categories determine whether the system withstands attacks and blocks unsafe behavior.

Primary references

Capability taxonomy

What buyers typically evaluate when comparing tools in this category.

AI asset discovery
Finds models, AI services, applications, agents, and related infrastructure across development and production environments.
Inventory & ownership
Maintains an inventory of AI assets, their owners, lineage, purpose, and deployment status.
AI risk posture
Identifies risky configurations, exposed assets, unapproved services, and missing safeguards.
Policy & governance
Defines and evaluates policies for approved models, providers, data use, and AI application behavior.
Framework mapping
Maps AI risks and controls to frameworks such as the NIST AI RMF and OWASP guidance.
Shadow AI monitoring
Detects unsanctioned workforce use of AI applications and services.

Tools in this category

Now that you know what AI-SPM does, see who does it.

Search Cyber Tool Stack

Jump to any tool, vendor, category, or glossary term.