AI Security FAQ — Complete Reference

AI Security FAQ — Complete Reference

Every AI security question Armorstack has answered, in one place

This page consolidates every published question and answer from Armorstack’s AI Adoption Security Framework, vertical cuts, and comparison pages into a single searchable reference. Browse by topic below, or use your browser’s find function to search the full text.

250
Questions Answered
42
Topics Covered
1
Nationwide Operating Model
Topic · 12 questions

About the Framework

Read the full About the Framework page →

What is the Observability Gap?
The Observability Gap is the widening distance between how fast mid-market enterprises are deploying AI and how slowly their security operations are gaining the visibility, classification, governance, and validation capacity required to secure it. It is not a tooling gap; it is an operating-model gap. The risk is that AI systems generate, transmit, and act on sensitive data inside organizations whose SOCs cannot see what the AI is doing — and cannot detect when it has been manipulated, exfiltrated, or used as a pivot.
How is the Armorstack framework different from a NIST AI RMF implementation guide?
The NIST AI Risk Management Framework defines the functions an organization should perform; it does not prescribe the operating model that performs them. Armorstack’s framework is a delivery methodology built around how a mid-market organization with finite security resources actually executes the NIST functions — who does the work, on what cadence, against what telemetry, with what governance artifacts produced.
Does my organization need this if we don’t use AI yet?
Pillar 1 — discovery — almost always finds AI in environments where leadership did not believe AI was in use. SaaS vendors are embedding AI in products you already license; employees are using public LLM interfaces against organizational data; departments are signing up for AI-augmented tooling without an updated security review.
How long does the framework take to implement?
A typical mid-market organization completes Pillars 1 and 2 in 30 to 60 days, Pillar 3 in 60 to 120 days depending on the SIEM and tooling baseline, Pillar 4 in 30 to 90 days running in parallel with Pillars 1 to 3, and reaches the first Pillar 5 validation cycle within six months of program start.
What does this cost?
The free 30-day AI Risk Assessment is the entry point for the first 50 qualifying organizations. Ongoing program work is scoped to the organization’s risk register; mid-market engagements typically run between $4,000 and $18,000 per month inclusive of vCISO time, SOC observability, validation testing, and policy work.
Is this only available in Wisconsin?
The framework is available to mid-market organizations in any U.S. state. Armorstack serves clients nationwide, with active engagements across the Midwest, South, and East Coast.
How is this different from an MSP or MSSP?
An MSP is built to operate IT. An MSSP is built to operate security tools. Neither is structured to operate the converged advisory, IT, security, and physical capability the AI Adoption Security Framework requires. Armorstack delivers as a Managed Intelligence Provider (MIP), a category we use to describe the converged operating model that the framework requires.
What if my AI is running on a major cloud provider’s platform?
The framework is platform-agnostic. AI running on Azure OpenAI, AWS Bedrock, Google Vertex, or self-hosted infrastructure all require the same five pillars; only the technical means of instrumentation differ.
Does the framework cover agentic AI?
Yes. Pillars 1, 3, and 5 are explicitly built to handle the agentic case: an AI system that is taking actions, not just generating text. Discovery enumerates agentic deployments, observability instruments the action chain not just the prompt chain, and validation tests the failure modes specific to autonomous action.
How does this connect to CMMC 2.0 or HIPAA compliance?
The risk register produced in Pillar 2 is explicitly cross-referenced against the regulatory framework governing the data each AI use case touches. For CMMC 2.0 organizations, AI use cases touching CUI receive the controls treatment CMMC requires, applied through the framework.
What does the SOC actually see once Pillar 3 is in place?
Prompt traffic against logged endpoints, model output flagged by DLP rules, behavior patterns indicating prompt-injection attempts or unusual access requests, and the same identity, network, and endpoint signals it sees today — but correlated against the AI inventory so a single incident can be reconstructed across the human, application, and AI surface in one investigation.
How do I get started?
Request the free 30-day AI Risk Assessment at armorstack.ai/ai-risk-assessment/ if your organization fits the eligibility criteria, or contact us to scope a paid engagement structured around the same five pillars.
Topic · 7 questions

About the AI Risk Assessment

Read the full About the AI Risk Assessment page →

Is this really free?
Yes. The 30-day assessment, the deliverable package, and the recommendations workshop are offered at no cost to the first 50 qualifying organizations. Organizations that choose to engage Armorstack for ongoing program work do so on a normal commercial basis.
What’s the catch?
The catch, if there is one, is that we want your time. The assessment requires read-only access to your major SaaS administrative consoles, telemetry from your SIEM and endpoint tooling, and approximately 12 to 16 hours of your security and executive leadership’s time across the 30 days.
What if we’re not selected for the 50?
Organizations not selected for the no-cost cohort can engage on a paid-equivalent scope and the same deliverables. We will also notify the next 50 organizations on the waitlist when capacity opens.
Do we have to sign a multi-year contract afterward?
No. There is no contract requirement to participate in or complete the assessment. The deliverables are yours; what you do with them is your call.
Will Armorstack see our sensitive data during the assessment?
No. The assessment is designed to enumerate AI activity from administrative-console metadata and telemetry summaries — not from inspecting payload content. Where deeper inspection would be required to characterize a specific use case, we will request it explicitly and only under your written authorization.
How do we apply?
Use the contact form at armorstack.ai/contact/ with ‘AI Risk Assessment’ in the subject line, call 877-890-5508, or email [email protected]. We will respond within one business day with eligibility confirmation and a scoping call.
What if our organization is just outside the 100–2,500 employee range?
Contact us. Organizations slightly below 100 employees with substantive AI exposure, and organizations slightly above 2,500 employees that fit the mid-market operating profile, are evaluated case-by-case.
Topic · 5 questions

About the Observability Gap

Read the full About the Observability Gap page →

Who coined the term “Observability Gap”?
Armorstack uses the term to describe the structural distance between mid-market AI adoption and mid-market AI security capability. The term reflects a thesis that the gap is not a tooling problem solvable by buying more security software; it is an operating-model problem requiring a converged advisory, IT, security, and physical-security capability that the existing MSP and MSSP categories do not structurally deliver.
Is the Observability Gap an enterprise-only problem?
No. The Observability Gap is most acute in mid-market organizations precisely because they have AI exposure comparable to enterprises but operate with smaller, more constrained security teams. Enterprises typically have dedicated AI security and governance functions; mid-market organizations rarely do. The Armorstack AI Adoption Security Framework is specifically scoped for mid-market reality.
How quickly does the Observability Gap manifest as a real incident?
The first wave of public AI security incidents in 2024 and 2025 included prompt-injection-driven data leaks, hallucinated decisions causing operational harm, and vendor-side AI compromise affecting downstream organizations. Mid-market organizations have already experienced these incidents, though most have not been publicly reported. The 24-month horizon is the realistic window in which the Observability Gap converts into reportable breach activity for organizations that do not close it.
How does the Observability Gap relate to existing cybersecurity frameworks?
The Observability Gap is the AI-era extension of the same operational challenges the NIST Cybersecurity Framework, ISO 27001, and SOC 2 are designed to address — visibility, classification, governance, and validation — but applied to autonomous and semi-autonomous AI systems acting on sensitive data. The NIST AI Risk Management Framework (AI RMF 1.0) is the formal framework specifically targeted at this problem; the Armorstack framework is a delivery methodology for mid-market implementation of NIST AI RMF.
How do I assess my organization’s Observability Gap?
The free 30-day AI Risk Assessment is open to the first 50 qualifying mid-market organizations and produces a complete observability-gap analysis. Self-assessment against the five operational signals above is a useful starting point; the formal assessment provides the inventory, risk register, gap analysis, and board-ready summary.
Topic · 24 questions

