Score your organization against the five Observability Gap signals
Ten questions. About four minutes. Self-scored against a transparent rubric. The result is an Observability Gap score from 0–100 and a recommended next step based on where your organization sits today.
The 10-question Observability Gap self-assessment
For each question below, choose the option that best describes your organization today. Each option lists the points you award yourself. Add up your total at the end — be honest, the assessment is for you, not for us.
Shadow-AI inventory
When was the last time you conducted a comprehensive inventory of every AI service touching your organization’s data?
SOC visibility into AI prompts
Can your security operations center answer the question “what prompts have employees sent to AI tools in the past 24 hours, and which contained sensitive data?”
SOC visibility into AI outputs
Can your SOC answer “what has the AI returned to users, and did any responses contain sensitive data that should not have left the system?”
Prompt injection defenses
Have you implemented dedicated prompt injection defenses on any of your production AI deployments?
AI acceptable use policy
Has your organization adopted a formal AI Acceptable Use Policy that addresses generative AI use across departments?
NIST AI RMF or equivalent framework mapping
Have you mapped your AI use cases to a recognized framework (NIST AI Risk Management Framework, ISO/IEC 23894, EU AI Act, industry-specific guidance)?
Board AI risk briefing
Has your board of directors received a formal briefing on AI risk in the past 12 months?
Vendor AI clauses
Have you added AI-specific clauses (data residency, training opt-out, AI security obligations) to your vendor contracts in the past 12 months?
AI-specific incident response capability
Does your incident response playbook address AI-specific incidents (model compromise, prompt-injection-driven data leak, hallucinated decision in a regulated workflow)?
AI system adversarial testing
Have your AI systems undergone adversarial testing (prompt injection, model extraction, data exfiltration) in the past 12 months?
Total your score and read your result
80–100: Operating at strength
Your organization has closed the Observability Gap on most operational dimensions. Continue the cadence; the work now is sustaining the program through staff turnover, vendor changes, and AI deployment expansion. If you have not yet shared your benchmark with a peer organization or your industry association, consider doing so — mid-market peers at this score are unusual and your operational learnings are valuable to the broader community.
60–79: Substantive progress, specific gaps
Your organization has substantive AI security capability with specific gaps to close. The most common gap at this score range is observability instrumentation (Questions 2 and 3) trailing governance maturity (Questions 5, 6, 7). The Armorstack AI Adoption Security Framework Pillar 3 work is sized exactly for organizations at this stage.
40–59: Foundations in place, operational gaps
You have governance scaffolding in place but the operational capability to execute is incomplete. The most common gap at this score range is shadow-AI inventory (Question 1) and AI-specific incident response (Question 9) lagging policy. Pillars 1 and 4 of the framework address this directly.
20–39: Material Observability Gap
Your organization has a material Observability Gap that warrants prioritized attention over the next two quarters. The risk concentration is highest if your organization is in healthcare (PHI exposure), defense contracting (CUI exposure), financial services (NPI exposure), or processes student records (FERPA exposure). The free 30-day Armorstack AI Risk Assessment is sized specifically for organizations in this score range.
0–19: Structural exposure
Your organization has structural AI security exposure that warrants immediate attention. This score is most common at organizations that have rapidly adopted generative AI without a corresponding security program build-out. The risk is that an AI-mediated incident occurs before the security program catches up. Reach out to Armorstack directly at [email protected] or 877-890-5508 — we can discuss what your team should prioritize in the next 90 days regardless of whether you engage us formally.
Apply your score to the next step
Whatever you scored, the most productive next move is to apply for the free 30-day AI Risk Assessment. Organizations at every score range benefit:
High scorers
External verification of your internal assessment — useful for board reporting and examiner discussions.
Mid scorers
A prioritized close-the-gap roadmap aligned to NIST AI RMF and the regulatory framework governing your industry.
Low scorers
A structural baseline assessment you can use to make the case for AI security investment at your next budget cycle.
The assessment is open to the first 50 qualifying mid-market organizations (100–2,500 employees; healthcare, manufacturing, defense, financial services, or K-12) through Friday, July 24, 2026.
Use your score. Apply now.
Free 30-day AI Risk Assessment. First 50 qualifying mid-market organizations.