AI Security Observability Gap Self-Assessment

AI Security Self-Assessment

Score your organization against the five Observability Gap signals

Ten questions. About four minutes. Self-scored against a transparent rubric. The result is an Observability Gap score from 0–100 and a recommended next step based on where your organization sits today.

How It Works

The 10-question Observability Gap self-assessment

For each question below, choose the option that best describes your organization today. Each option lists the points you award yourself. Add up your total at the end — be honest, the assessment is for you, not for us.

01

Shadow-AI inventory

When was the last time you conducted a comprehensive inventory of every AI service touching your organization’s data?

Within the past 6 months10 pts
Within the past 12 months7 pts
More than 12 months ago, but we have done one3 pts
Never, or we don’t know0 pts
02

SOC visibility into AI prompts

Can your security operations center answer the question “what prompts have employees sent to AI tools in the past 24 hours, and which contained sensitive data?”

Yes, comprehensively10 pts
Yes, partially (some tools or some users covered)5 pts
No0 pts
03

SOC visibility into AI outputs

Can your SOC answer “what has the AI returned to users, and did any responses contain sensitive data that should not have left the system?”

Yes, comprehensively10 pts
Yes, partially5 pts
No0 pts
04

Prompt injection defenses

Have you implemented dedicated prompt injection defenses on any of your production AI deployments?

Yes, on most or all deployments10 pts
Yes, on some deployments5 pts
No0 pts
05

AI acceptable use policy

Has your organization adopted a formal AI Acceptable Use Policy that addresses generative AI use across departments?

Yes, organization-wide and current10 pts
Yes, but only in some departments or outdated5 pts
In progress3 pts
No0 pts
06

NIST AI RMF or equivalent framework mapping

Have you mapped your AI use cases to a recognized framework (NIST AI Risk Management Framework, ISO/IEC 23894, EU AI Act, industry-specific guidance)?

Yes, all major AI use cases mapped10 pts
Yes, some use cases mapped5 pts
No, but planning to3 pts
No, and not planning to0 pts
07

Board AI risk briefing

Has your board of directors received a formal briefing on AI risk in the past 12 months?

Yes, multiple times10 pts
Yes, once7 pts
Scheduled but not yet held3 pts
No0 pts
08

Vendor AI clauses

Have you added AI-specific clauses (data residency, training opt-out, AI security obligations) to your vendor contracts in the past 12 months?

Yes, in most new contracts10 pts
Yes, in some new contracts5 pts
Planning to3 pts
No0 pts
09

AI-specific incident response capability

Does your incident response playbook address AI-specific incidents (model compromise, prompt-injection-driven data leak, hallucinated decision in a regulated workflow)?

Yes, with tested procedures10 pts
Yes, with documented but untested procedures5 pts
In progress3 pts
No0 pts
10

AI system adversarial testing

Have your AI systems undergone adversarial testing (prompt injection, model extraction, data exfiltration) in the past 12 months?

Yes, on quarterly schedule10 pts
Yes, once7 pts
No, but planned3 pts
No0 pts
Your Result

Total your score and read your result

80–100: Operating at strength

Your organization has closed the Observability Gap on most operational dimensions. Continue the cadence; the work now is sustaining the program through staff turnover, vendor changes, and AI deployment expansion. If you have not yet shared your benchmark with a peer organization or your industry association, consider doing so — mid-market peers at this score are unusual and your operational learnings are valuable to the broader community.

60–79: Substantive progress, specific gaps

Your organization has substantive AI security capability with specific gaps to close. The most common gap at this score range is observability instrumentation (Questions 2 and 3) trailing governance maturity (Questions 5, 6, 7). The Armorstack AI Adoption Security Framework Pillar 3 work is sized exactly for organizations at this stage.

40–59: Foundations in place, operational gaps

You have governance scaffolding in place but the operational capability to execute is incomplete. The most common gap at this score range is shadow-AI inventory (Question 1) and AI-specific incident response (Question 9) lagging policy. Pillars 1 and 4 of the framework address this directly.

20–39: Material Observability Gap

Your organization has a material Observability Gap that warrants prioritized attention over the next two quarters. The risk concentration is highest if your organization is in healthcare (PHI exposure), defense contracting (CUI exposure), financial services (NPI exposure), or processes student records (FERPA exposure). The free 30-day Armorstack AI Risk Assessment is sized specifically for organizations in this score range.

0–19: Structural exposure

Your organization has structural AI security exposure that warrants immediate attention. This score is most common at organizations that have rapidly adopted generative AI without a corresponding security program build-out. The risk is that an AI-mediated incident occurs before the security program catches up. Reach out to Armorstack directly at [email protected] or 877-890-5508 — we can discuss what your team should prioritize in the next 90 days regardless of whether you engage us formally.

Apply Your Score

Apply your score to the next step

Whatever you scored, the most productive next move is to apply for the free 30-day AI Risk Assessment. Organizations at every score range benefit:

High scorers

External verification of your internal assessment — useful for board reporting and examiner discussions.

Mid scorers

A prioritized close-the-gap roadmap aligned to NIST AI RMF and the regulatory framework governing your industry.

Low scorers

A structural baseline assessment you can use to make the case for AI security investment at your next budget cycle.

The assessment is open to the first 50 qualifying mid-market organizations (100–2,500 employees; healthcare, manufacturing, defense, financial services, or K-12) through Friday, July 24, 2026.

Use your score. Apply now.

Free 30-day AI Risk Assessment. First 50 qualifying mid-market organizations.