About the Managed Intelligence Provider (MIP) Model

Read the full About the Managed Intelligence Provider (MIP) Model page →

How is an MIP different from an MSP or MSSP?
An MSP manages IT infrastructure and helpdesk. An MSSP monitors security tools. A Managed Intelligence Provider (MIP) unifies managed IT, 24×7 cybersecurity, physical security integration, and executive advisory under one contract, with deterministic observability across all four layers — replacing the six-vendor stack most mid-market organizations currently juggle.
Do I need an MIP, or will a traditional MSP be enough?
If you are a 50-to-500-employee organization in a regulated industry — healthcare, finance, manufacturing, defense, legal, K-12 — you need an MIP. If you are a small business below 30 employees with low compliance exposure, a competent MSP will serve you well. The inflection point is compliance burden plus employee count.
How much does an MIP cost for a mid-market organization?
Typical MIP investment runs $185 to $425 per user per month, or $6,000 to $85,000 per month depending on size and scope. A 150-user healthcare organization with HIPAA overlay typically pays $42,000 to $58,000 monthly — 20 to 35 percent below the six-vendor baseline it replaces.
Can an MIP handle my compliance requirements?
Yes. A genuine MIP delivers compliance evidence packages mapped to your specific framework: HIPAA, HITECH, CMMC 2.0, SOC 2 Type II, PCI-DSS, GLBA, NIST CSF 2.0, NIST 800-171, NIST 800-82, and the emerging NIST AI RMF. Audit-ready evidence is generated by the platform, not assembled manually by your team.
Does an MIP include a CISO or vCIO?
Yes. MIPs staff three fractional executive roles under the VERITY portfolio: virtual CIO, virtual CISO, and virtual CAIO. These are named, contractually committed, hour-backed engagements — not ad-hoc consulting. Most mid-market clients receive 20 to 60 hours of vCIO or vCISO time per month, depending on scope.
How long is a typical MIP contract?
Standard MIP contracts run 36 months because the operational and compliance value accrues across multiple audit cycles and budget years. Armorstack offers a 90-Day No-Contract Proof for organizations that want to validate fit before committing — the first 90 days are evaluation, not commitment.
What happens if I am already working with multiple vendors?
Vendor consolidation is a core MIP value proposition. A typical onboarding rationalizes six to ten existing vendors into the MIP over 60 to 120 days, preserves the relationships that genuinely add value, and terminates the duplicative ones at contract anniversary. Expect 20 to 35 percent reduction in total technology-operations cost within 12 months.
Does an MIP replace my internal IT team?
No. MIPs augment and extend internal teams — they do not replace them. The best outcomes come when an in-house IT director or CIO operates as the client-side partner to the MIP, translating business priorities into technology execution. MIPs eliminate the need for six specialty hires, not the internal leader.
What about AI security and shadow AI?
AI governance is a core MIP competency. MIPs detect shadow AI through DNS telemetry and CASB, run a model risk management program on internal AI deployments, implement the NIST AI Risk Management Framework, and staff a vCAIO for executive-level AI posture. Traditional MSPs and MSSPs are structurally not equipped for this work.
How do I switch from my current MSP to an MIP?
Switching starts with a 30-day discovery and gap assessment, followed by a 60-to-90-day phased transition in which the MIP takes over helpdesk, endpoint management, SOC monitoring, compliance reporting, and physical security integration in sequence. No big-bang cutover. The outgoing MSP retains access to non-critical systems until transition is verified complete.
How is Armorstack different from Kaseya, Connectwise, or other MSP platforms?
Those are tools that MSPs use to operate their business. Armorstack is the MIP itself — we use those tools (and a stack of others) to deliver converged services. Think of it as the difference between ‘car manufacturer’ and ‘CarMax’.
We already have an MSP we like. Why switch?
Most clients don’t switch away from a good MSP to come to Armorstack; they add the security, compliance, and physical components that their MSP doesn’t offer. Over time, if the MSP model is no longer producing value beyond what’s already converged in Armorstack, some clients consolidate. We explicitly don’t pressure that; it’s a decision the client makes on their own timeline.
Can you handle CMMC 2.0 while also covering HIPAA?
Yes. Multi-framework is a primary MIP differentiator. Armorstack’s compliance team maintains control crosswalks across CMMC 2.0, NIST 800-171, HIPAA, SOC 2 Type II, NIST CSF 2.0, ISO 27001, PCI-DSS, NYDFS Part 500, and state-specific requirements. A single control implementation typically satisfies evidence requirements for multiple frameworks.
What’s your typical client size?
Our best-fit range is 75-1,500 employees, single to 20 locations, regulated industry (healthcare, financial services, manufacturing, legal, defense contracting, K-12 education, or SaaS with compliance obligations). We have clients outside that range in both directions, but the MIP model produces the clearest ROI within it.
How do you price transparently?
Published tier pricing on armorstack.ai/core/, /sentry/, /verity/, /citadel/, and this page. No hidden ‘enterprise pricing’ tier behind a sales call. Custom scoping happens only for large multi-site enterprises where facility count and integration scope drive significant variation.
What’s your SLA?
P1 (service down, production-impacting security incident) response within 15 minutes, 24/7. P2 (degraded service, active but non-critical incident) within 1 hour. P3 (general issue, planned change) within 4 business hours. SLA credits apply for misses. Published in full in our MSA.
Do you require long-term contracts?
Minimum 12-month initial term to cover onboarding investment, then month-to-month with 90 days’ notice. No multi-year lock-ins. Early termination is supported if we’re not delivering; the industry standard ‘auto-renewal with 180-day notice window’ traps don’t exist in our contracts.
Can you work with our cyber insurance broker?
Yes. Armorstack-managed environments typically see 15-35% cyber insurance premium reductions because underwriters can verify managed detection, MFA coverage, backup testing, and incident response readiness. We provide attestation documentation directly to your broker.
What is a Managed Intelligence Provider (MIP)?
A Managed Intelligence Provider is a category Armorstack created to describe the converged operating model that mid-market organizations need for the AI era. An MIP combines strategic advisory (vCIO, vCISO), IT-as-a-service, cybersecurity (24/7 SOC, MDR, AI security observability), and physical security under one operations layer. It is the operating model that replaces the MSP and MSSP categories, which were built for an older threat model.
What size organizations does Armorstack serve?
Armorstack serves mid-market organizations between 100 and 2,500 employees in regulated industries — primarily healthcare, manufacturing, defense contracting, financial services, and K-12 education. The MIP model is sized for organizations large enough to be a target for AI-augmented threat actors and to face regulatory exposure, but typically too small to staff dedicated advisory, security, and physical-security teams independently.
Where does Armorstack operate?
Armorstack serves clients across the United States; remote SOC, monitoring, and advisory delivery are location-independent, and on-site engineering is dispatched nationwide. 100+ technical experts deliver the MIP operating model across the footprint.
How long has Armorstack been operating?
Armorstack was founded in 2002 as Caspian Technologies and rebranded as Armorstack in January 2026 to reflect the converged MIP operating model. The company has 24 years of mid-market security operations experience, predating the MIP category formalization by more than two decades.
What is the 90-day no-contract program?
Armorstack offers a 90-day no-contract engagement for prospective mid-market clients to experience the MIP operating model with no long-term commitment. The program covers scoped advisory, security operations, and converged monitoring across the four portfolios for 90 days. Organizations can begin at armorstack.ai/ninety-day-proof/ or via direct contact.
How do the four portfolios work together?
VERITY (strategic advisory and governance), CORE (IT-as-a-service and infrastructure), SENTRY (cybersecurity and threat management), and CITADEL (physical security and integration) are delivered as one operating layer, not as separate practices. The convergence is the point — a single team sees the AI, the network it runs on, the data it touches, and the physical environment it operates in, and correlates events across all four domains in real time.
Topic · 7 questions

About Armorstack

Read the full About Armorstack page →

Who is Armorstack?
Armorstack is a national Managed Intelligence Provider (MIP) — converged cybersecurity, IT-as-a-service, strategic advisory, and physical security for mid-market regulated industries. Founded in 2002 as Caspian Technologies and rebranded as Armorstack in January 2026, the company serves clients across the United States with 100+ technical experts.
When was Armorstack founded?
Armorstack was founded in 2002 under the original name Caspian Technologies. The company operated as Caspian for 24 years securing enterprises, hospitals, financial institutions, and government agencies. In January 2026, the company rebranded as Armorstack to reflect the converged Managed Intelligence Provider operating model and the AI-era thesis around the Observability Gap.
Who founded Armorstack?
Dale Boehm founded the company in 2002 as Caspian Technologies and continues as President and CEO of Armorstack today. He holds CISA and CDPP certifications and has 23 years of infrastructure expertise.
What industries does Armorstack serve?
Armorstack serves mid-market regulated industries: healthcare (HIPAA, EHR security on Epic and Oracle Health/Cerner), financial services (PCI-DSS, SOX, GLBA), manufacturing (OT/IT convergence, NIST 800-82), defense contractors (CMMC 2.0, NIST 800-171), and K-12 education and libraries (E-Rate, CIPA, FERPA, COPPA).
What is Armorstack’s geographic service area?
Armorstack serves clients across the United States, with national accounts in healthcare, defense, and financial services among regulated industries. 24/7 SOC, vCISO, IT, and physical security services are delivered nationwide from a remote-first operating model, with on-site engineering dispatched wherever a client needs it.
How large is Armorstack?
Armorstack employs more than 100 technical experts across security operations, IT, advisory, and physical security disciplines. The company is FCC-licensed as a wholesale telecommunications carrier and an approved E-Rate vendor with active SPIN registration.
How is Armorstack different from a typical MSP or MSSP?
Armorstack is a Managed Intelligence Provider (MIP) — a converged operating model spanning strategic advisory, IT-as-a-service, cybersecurity, and physical security under one operations layer. The MSP and MSSP categories were built for older threat models. The MIP model is purpose-built for the AI era, where mid-market organizations need converged visibility across all four operating domains simultaneously.
Topic · 5 questions

Converged Cyber-Physical Security

Read the full Converged Cyber-Physical Security page →

Isn’t convergence just an integration project we could do ourselves?
In theory, yes. In practice, three things defeat DIY convergence: (1) the tool vendors optimize for single-domain customers and their APIs are messy at the physical/cyber boundary; (2) the correlation rule-writing is an ongoing discipline that needs a dedicated analyst, not a one-time project; (3) when the integration breaks at 2am, you need a team that can troubleshoot both domains. Armorstack delivers the integration as a managed service so your team consumes the outcome rather than owning the integration.
Do we need to replace all our existing physical security hardware?
No. Armorstack CITADEL is hardware-agnostic within the mid-market standard vendors (Avigilon, Hanwha, Axis, Milestone, Genetec, Verkada, Brivo, Kisi, Lenel, S2). We integrate with what you have; we only replace equipment that is end-of-life, insecure by design (legacy analog systems with known vulnerabilities), or not capable of supporting the monitoring integration.
How does this interact with our existing SOC or SIEM?
If you have an in-house SOC or existing SIEM (Splunk, Sentinel, Elastic, Panther, Chronicle), Armorstack integrates with them. Our SENTRY SOC can operate in a 24/7 augmentation model where we cover nights and weekends while your team handles business hours. For full managed service, we run both the SIEM and the SOC end-to-end.
What’s the expected cost?
Converged cyber-physical programs typically run 20-35% less than operating separate cyber and physical programs of equivalent capability, primarily from vendor consolidation, unified monitoring infrastructure, and reduced duplicate licensing. For mid-market organizations, the annual managed services cost ranges from $8,000/month to $40,000/month depending on facility count, user count, and scope. Most clients see cyber insurance premium reductions of 15-30% at renewal, which offsets 10-20% of the program cost directly.
Is this relevant for small locations like a branch office?
Yes, and often more so. Small locations have fewer on-site personnel, smaller IT teams, and worse tooling. Converged monitoring from a central SOC produces the same protection as a small branch would receive in a dedicated security posture — at a fraction of the cost. Retail chains, healthcare networks with satellite clinics, and multi-branch financial services firms are among our highest-value converged clients.
Topic · 8 questions

Healthcare

Read the full Healthcare page →

Does Armorstack work with Epic and Cerner (Oracle Health) environments?
Yes. Armorstack has deep experience with both Epic and Oracle Health (Cerner) environments. SENTRY’s SOC operates Epic-aware and Cerner-aware monitoring rules; our clinical IT practice supports the workflow-sensitive operating posture both environments require. Armorstack engagements typically include explicit Epic or Cerner reference architecture in the security program design.
How does Armorstack handle HIPAA compliance and PHI protection?
Armorstack’s VERITY practice delivers HIPAA Security Rule and Privacy Rule advisory, including ongoing risk analysis, policy development, audit preparation, and Breach Notification Rule readiness. SENTRY operates a HIPAA-aligned 24/7 SOC with PHI-aware DLP rules, encrypted incident response, and HITRUST CSF-aligned operational controls.
Can Armorstack support clinical AI deployments safely?
Yes. Armorstack’s AI Adoption Security Framework was built specifically for organizations adopting clinical decision support, scribing, and AI-augmented diagnostics. The framework’s five pillars include shadow-AI discovery (identifying clinical-AI tools touching PHI), NIST AI RMF risk classification, observability instrumentation, governance and policy work, and quarterly adversarial validation. Healthcare is one of the framework’s primary verticals.
What regulatory frameworks does Armorstack map healthcare clients against?
Armorstack maps healthcare clients against the full HIPAA Security and Privacy Rules, HITRUST CSF, NIST 800-66 (HIPAA Security Rule guidance), NIST CSF 2.0, Joint Commission information management standards, CMS Conditions of Participation IT requirements, 42 CFR Part 2 (substance use disorder records), FDA Pre-Market Cybersecurity (medical device manufacturers), NIST AI RMF (clinical AI), and SOC 2 Type II for vendor relationships.
Does Armorstack handle physical security for healthcare campuses?
Yes. CITADEL delivers access control, video surveillance with AI analytics, nurse call integration, infant protection, wander management, and visitor management across hospital campuses, ambulatory facilities, and senior living environments. CITADEL is designed to integrate with clinical workflow systems and to feed physical telemetry into the same SOC view that monitors cyber events.
What care settings does Armorstack serve?
Armorstack serves acute-care hospitals, ambulatory surgery centers, specialty clinics, long-term and skilled nursing facilities, behavioral health organizations, federally qualified health centers (FQHCs) and community mental health centers (CMHCs), community-based residential facilities (CBRFs) and assisted living, imaging and diagnostics centers, and multi-specialty physician groups.
How does Armorstack handle ransomware risk in healthcare?
Armorstack treats ransomware in healthcare as a patient safety event, not just an IT event. SENTRY’s healthcare incident response posture includes pre-staged isolation playbooks, downtime procedure coordination with clinical operations leadership, ransom negotiation guidance through vetted partners, and post-event regulatory notification support. The 24/7 SOC posture is designed to detect and contain ransomware in clinical environments before it reaches PHI-bearing systems.
Can Armorstack provide a free 30-day AI Risk Assessment for our hospital?
Yes. Armorstack is offering a no-cost 30-day AI Risk Assessment to the first 50 qualifying mid-market organizations — healthcare systems are explicitly eligible. The assessment produces a shadow-AI inventory, NIST AI RMF risk classification (cross-referenced to HIPAA obligations), an observability-gap analysis against your existing SIEM and tooling, and a board-ready summary. Apply at armorstack.ai/ai-risk-assessment/.
Topic · 5 questions

Converged Security vs. MSSP

Read the full Converged Security vs. MSSP page →

Is converged security just a marketing repackaging of MSSP?
No. Converged security is a different operating model with different organizational structure, different procurement model, and different operational outcomes. An MSSP that adds vCISO services or IT services as additional offerings is still operating the MSSP model with bundled services. Converged security operates the four practices as one team, not as separately-delivered services under one brand.
How is the cost structure different?
Converged security typically operates 20-35% below the equivalent multi-vendor MSSP + MSP + advisory + physical security spend, primarily from vendor consolidation, unified monitoring infrastructure, and reduced duplicate licensing. Specific cost outcomes depend on the organization’s current vendor mix.
How is the procurement model different?
Converged security is one procurement decision producing one contract spanning the four practices. The procurement process is typically simpler than the MSSP-only model because there are fewer parallel evaluations to coordinate.
What about transition from existing MSSP relationships?
Most organizations moving to converged security do so over a 6-12 month transition period, not as a sudden cutover. Armorstack supports the transition by operating in augmentation with the existing MSSP during transition, allowing the organization to evaluate the converged model with reduced risk.
How does this affect cyber insurance?
Cyber insurance carriers typically respond favorably to converged security because the documentation, cross-domain visibility, and reduced vendor coordination overhead reduce the carrier’s underwriting risk. Most clients see cyber insurance premium reductions of 15-30% at renewal after moving to converged security.
Topic · 5 questions

Armorstack vs. Clearwater Compliance

Read the full Armorstack vs. Clearwater Compliance page →

Is Clearwater larger than Armorstack?
Clearwater’s parent organization has a larger national footprint. Armorstack employs more than 100 technical experts and serves clients nationwide. Buyer fit depends on the operating model rather than headcount.
Does Armorstack also offer OCR audit preparation?
Yes. The VERITY portfolio delivers HIPAA Security Rule risk analysis and OCR audit preparation as part of the broader managed-security relationship. Armorstack’s preference is to deliver this work within the converged operating model rather than as a standalone engagement.
Can we use Clearwater for compliance and Armorstack for operations?
Yes — some mid-market healthcare organizations operate this way. Armorstack’s SENTRY 24/7 SOC and CORE managed IT can coordinate with a separate compliance advisory firm. The trade-off is that the convergence benefit of the Armorstack MIP model is reduced when compliance is held outside the relationship.
How do I evaluate AI security capability between the two firms?
Ask each firm directly for their published AI security framework, the regulatory frameworks they cross-reference AI use cases against, and the operational AI observability capability their SOC provides. Armorstack publishes the AI Adoption Security Framework at armorstack.ai/ai-adoption-security-framework/ and a healthcare-specific cut at armorstack.ai/ai-adoption-security-framework-healthcare/.
Does it matter if we’re not near an Armorstack office?
Armorstack serves clients nationwide, including national healthcare accounts, and delivery is remote-first by design — SOC, vCISO, and compliance work do not depend on physical proximity. Where a client needs on-site engineering, Armorstack dispatches nationwide. The practical evaluation question is whether your organization needs a partner with a physical office in your city, or whether a remote-first, nationally-delivered operating model meets your needs; most mid-market regulated organizations find the latter is sufficient for everything short of hands-on physical security installation.
Topic · 3 questions

Armorstack vs. Pondurance

Read the full Armorstack vs. Pondurance page →

Is Pondurance larger than Armorstack?
Pondurance operates with a larger national footprint. Armorstack employs more than 100 technical experts serving clients nationwide. Buyer fit depends on operating-model preference rather than headcount comparison.
Does Armorstack handle threat hunting at the depth of a specialist MDR firm?
Yes. SENTRY’s 24/7 SOC operates managed threat hunting as a core capability. Armorstack’s preference is to deliver threat hunting within the converged operating model, where the threat hunting team has explicit visibility into IT, advisory, and physical security signal alongside traditional security telemetry.
Can we use Pondurance for SOC and Armorstack for everything else?
Some mid-market organizations operate this way. Armorstack can deliver advisory (VERITY), managed IT (CORE), and physical security (CITADEL) alongside a separately-contracted MDR firm. The trade-off is that the convergence benefit of the MIP model is reduced when SOC operations are held outside the relationship, because incident reconstruction across IT, AI, and physical signal becomes a multi-vendor coordination exercise.
Topic · 5 questions

Armorstack vs. Arctic Wolf

Read the full Armorstack vs. Arctic Wolf page →

Is Arctic Wolf larger than Armorstack?
Arctic Wolf operates at significantly larger platform scale globally. Armorstack employs more than 100 technical experts serving clients nationwide. Buyer fit depends on operating-model preference and the breadth of services required rather than headcount.
Can Armorstack match Arctic Wolf’s SOC platform scale?
SOC platform scale is one component of buyer evaluation but is rarely the deciding factor for mid-market regulated organizations once the buyer is comparing credible options. The deciding factors are typically: vertical experience, regulatory cross-referencing depth, operating-model alignment, and the willingness to engage in a converged vs. multi-vendor delivery model.
Can we use Arctic Wolf for SOC and Armorstack for the rest?
Some mid-market organizations operate this way. Armorstack can deliver VERITY (advisory), CORE (managed IT), and CITADEL (physical security) alongside a separately-contracted SOC vendor. The trade-off is that the convergence benefit of the MIP model is reduced when SOC operations are external, because cross-domain incident reconstruction becomes a multi-vendor coordination exercise rather than a single-team activity.
How do I evaluate the AI security capability of each firm?
Ask each firm directly for: (a) a published AI security framework, (b) the regulatory frameworks they cross-reference AI use cases against, (c) the operational AI observability capability their SOC provides today (prompt logging, output monitoring, behavior analytics calibrated to AI), and (d) their experience implementing NIST AI RMF in mid-market regulated environments. Armorstack publishes the framework at armorstack.ai/ai-adoption-security-framework/.
What if our organization is enterprise-scale, not mid-market?
Armorstack’s framework is purpose-built for the 100–2,500 employee mid-market band. Enterprises at significantly larger scale typically engage a Big Four advisory firm and a platform-scale MSSP separately. Arctic Wolf serves the enterprise segment; Armorstack does not aggressively pursue it. For enterprises, the buying decision is different from mid-market and the right answer is often a platform vendor like Arctic Wolf paired with a dedicated advisory firm.
Topic · 7 questions

Healthcare AI Security

Read the full Healthcare AI Security page →

Does Armorstack have specific experience with Epic and Oracle Health (Cerner) environments?
Yes. Armorstack has deep operational experience with both Epic and Oracle Health (Cerner) environments, including the security monitoring posture each requires, the integration patterns for third-party clinical AI vendors connecting via FHIR or HL7, and the workflow-sensitive operating posture both environments require. Engagements typically include explicit Epic or Cerner reference architecture in the security program design.
How does the framework handle clinical AI vendor risk?
Pillar 4 governance work specifically addresses clinical AI vendor risk. Deliverables include AI-specific contract clauses for Business Associate Agreements, vendor security questionnaires calibrated to clinical AI vendors, periodic vendor reassessment cadence aligned to your existing vendor risk management program, and an incident response playbook that addresses vendor-side AI compromise affecting your PHI.
Will the assessment disrupt clinical operations?
No. The framework is explicitly designed to operate without disrupting clinical workflows. Discovery uses read-only telemetry and administrative-console metadata; observability instrumentation deploys to security infrastructure not clinical infrastructure; validation testing is conducted against AI systems in test environments or with explicit clinical operations coordination. Engagements are scoped with your CMO, CNIO, and clinical operations leadership before fieldwork begins.
How does this connect to our existing HIPAA Security Rule risk analysis?
Pillar 2 risk classification is designed to feed directly into the HIPAA Security Rule risk analysis you are already required to maintain. The AI risk register produced by Pillar 2 becomes an input to your ongoing 45 CFR 164.308(a)(1)(ii)(A) risk analysis. For organizations using NIST 800-66 as the implementation guidance, Pillar 2 output maps cleanly to the 800-66 risk analysis structure.
Does Armorstack support smaller satellite clinics and ambulatory facilities?
Yes. The framework is designed for organizations with distributed facility footprints — main hospital campuses, ambulatory surgery centers, satellite clinics, telehealth-only locations, and community-based behavioral health facilities. The converged SOC posture produces consistent monitoring across all facilities regardless of size, which is typically more economical than each facility maintaining its own security posture.
Can we apply for the free 30-day AI Risk Assessment?
Yes. Healthcare systems between 100 and 2,500 employees are explicitly eligible. Apply at armorstack.ai/ai-risk-assessment/. The assessment produces a healthcare-specific shadow-AI inventory, a risk register cross-referenced to HIPAA and Joint Commission standards, an observability-gap analysis against your existing security infrastructure, and a board-ready summary suitable for your next audit-committee meeting.
What if our hospital uses a CIO-as-a-service or co-managed IT model?
The framework accommodates both. Armorstack can deliver the full framework end-to-end, or operate in augmentation with your existing CIO-as-a-service or co-managed IT partner. The VERITY virtual CISO practice frequently works in coordination with other advisory providers; SENTRY’s 24/7 SOC frequently augments existing internal or co-managed security teams without displacing them.
Topic · 6 questions

Manufacturing AI Security

Read the full Manufacturing AI Security page →

Does Armorstack work with operational technology (OT) environments, not just IT?
Yes. SENTRY operates OT-aware monitoring across ICS, SCADA, and historian environments alongside IT. The framework explicitly addresses the OT/IT convergence reality where AI systems are increasingly the bridge between zones. CITADEL adds physical-security signal to the cyber-physical investigative picture.
How does the framework integrate with CMMC 2.0 compliance?
Pillar 2 risk classification cross-references AI use cases to NIST 800-171 controls (which CMMC 2.0 Level 2 inherits). For defense-supply-chain manufacturers, AI use cases touching CUI flow into the same controls inventory the CMMC assessment is scoped against, and the AI-specific governance produced in Pillar 4 becomes part of the System Security Plan (SSP) documented for CMMC assessors.
Will the assessment disrupt production?
No. Discovery uses read-only telemetry; observability instrumentation deploys to security infrastructure, not to production-critical OT; Pillar 5 validation testing is conducted in test environments or coordinated with plant operations leadership. Engagements are scoped with your Plant Manager and Operations leadership before fieldwork begins, and we follow the same change-management discipline as any other security-tool deployment.
How does the framework handle AI in engineering and design workflows?
Pillar 1 discovery explicitly enumerates AI in CAD, CAM, CAE, PLM, and engineering generative tools, then classifies by data sensitivity (trade secret, ITAR, EAR, customer IP). Pillar 2 cross-references to your customer contract obligations and export-control requirements. Pillar 3 instrumentation flags engineering-AI behavior anomalies that could indicate IP exfiltration or contract compliance issues.
Does Armorstack support multi-plant manufacturers with distributed facilities?
Yes. The converged SOC posture produces consistent monitoring across all plants regardless of size or location. CITADEL extends physical security uniformly across distributed facilities. The MIP operating model is typically more economical for multi-plant manufacturers than each plant maintaining its own security posture.
What if our manufacturing customer requires a specific security framework?
Common: automotive OEMs require alignment to TISAX or VDA-ISA; aerospace OEMs require alignment to AS9100 or DFARS clauses; DoD contracts require CMMC 2.0; energy-sector customers require NERC CIP or IEC 62443. Armorstack maps the AI risk register against whichever framework your customer requires, in addition to the baseline NIST AI RMF + NIST 800-171 mapping.
Topic · 6 questions

Defense Contractor AI Security

Read the full Defense Contractor AI Security page →

How does the framework integrate with CMMC 2.0 assessment preparation?
Pillar 2 risk classification cross-references each AI use case to the 110 NIST 800-171 controls that CMMC 2.0 Level 2 inherits. The output maps directly into your System Security Plan. The AI-specific governance produced in Pillar 4 becomes documented evidence for the CMMC assessor of how AI is managed within your CMMC-scoped boundary. Armorstack delivers this in coordination with your existing C3PAO or as preparation in advance of selecting one.
Will the framework affect our SPRS score?
The framework helps your SPRS score by closing AI-mediated control gaps that would otherwise reduce the score. Pillar 1 discovery typically finds AI use cases touching CUI that weren’t previously inventoried in the SSP; bringing these under managed controls and POA&M improves the score during the next assessment cycle.
Does Armorstack have ITAR-compliant employees?
Yes. Armorstack maintains the personnel and facility posture required to deliver services to defense contractors handling ITAR-controlled technical data. Engagement scoping will confirm the specific compartment of work that requires ITAR-cleared personnel.
How does the framework handle DFARS 252.204-7012 incident reporting?
Pillar 4 governance includes an AI-specific incident response playbook that integrates with the DFARS 72-hour reporting timeline. The SENTRY SOC operating under the framework has the operational capacity to detect AI-mediated CUI exposure in time to support the reporting obligation.
What about classified contract work?
The framework as documented applies to CUI environments (CMMC Level 2 / NIST 800-171). Classified contract work operates under separate frameworks (NISPOM, NIST 800-53 Moderate or High at minimum, specific contract overlays). Armorstack can scope an extended engagement for organizations with both CUI and classified work, but the published framework focuses on the unclassified-CUI segment where the largest mid-market defense contractor population operates.
How does the framework address customer prime contractor security flow-downs?
Pillar 2 maps each AI use case against your specific prime customer’s security flow-downs in addition to baseline NIST 800-171. Pillar 4 governance produces vendor and subcontractor flow-down language compliant with the obligations your primes have placed on you, so your supply chain inherits the same posture.
Topic · 6 questions

Financial Services AI Security

Read the full Financial Services AI Security page →

How does the framework integrate with our existing model risk management framework?
Pillar 2 risk classification explicitly identifies AI use cases that function as models under SR 11-7. For those use cases, the framework feeds into your existing model risk management process — model inventory, validation, ongoing monitoring, and model risk reporting to the board. Pillar 4 governance is designed to coexist with your existing MRM framework, not displace it.
How does the framework handle GLBA Safeguards Rule expectations?
Pillar 1 discovery surfaces every AI use case touching NPI. Pillar 2 classifies each against the Safeguards Rule requirements. Pillar 3 implements the technical safeguards specifically targeted at AI-mediated NPI movement. Pillar 4 produces the policy and program documentation Safeguards Rule examiners expect, including the written information security program element that addresses AI.
Will the assessment disrupt customer-facing services?
No. Discovery uses read-only telemetry; observability instrumentation deploys to security infrastructure; Pillar 5 validation is conducted in test environments or coordinated with line-of-business leadership. The assessment is scoped with your CISO, CIO, and Chief Risk Officer before fieldwork begins.
How does the framework address AI in customer communication?
Pillar 1 enumerates AI-augmented customer communication tools. Pillar 2 cross-references customer communication AI against FINRA suitability rules, Regulation Best Interest, consumer financial protection rules, and state insurance market conduct requirements where applicable. Pillar 4 produces governance that addresses the specific question of when AI-generated content is being communicated to customers and what disclosure or human-review requirements apply.
Does Armorstack support FFIEC examination preparation?
Yes. The AI risk register produced by Pillar 2, combined with the program documentation produced by Pillar 4, is sized to be examiner-ready. Armorstack frequently coordinates with your existing audit and compliance function in advance of examination.
How does the framework handle insurance carriers under NAIC?
Pillar 2 cross-references against the NAIC Model Law on Insurance Data Security as adopted by your state of domicile. Pillar 4 governance addresses the AI-specific elements of the WISP that state insurance regulators are increasingly expecting in market conduct examination.
Topic · 6 questions

K-12 AI Security

Read the full K-12 AI Security page →

Can the framework implementation be funded through E-Rate?
Some elements can. E-Rate Category 1 covers WAN and Internet access; Category 2 covers internal connections including certain managed network and security services. The framework’s observability and SOC components are sometimes eligible. Armorstack will scope specifically what is and is not E-Rate eligible during the engagement, and support the Form 470 competitive bidding process to bring federal funding to bear. The non-eligible elements typically run inside existing district technology budgets.
How does the framework handle the “click-wrap crisis” with AI vendors?
Pillar 4 governance produces explicit vendor-management language for AI tools where the vendor is exposing terms only through a clickthrough EULA. Armorstack works with district legal counsel or shared-services regional councils to produce model contract language for AI vendors. The discovery work in Pillar 1 specifically surfaces vendors who have changed terms without notice.
Will the framework restrict classroom AI use?
No, not by default. The framework is designed to enable safe AI adoption, not block it. Pillar 4 governance produces an AI Acceptable Use Policy that defines what is and isn’t acceptable at the district level; the operational decisions about classroom-level usage stay with curriculum and administration leadership. The framework gives the district leadership the information they need to make those decisions defensibly.
Does Armorstack work with small districts and libraries?
Yes. The MIP operating model is sized to district reality. Engagement scoping accounts for districts with one or two-person IT teams and library systems without dedicated security staff. Where the full framework is beyond what budget allows, Armorstack scopes a foundation phase (Pillars 1 and 2 only) that produces immediate value at a smaller engagement size.
How does the framework handle CIPA content filtering in an AI era?
Pillar 3 observability includes integration with CIPA content filtering specifically targeted at AI-generated content. The challenge is that AI is generating content that didn’t exist when the URL block list was built. SENTRY’s monitoring includes AI-generated content classification that supplements URL-based filtering with content-based filtering, addressing the CIPA obligation as the technology has actually evolved.
How does the framework support special education and IDEA?
Pillar 2 risk classification flags AI workflows touching IEP, 504, or special education-specific records as a higher tier requiring additional safeguards under IDEA confidentiality requirements. Pillar 4 produces governance specific to special education AI workflows.
Topic · 5 questions

Epic AI Security

Read the full Epic AI Security page →

Does Armorstack have Epic-environment operational experience?
Yes. Armorstack’s SENTRY SOC operates Epic-aware monitoring rules and the VERITY advisory practice has explicit experience with Epic security and compliance posture. Engagements with Epic-running health systems include explicit Epic reference architecture in the security program design.
How does the framework address Epic Connection Hub integrations?
Pillar 1 inventory enumerates third-party clinical AI vendors integrated via Connection Hub. Pillar 2 risk classification cross-references each vendor against your existing Business Associate Agreement structure and HIPAA Security Rule obligations. Pillar 4 governance produces specific contract language for AI-vendor BAAs aligned to the realities of clinical AI integration.
Will the assessment require Epic Hyperspace access?
No. Read-only access to Epic Audit Log data and Connection Hub configuration metadata is typically sufficient for the assessment scope. Where deeper inspection is needed for a specific clinical AI use case, we coordinate explicitly with Epic and your Epic operations team.
Does Armorstack work with Epic Community Connect or hosted Epic deployments?
Yes. The framework applies regardless of whether your Epic instance is self-hosted, Community Connect (with a host organization), or hosted by Epic directly. The discovery and classification work adapts to the specific operational model.
How does Epic-specific AI security connect to HIPAA Security Rule risk analysis?
Pillar 2 of the framework is explicitly designed to feed into the ongoing 45 CFR 164.308(a)(1)(ii)(A) risk analysis you maintain. The AI risk register produced by Pillar 2 becomes a section of (or input to) your overall HIPAA Security Rule risk analysis.
Topic · 5 questions

HIPAA AI Compliance

Read the full HIPAA AI Compliance page →

Does HIPAA explicitly address AI today?
HIPAA’s existing rules apply to PHI regardless of whether AI is processing it. The Security and Privacy Rules’ principles — minimum necessary, access controls, audit controls, integrity, transmission security — apply to AI workflows. What HIPAA does not do is provide AI-specific implementation guidance. NIST 800-66 has limited AI-specific guidance. The Department of Health and Human Services has issued non-binding AI guidance through OCR statements. Compliance work for AI inside HIPAA-covered entities requires translating existing HIPAA requirements into the AI operational context, which is what the framework’s Pillar 2 produces.
Does a Business Associate Agreement automatically cover AI use by a vendor?
No. Most Business Associate Agreements were signed before the vendor introduced AI features. The BAA may not explicitly contemplate AI use of PHI, AI training on PHI, AI output containing PHI, or vendor-side prompt logging that processes PHI. Pillar 4 governance work explicitly addresses this by producing AI-specific BAA clauses and BAA addendum language for existing vendor relationships.
How does the framework address PHI minimum-necessary requirements with AI?
Pillar 3 observability instrumentation includes PHI-aware data-loss-prevention rules applied to AI inputs and outputs, behavior analytics that flag AI access patterns inconsistent with minimum-necessary principles, and integration with your existing audit infrastructure to produce minimum-necessary justification documentation when needed for OCR review.
Is AI-mediated PHI exposure a HIPAA breach?
Often yes, depending on the specific facts. The Breach Notification Rule requires assessment of whether PHI was actually acquired, accessed, used, or disclosed and whether the probability of compromise was low. AI-mediated exposure events — an AI tool returning PHI to an unauthorized recipient, a prompt injection causing PHI disclosure, vendor-side AI compromise affecting your PHI — require breach assessment under 164.402, often resulting in a reportable breach. Pillar 4 governance includes the incident response playbook that integrates AI incidents with HIPAA notification timelines.
How does the framework support OCR audit preparation?
The risk register from Pillar 2 and the program documentation from Pillar 4 are sized to be examiner-ready. Both VERITY and SENTRY have OCR audit experience and frequently coordinate with healthcare client legal counsel during enforcement action review. The framework’s documentation feeds directly into OCR audit responses.
Topic · 6 questions

Clinical Decision Support Security

Read the full Clinical Decision Support Security page →

Does AI-augmented CDS require FDA clearance?
It depends on the specific use case. Some AI-augmented CDS qualifies as a medical device under FDA’s Software as a Medical Device guidance and requires premarket clearance. Other AI-augmented CDS qualifies for the CDS Software exemption under Section 3060 of the 21st Century Cures Act. The framework’s Pillar 2 work cross-references your specific AI-augmented CDS use cases against FDA’s current guidance and your existing medical device regulatory posture.
How does the framework address model drift in clinical AI?
Pillar 5 continuous validation includes scheduled assessment of model performance against current patient population data, scheduled reassessment of model assumptions, and scheduled adversarial testing of AI-augmented CDS for failure modes specific to the clinical decisions the AI is informing.
What about AI-augmented CDS bias and fairness?
Pillar 2 risk classification includes fairness and explainability scoring for AI use cases informing clinical decisions affecting patient populations. The framework cross-references each clinical AI use case to NIST AI RMF’s fairness and bias considerations and produces governance documentation suitable for clinical and quality leadership review.
How does Armorstack handle vendor-supplied AI-augmented CDS?
Pillar 1 discovery enumerates every vendor-supplied AI-augmented CDS in use. Pillar 4 governance produces vendor-management posture for CDS specifically — including the model documentation, validation evidence, and ongoing monitoring obligations the vendor must provide. Where vendors cannot or will not provide adequate documentation, Pillar 4 produces escalation language for the executive sponsor relationship with that vendor.
Can the framework support a hospital’s existing AI governance committee?
Yes. Many mid-market hospitals have established or are establishing AI governance committees with clinical, quality, IT, security, compliance, and legal representation. The framework’s deliverables — the risk register, the observability-gap analysis, the governance documentation — are designed to feed into the committee’s ongoing operations rather than displace them.
How does the framework address ambient clinical documentation security?
Ambient clinical documentation tools (Nuance DAX, Suki, Augmedix, Abridge, others) are a specific high-PHI-exposure AI use case. Pillar 1 enumerates the specific ambient tools deployed and their integration patterns with Epic or your EHR. Pillar 3 observability includes monitoring of the ambient transcription output for PHI exposure paths. Pillar 4 governance addresses the specific vendor-management obligations these tools require.
Topic · 5 questions

Shadow AI in Healthcare

Read the full Shadow AI in Healthcare page →

How does shadow AI become a HIPAA issue?
Three primary paths: (1) PHI is disclosed to an unauthorized AI service that is not under a Business Associate Agreement, becoming an impermissible disclosure under the Privacy Rule and potentially a reportable breach; (2) PHI processed by an AI vendor is used to train the vendor’s models without explicit authorization, raising 164.502 use questions; (3) AI-generated content based on PHI is shared inappropriately, replicating disclosure paths the security team’s existing DLP rules don’t recognize because they were built for human action patterns, not AI output patterns.
Can we just ban AI use by clinical staff?
Bans rarely work in practice and often create worse outcomes than governance. Clinical staff under workflow pressure will find ways to use AI to accelerate documentation and decision-making; if the organization has banned approved tools, staff use unapproved tools on personal devices, removing all visibility. The more durable approach is governance — an Acceptable Use Policy that defines what AI use is permitted, with what data, on what devices — combined with visibility into actual use.
Will the discovery work identify our clinical AI vendors?
Yes. Pillar 1 discovery is explicitly scoped to enumerate vendor-supplied AI in addition to staff-use AI. The discovery work surfaces vendor AI features that may have been enabled without explicit organizational authorization and produces the inventory of clinical AI vendor relationships your governance committee can review.
How does shadow-AI discovery feed into our existing Joint Commission preparation?
Joint Commission information management standards require organizations to know how clinical information is being used and protected. The shadow-AI inventory becomes documentary evidence that the organization knows what AI is touching clinical information, classified appropriately, with governance documented. Pillar 4’s deliverables feed into Joint Commission survey preparation directly.
What happens with the inventory after the assessment?
The inventory is yours. Some organizations operate it as a living artifact maintained quarterly. Others integrate it into their existing IT asset inventory or vendor risk management program. Armorstack can operate the inventory as a managed service for organizations that prefer ongoing managed shadow-AI discovery, but the assessment itself produces the inventory as a deliverable regardless of whether the relationship continues.
Topic · 6 questions

Healthcare AI Vendor Risk

Read the full Healthcare AI Vendor Risk page →

How does this fit with our existing vendor risk management program?
The Pillar 4 vendor risk work is designed to extend, not replace, your existing program. Most mid-market hospitals have established vendor risk management (often centered on the SIG questionnaire, HITRUST CSF assessments, or NIST 800-66-aligned vendor reviews). The AI vendor risk work adds AI-specific instruments and reassessment triggers to the existing program rather than creating a parallel one.
How many of our vendors actually need a BAA addendum?
It depends on what discovery surfaces. Mid-market hospitals typically have 30-100 active vendor relationships involving PHI. Of those, a subset have meaningful AI features in active use. The Pillar 1 discovery and Pillar 2 classification work identify which specific vendor relationships warrant priority addendum negotiation. The framework does not recommend rewriting every BAA; it prioritizes the highest-risk subset.
What if a vendor refuses to sign an AI-specific BAA addendum?
Some vendors will. Pillar 4 governance includes escalation language for the executive sponsor relationship with that vendor, alternative-vendor evaluation criteria, and risk-acceptance documentation if your organization decides to continue the relationship despite the gap. The framework supports the decision either way; it ensures the decision is documented and defensible.
How does this connect to vendor AI sub-processors?
Healthcare AI vendors increasingly rely on infrastructure-layer AI vendors — OpenAI, Anthropic, Google, AWS Bedrock, Azure OpenAI — as sub-processors of their AI features. Pillar 4 governance specifically addresses sub-processor disclosure: which infrastructure AI vendor is processing your PHI, what their downstream BAA posture is, what their data residency and training posture is. The chain of BAA coverage must extend through the sub-processor relationship to be defensible.
How does this affect our existing HITRUST CSF program?
HITRUST CSF’s vendor risk management controls map directly to the framework’s Pillar 4 vendor risk work. The framework’s deliverables can feed into HITRUST CSF self-assessment or external assessment evidence directly.
Does Armorstack maintain a healthcare AI vendor reference list?
Armorstack maintains operational knowledge of the major healthcare AI vendor ecosystem and updates this knowledge continuously through engagement work. The reference is not published as a public list (vendor situations change rapidly and a published list dates quickly) but is shared with clients during engagement.
Topic · 5 questions

Prompt Injection in Healthcare AI

Read the full Prompt Injection in Healthcare AI page →

Has prompt injection actually affected healthcare organizations?
Published incidents involving prompt injection against healthcare AI deployments exist in the academic literature and in vendor disclosures, though specific organizational attributions are rare given the sensitivity. Multiple security researchers have demonstrated prompt injection against widely-deployed healthcare-adjacent AI tools. The realistic operational posture treats prompt injection as a present and active threat rather than a future hypothetical.
Can our existing SOC detect prompt injection?
Most mid-market hospital SOCs cannot detect prompt injection today because their monitoring tools were built for traditional cybersecurity threats and do not have visibility into AI prompts or outputs. Pillar 3 observability instrumentation specifically extends the SOC’s visibility to include AI inputs and outputs, enabling prompt-injection detection as part of the SOC’s standard monitoring posture.
How does vendor-side prompt injection affect us?
If a vendor providing AI-augmented services to your organization experiences a successful prompt injection that affects PHI, your organization may have HIPAA breach notification obligations under the Breach Notification Rule depending on the specific facts. Pillar 4 governance produces vendor contract language requiring vendor notification of AI security incidents specifically and a defined incident-response coordination protocol with the vendor.
Is there a HIPAA-specific requirement to defend against prompt injection?
HIPAA does not name prompt injection specifically but requires reasonable and appropriate safeguards to protect PHI. As prompt injection becomes a recognized attack class, the standard for “reasonable and appropriate” includes operational capability to detect and respond to AI-specific threats. OCR has not issued specific prompt-injection guidance as of the framework’s publication date.
How frequently does the framework recommend prompt-injection testing?
Pillar 5 recommends quarterly adversarial testing including prompt-injection scenarios, with the test set updated continuously as new attack techniques are published. The frequency reflects the velocity at which adversarial techniques against language models are being developed and published.
Topic · 5 questions

ICS/SCADA AI Security

Read the full ICS/SCADA AI Security page →

Does the framework integrate with our existing OT monitoring tools?
Yes. SENTRY operates alongside common OT monitoring tools including Claroty, Nozomi Networks, Dragos, and Industrial Defender, extending visibility to include AI inputs and outputs alongside the OT telemetry these tools already produce. Where you have no existing OT monitoring, SENTRY’s deployment includes recommendation on which platform fits your environment.
How does the framework handle predictive maintenance AI?
Pillar 1 discovery enumerates every predictive maintenance vendor in use and the historian data each consumes. Pillar 2 classifies the AI use case by data sensitivity (CUI, trade secret, proprietary) and by the physical-safety impact of an AI manipulation. Pillar 3 instruments observability into the AI vendor’s data flow without disrupting the OT environment.
Will instrumentation affect production?
No. The framework’s Pillar 3 observability is deployed to security infrastructure that observes OT traffic out-of-band, not to OT-critical control systems. Engagements are coordinated with plant operations leadership before any sensor or tap is deployed.
How does this fit with our existing NIST 800-82 work?
The framework’s Pillar 2 risk classification is designed to feed into your existing 800-82 implementation. AI use cases are cross-referenced to 800-82 controls in addition to NIST AI RMF, producing an updated 800-82 controls inventory that includes AI considerations the original 800-82 implementation did not.
Does Armorstack have OT engineering experience?
Yes. The SENTRY practice includes engineers experienced with Rockwell, Siemens, Schneider Electric, GE, and Wonderware MES environments. Engagement scoping confirms the specific OT vendor stack in your environment and matches the engagement team accordingly.
Topic · 5 questions

AI in PLM and Engineering Tools

Read the full AI in PLM and Engineering Tools page →

How does the framework handle engineering staff use of public LLM tools?
Pillar 1 discovery enumerates public LLM access from organizational devices including engineering workstations. Pillar 4 governance produces an Engineering AI Acceptable Use Policy specifically addressing what categories of design content may and may not be processed by public LLM tools. Pillar 3 observability flags engineering AI usage patterns inconsistent with policy.
What about AI features embedded in CAD by the vendor?
Pillar 1 discovery enumerates vendor-embedded AI features in CAD, CAM, and CAE tools. Pillar 4 governance addresses vendor contract language for AI use of customer-uploaded design content, AI training on design content, and AI output that contains design-derived information.
How does this address ITAR-controlled technical data and AI?
Pillar 2 risk classification specifically identifies AI workflows touching ITAR-controlled technical data. Pillar 4 governance produces ITAR-aligned AI use restrictions including jurisdiction-of-AI-processing requirements (AI infrastructure must be operated from within the US for ITAR-controlled data).
Does the framework support automotive Tier 1 customer security requirements?
Yes. Pillar 2 cross-references AI workflows against TISAX, VDA-ISA, and similar automotive supply-chain security frameworks. Pillar 4 governance produces flow-down language for sub-suppliers and contract amendment language for prime customer relationships.
What about aerospace AS9100 requirements?
Pillar 2 cross-references AI workflows against AS9100 requirements. The framework’s governance work integrates with your existing AS9100 quality management system documentation rather than creating parallel documentation.
Topic · 5 questions

Predictive Maintenance AI Security

Read the full Predictive Maintenance AI Security page →

How does the framework address third-party predictive maintenance vendors?
Pillar 1 discovery enumerates each vendor and the data path between your OT environment and the vendor’s AI infrastructure. Pillar 4 governance produces vendor risk management posture including AI-specific contract language addressing vendor-side data security, model security, and incident notification.
What if our predictive maintenance vendor uses sub-processor AI infrastructure?
Many predictive maintenance vendors use cloud AI infrastructure (AWS SageMaker, Azure ML, Google Vertex) as sub-processors. Pillar 4 governance requires vendor disclosure of these sub-processor relationships and produces language requiring vendors to flow down equivalent security obligations to their sub-processors.
How does the framework address adversarial input to predictive maintenance AI?
Pillar 5 continuous validation includes adversarial testing of predictive maintenance AI workflows: simulated sensor-data manipulation to test the AI’s response, model behavior testing under boundary conditions, and verification that the vendor’s incident response includes detection of input-manipulation patterns.
Can the framework support OEM warranty requirements?
Yes. Many OEMs require specific maintenance procedures to preserve warranty coverage. Pillar 4 governance addresses the interaction between AI-recommended maintenance actions and OEM-specified maintenance procedures, ensuring that AI-driven maintenance decisions do not inadvertently void warranties.
How does this integrate with our existing CMMS?
The framework operates alongside your existing computerized maintenance management system (Maximo, IFS, eMaint, others), not as a replacement. Predictive maintenance AI recommendations are observed as they flow from the AI vendor into the CMMS for action.
Topic · 5 questions

Manufacturing Supply Chain AI Risk

Read the full Manufacturing Supply Chain AI Risk page →

How does the framework address upstream supplier AI risk?
Pillar 1 discovery extends to enumerate AI features in the supplier-side production capability your suppliers operate. Pillar 4 governance produces supplier contract language addressing supplier AI security obligations, AI-vendor sub-processor disclosure, and AI incident notification.
What about customer-imposed AI forecasting and planning systems?
Many OEM customers impose specific forecasting, planning, or quality systems on their suppliers. As these systems incorporate AI, the supplier’s security posture must address the customer AI. Pillar 2 classifies customer-imposed AI systems by the data they process and the regulatory framework governing the data.
How does the framework support OEM customer security flow-down compliance?
Pillar 4 governance produces flow-down language inheriting your customers’ AI security requirements to your own suppliers. The framework is designed to extend security obligations through the supply chain rather than terminating at your perimeter.
What about logistics and freight AI?
Logistics and freight optimization AI increasingly touches shipment metadata that may include CUI, trade secret, or proprietary product information. Pillar 1 discovery enumerates logistics AI; Pillar 4 governance addresses the contractual and data-protection obligations.
How does this affect our IATF 16949 or AS9100 compliance?
IATF 16949 (automotive) and AS9100 (aerospace) quality management systems include supplier control requirements. The framework’s supply chain AI work integrates with these QMS requirements and produces documentation suitable for QMS audit review.
Topic · 6 questions

CMMC 2.0 AI Risk Management

Read the full CMMC 2.0 AI Risk Management page →

Does CMMC 2.0 explicitly require AI risk management?
The CMMC 2.0 standard does not explicitly name AI. It requires implementation of the 110 NIST 800-171 controls. AI use cases touching CUI fall under the same controls structure that all CUI-handling systems do. The framework’s value is producing the documented mapping so the assessor sees how each AI use case is covered by which 800-171 controls.
How does the framework feed into our System Security Plan?
Pillar 2 risk classification produces a register that maps directly into the SSP structure. Each AI use case becomes a documented entry in the SSP cross-referenced to the 800-171 controls that implement protection for it. Pillar 4 governance produces the AI-specific policy documents that the SSP references.
How does Armorstack coordinate with our C3PAO?
Armorstack frequently coordinates with the customer’s selected C3PAO during assessment preparation, providing documentation, pre-assessment review, and remediation support for findings that surface during the assessment cycle. Armorstack is not a C3PAO itself; we operate in support of the customer’s chosen assessor.
What about Level 3 assessment requirements?
Level 3 assessment inherits Level 2 controls and adds additional NIST 800-172 controls. The framework’s approach scales to Level 3 by adding the 800-172-specific AI considerations to the risk register and governance work. Mid-market organizations pursuing Level 3 are typically subject to more stringent customer security flow-downs anyway, which the framework’s Pillar 4 governance addresses.
How does this affect our SPRS score?
Pillar 1 discovery typically identifies AI use cases touching CUI that were not previously inventoried in the SSP, which would otherwise reduce your SPRS score at next assessment. Bringing these under managed controls and POA&M improves the score during the next assessment cycle.
What if our prime contractor customer has specific AI requirements?
Pillar 2 maps each AI use case against your prime customer’s specific security flow-downs in addition to baseline NIST 800-171. Pillar 4 governance produces vendor and subcontractor flow-down language that inherits from your prime customer’s obligations.
Topic · 5 questions

ITAR and AI Engineering Tools

Read the full ITAR and AI Engineering Tools page →

Can we use cloud AI infrastructure with ITAR-controlled data?
Conditionally yes, with specific constraints. AWS GovCloud, Azure Government, and Google Cloud Assured Workloads for Government offer ITAR-compliant cloud environments. Commercial AI services running on non-government cloud infrastructure are typically not ITAR-compliant for ITAR-controlled data processing. Pillar 1 discovery enumerates which AI services in your environment are operating from ITAR-compliant infrastructure and which are not.
Can engineering staff use ChatGPT with ITAR-controlled content?
No. OpenAI’s public ChatGPT service is not ITAR-compliant infrastructure. Pillar 4 governance produces an explicit policy prohibiting engineering staff use of public LLM tools for ITAR-controlled content and identifies the approved AI tooling that is appropriate for ITAR workflows.
How does the framework address deemed exports through AI output?
Pillar 4 governance addresses the deemed export risk through documented access controls on AI tools processing ITAR-controlled data, role-based access for AI workflows touching ITAR-controlled technical data, and personnel security clearance verification for users of AI tools that operate on ITAR content.
What about AI training on ITAR-controlled data?
Most commercial AI vendor terms include training rights on customer data. Pillar 4 governance produces contract language explicitly opting out of training on ITAR-controlled content and requiring vendor documentation that ITAR-controlled data is not used for model training.
How does this affect DDTC reporting?
The framework supports your existing Directorate of Defense Trade Controls reporting posture. AI processing that crosses jurisdictional boundaries is captured in the inventory; any reporting obligations are addressed through your existing compliance counsel relationship.
Topic · 5 questions

CUI Exposure Through AI

Read the full CUI Exposure Through AI page →

Does the framework address the new 32 CFR 2002 CUI Program requirements?
Yes. The CUI Program established by 32 CFR 2002 governs how Executive Branch agencies designate and handle CUI; contractors handling CUI inherit obligations through DFARS 252.204-7012 and equivalent clauses. The framework’s Pillar 2 classification work cross-references AI use cases to the specific CUI category (basic CUI, specified CUI, CUI categories with additional handling requirements) and the controls each requires.
How does the framework address the DoD Cyber Crime Center reporting requirement?
Pillar 4 governance includes an incident response playbook that addresses DFARS 252.204-7012 reporting obligations including the 72-hour DC3 reporting timeline. AI-mediated CUI exposure events are documented to support the report.
What if our AI use case is processing CUI categorized as Specified CUI?
Specified CUI categories carry additional handling requirements beyond basic CUI. Pillar 2 classification identifies AI use cases touching specified CUI categories (for example, export-controlled, privacy, financial) and applies the additional safeguards each category requires. Pillar 3 observability calibrates to the specific data category.
How does the framework integrate with Project Spectrum tools?
For mid-market defense contractors using Project Spectrum and related DoD Cybersecurity-as-a-Service offerings, the framework’s deliverables are designed to complement those tools. The risk register and governance documentation produced by the framework are exportable for use in Project Spectrum’s reporting.
Does the framework address the recent NIST 800-171 Rev 3 update?
Yes. The framework cross-references AI use cases to both 800-171 Rev 2 and Rev 3 controls. As the CMMC 2.0 program transitions to Rev 3 references, the framework’s mapping is updated accordingly. Engagements scope explicitly to the Rev currently applicable to your contract obligations.
Topic · 5 questions

DFARS 252.204-7012 and AI

Read the full DFARS 252.204-7012 and AI page →

What triggers DFARS 252.204-7012 reporting for AI incidents?
The reporting trigger is discovery of a cyber incident affecting covered defense information. Pillar 3 observability instrumentation is configured to detect AI-mediated exposure events as discovery triggers, supporting the contractor’s 72-hour reporting obligation.
How does the framework support the DC3 reporting process?
Pillar 4 governance produces an incident response playbook that integrates DC3 reporting timeline, content requirements (incident description, technical details, malicious software collection), and follow-up obligations. The playbook is designed to be operationally executable within the 72-hour window.
What about DFARS 252.204-7019 and 7020 SPRS reporting?
The 7019 and 7020 clauses require NIST 800-171 self-assessment scoring and reporting to SPRS. AI use cases touching CUI affect the 800-171 controls inventory and consequently the SPRS score. Pillar 2 risk classification work produces the updated controls implementation that affects SPRS posture.
What if a vendor-side AI incident affects our CUI?
Vendor-side AI compromises affecting CUI processed under your DFARS-flow-down obligations trigger your reporting requirements regardless of whether the incident originated inside your perimeter. Pillar 4 governance produces vendor contract language requiring vendor notification of AI-mediated incidents and your coordinated response posture for vendor-originated incidents.
How does this affect our DFARS 252.204-7021 CMMC requirements?
The 7021 clause incorporates CMMC 2.0 requirements. AI risk management feeds into the CMMC controls implementation evaluated during assessment. Pillar 4 governance documentation supports CMMC assessment preparation with AI considerations in scope.
Topic · 5 questions

GLBA Safeguards Rule and AI

Read the full GLBA Safeguards Rule and AI page →

Does the Safeguards Rule explicitly require AI risk management?
The Safeguards Rule does not name AI specifically but requires risk assessment to identify reasonably foreseeable internal and external risks to customer information. AI use cases touching NPI are reasonably foreseeable risks that the risk assessment is required to address. The framework’s Pillar 2 produces the AI-specific risk assessment input.
How does the framework update our WISP for AI?
Pillar 4 governance produces WISP addendum language addressing the AI-specific elements: AI inventory, AI risk assessment results, AI controls implementation, AI vendor oversight, AI monitoring, AI incident response, and AI employee training. The addendum integrates with your existing WISP rather than replacing it.
What about the qualified individual designation under the Safeguards Rule?
The Rule requires designation of a qualified individual responsible for the WISP. The framework supports this individual by producing the documented AI security program they oversee. Where the qualified individual is a vCISO (which the Rule allows), Armorstack’s VERITY practice can serve in that role directly.
How does the framework address vendor oversight under 16 CFR 314.4(f)?
Pillar 4 governance produces vendor oversight documentation specifically for AI vendor relationships, addressing the Rule’s requirements for selection, contractual obligations, and periodic assessment. The framework’s vendor risk approach is calibrated to the Safeguards Rule’s specific language.
What about the breach notification provisions added to the Safeguards Rule?
The FTC’s amendments require notification of certain security events affecting 500 or more consumers. Pillar 4 governance addresses AI-specific incident response with explicit attention to the notification threshold, timeline, and content requirements. Pillar 3 observability instrumentation produces the detection capability that supports timely notification when required.
Topic · 5 questions

SR 11-7 Model Risk Management and AI

Read the full SR 11-7 Model Risk Management and AI page →

Which AI use cases are “models” under SR 11-7?
SR 11-7 applies broadly to any quantitative method producing decisions or estimates used in business processes. AI-driven fraud detection, AML monitoring, underwriting, loss reserving, fair lending analysis, and pricing decisions almost certainly qualify. AI-driven customer service may not, depending on whether the AI is influencing material business decisions. Pillar 2 classification addresses the case-by-case determination.
How does the framework integrate with our existing MRM function?
The framework is designed to feed into your existing MRM framework rather than replace it. Pillar 1 discovery produces an updated model inventory that includes AI models. Pillar 2 classification identifies SR 11-7-relevant AI models for MRM intake. Pillar 4 governance produces AI-specific MRM policy elements.
How do we validate generative AI models under SR 11-7?
SR 11-7 validation requires evaluation of conceptual soundness, ongoing monitoring, and outcomes analysis. For generative AI models the conceptual soundness review evaluates the model architecture and training approach; ongoing monitoring includes prompt-injection and output-quality monitoring; outcomes analysis tracks model behavior over time. The framework’s Pillar 3 observability produces the monitoring data the validation function needs.
What about vendor-supplied AI models?
SR 11-7 applies to vendor-supplied models the institution uses. The framework’s Pillar 4 governance addresses vendor model documentation requirements, validation expectations, and ongoing monitoring obligations the vendor must provide.
How does this affect our model risk governance committee?
The framework’s deliverables — the updated model inventory, the AI model risk register, the validation evidence, the ongoing monitoring data — are sized to feed into your existing model risk governance committee. Most committees benefit from explicit AI model agenda items added to their standing reviews.
Topic · 5 questions

FFIEC AI Examination Preparation

Read the full FFIEC AI Examination Preparation page →

How does the framework integrate with our existing FFIEC examination preparation?
The framework’s deliverables are designed to extend, not replace, your existing FFIEC examination preparation. Most institutions maintain examination-ready documentation organized by FFIEC handbook section; the framework’s AI-specific documentation slots into the existing structure (typically Information Security and Architecture & Operations sections).
What specific AIO Booklet sections does the framework address?
The framework addresses AIO Booklet sections on architecture risk management, operations risk management, change management, and third-party risk management as they apply to AI. The Pillar 2 risk classification work and Pillar 4 governance work specifically reference AIO Booklet expectations.
How does this address the FFIEC Cybersecurity Assessment Tool (CAT)?
The CAT measures inherent risk and cybersecurity maturity across five domains. AI-specific risk and maturity considerations integrate into each domain. The framework’s deliverables feed into the CAT assessment with explicit AI considerations the original tool did not address.
What about state examination cycles?
State banking departments and state credit union regulators inherit much of the FFIEC framework but add state-specific expectations. The framework adapts to state examination cycles by cross-referencing state-specific cybersecurity and consumer protection law (Wisconsin, Illinois, Minnesota, Iowa, Michigan, Indiana, Ohio, Kentucky, and Missouri equivalents).
How does the framework support our existing CISA Cybersecurity Performance Goals?
For institutions referencing the CISA CPGs, the framework’s deliverables address the AI-specific extensions of each performance goal. AI inventory feeds into asset inventory CPGs; AI governance feeds into risk management CPGs; AI observability feeds into detection CPGs.
Topic · 5 questions

NAIC Model Law and AI Insurance

Read the full NAIC Model Law and AI Insurance page →

Which states have adopted the NAIC Insurance Data Security Model Law?
Adoption is ongoing and varies by state legislative cycle. Across the states Armorstack’s clients operate in nationally, multiple states have adopted, are in active adoption, or have substantively-equivalent state law. The framework’s Pillar 2 classification specifically references the state-by-state adoption status applicable to your domicile and operating states.
How does the framework address Colorado Regulation 10-1-1 on AI in insurance?
Colorado’s regulation imposes specific governance and testing expectations on insurance use of external consumer data and AI predictive models. The framework’s Pillar 2 risk classification and Pillar 4 governance work address the regulation’s specific expectations including fairness testing, bias mitigation, and consumer notification.
What about California, New York, and Connecticut insurance AI guidance?
California Department of Insurance, New York Department of Financial Services, and Connecticut Department of Insurance have each issued AI guidance. The framework adapts to each jurisdiction by cross-referencing AI use cases to the specific jurisdictional expectations applicable to your operating territory.
How does this affect our market conduct examination preparation?
State market conduct examinations increasingly include AI-related questions about underwriting practices, claims handling, fairness testing, and complaint patterns. The framework’s deliverables produce documented evidence of AI governance, fairness testing, and complaint pattern analysis suitable for market conduct examiner review.
What about the NAIC AI Principles?
The NAIC Principles on Artificial Intelligence establish high-level expectations for fair, accountable, compliant, transparent, secure, safe, and robust AI. The framework’s Pillar 4 governance work explicitly addresses each Principle area and produces governance documentation aligned to the Principles.
Topic · 5 questions

FINRA AI Suitability

Read the full FINRA AI Suitability page →

Does FINRA require explainability of AI-driven recommendations?
FINRA Rule 2111 requires that suitability determinations have a reasonable basis. For AI-driven recommendations, the reasonable basis must be documentable. Pillar 4 governance produces documentation requirements for AI-driven recommendation systems including the customer profile inputs, the recommendation logic, and the basis for the recommendation in customer-suitability terms.
What about Reg BI’s duty of care for AI?
Reg BI’s duty of care requires broker-dealers to exercise reasonable diligence, care, and skill. For AI-driven recommendation workflows, this includes evaluating the AI’s recommendation methodology, monitoring outcomes for systematic deviation from customer best interest, and maintaining the documented record of the AI’s role in the recommendation chain.
How does the framework address robo-advisor compliance?
For broker-dealer robo-advisor platforms, the framework’s Pillar 2 risk classification addresses the specific AI use cases in the robo-advisor’s recommendation workflow. Pillar 4 governance produces policy aligned to FINRA Regulatory Notice 17-13 (Roboadvisors) and subsequent guidance.
What about RIA-specific AI compliance?
RIAs operate under the Investment Advisers Act of 1940’s fiduciary standard. The framework’s Pillar 2 cross-references RIA AI use cases against the fiduciary standard and the SEC’s specific guidance for AI use by investment advisers. Pillar 4 governance addresses the recordkeeping requirements under Advisers Act Rule 204-2 as they apply to AI workflows.
How does this affect FINRA examination preparation?
FINRA examinations increasingly include AI-related questions about supervision, recordkeeping, and suitability documentation. The framework’s deliverables produce examiner-ready documentation of AI governance and AI-suitability processes.
Topic · 5 questions

AI Fair Lending Compliance

Read the full AI Fair Lending Compliance page →

Does the CFPB regulate AI in underwriting?
Yes. The CFPB has issued guidance on AI in credit decisions including adverse action notice requirements when AI is used. Pillar 4 governance addresses CFPB adverse action notice requirements for AI-driven credit decisions including the explanation requirements for AI recommendations.
How does the framework address disparate impact testing for AI?
Pillar 5 continuous validation includes scheduled disparate impact testing of AI underwriting models, measuring approval rates and pricing across protected-characteristic categories. Where disparate impact is observed, Pillar 5 produces remediation recommendations.
What about state-level AI underwriting requirements?
Several states (Colorado, New York, California) have enacted or proposed specific requirements for AI underwriting transparency and testing. The framework’s Pillar 2 cross-references AI use cases against state-specific requirements applicable to your operating territory.
How does this address vendor-supplied AI underwriting models?
Many community lenders use vendor-supplied AI underwriting tools. The framework’s Pillar 4 vendor management work addresses vendor obligations to support fair lending compliance: documentation of training data, disparate impact testing evidence, explanation capabilities for adverse action notices, and indemnification for vendor-side fair lending exposure.
How does the framework support fair lending examination preparation?
Fair lending examinations are increasingly AI-aware. The framework’s deliverables produce documented evidence of AI fair lending governance, testing, and remediation history suitable for fair lending examination preparation.
Topic · 5 questions

FERPA AI Compliance

Read the full FERPA AI Compliance page →

Can students consent to AI processing of their own records under FERPA?
FERPA assigns rights to parents until the student turns 18 or attends postsecondary education. K-12 student consent has limited effect; parental consent is what FERPA requires. The framework’s Pillar 4 governance produces parent notification and consent procedures appropriate for AI processing scenarios.
How do we ensure an AI vendor qualifies as a school official under FERPA?
Pillar 4 governance produces vendor contract language explicitly addressing the school official requirements: legitimate educational interest, FERPA-equivalent use restrictions, redisclosure controls, and the district’s authority over the contractor’s data handling. The framework also identifies vendors whose current contracts do not meet these requirements and prioritizes them for contract amendment.
How does the framework address the directory information exception?
Districts may designate certain student information as directory information that can be disclosed without consent unless parents opt out. Pillar 4 governance addresses the interaction between AI processing of directory information and FERPA requirements, including the parent opt-out tracking that must be maintained.
What about AI-generated content based on student work?
AI-generated content based on student work raises distinct questions: ownership, FERPA classification, and use rights. Pillar 4 governance addresses district policy on student work used as AI input or AI training data, including parent notification and consent procedures.
How does the framework handle FERPA breach response?
Pillar 4 includes an incident response playbook addressing FERPA breach scenarios with state notification, parent notification, and Department of Education considerations. The framework’s documentation supports the district’s response posture for AI-mediated FERPA exposure events.
Topic · 5 questions

COPPA and AI for K-8 Students

Read the full COPPA and AI for K-8 Students page →

Can schools consent to AI tool use on behalf of parents under COPPA?
Under specific conditions yes, per FTC guidance. The conditions include: use solely for authorized educational purposes, no commercial use of student data, no marketing to students based on data collected, no longer retention than the educational purpose requires. AI tools meeting these conditions can be deployed under school consent; AI tools that do not require explicit parental consent.
How does the framework evaluate whether an AI tool meets the school-consent conditions?
Pillar 4 governance produces an AI tool evaluation rubric specifically addressing the FTC school-consent conditions. Each AI tool in use is evaluated against the rubric; tools that meet conditions are documented as appropriate for school consent; tools that do not are either reconfigured, replaced, or moved to parental consent flow.
What about AI tools that students use on personal devices outside the school’s direct authorization?
Personal-device AI use is outside the school’s COPPA-compliance responsibility but is addressed through the district’s AI Acceptable Use Policy and parent communication. The framework’s Pillar 4 governance produces parent communication templates addressing AI use awareness and family discussion guidance.
How does COPPA interact with state student-data privacy laws?
State student-data privacy laws often impose additional or different requirements than COPPA. The framework’s Pillar 2 risk classification cross-references AI tools against COPPA and against the state student-data privacy laws applicable to the district’s location (Wisconsin, Illinois SOPPA, Minnesota, Michigan, Iowa, Ohio, Indiana, Kentucky, Missouri equivalents).
What about the FTC’s COPPA enforcement priorities?
The FTC has prioritized enforcement against educational technology vendors that violate COPPA. The framework’s Pillar 4 vendor management approach addresses this by producing vendor contract language requiring documented COPPA compliance and incident notification.
Topic · 5 questions

CIPA Content Filtering and AI

Read the full CIPA Content Filtering and AI page →

Does CIPA require AI-specific content filtering?
CIPA does not name AI specifically but requires technology protection measures to block content described in the statute. As AI-generated content becomes a significant pathway for the categories CIPA addresses, the reasonable interpretation is that technology protection measures should extend to AI-generated content. USAC has not issued specific guidance on AI content filtering as of the framework’s publication.
How does the framework extend our existing content filter for AI?
Pillar 3 observability includes content-based filtering (in addition to URL-based filtering) that evaluates the content of AI tool responses against CIPA-relevant categories. The instrumentation integrates with major content filter vendor APIs rather than replacing them.
What about AI tools that students use through SSO to district-licensed accounts?
District-licensed AI tools (Google Workspace AI features, Microsoft 365 AI features, district-procured AI tutors) typically have administrative controls that allow districts to enforce content categorization. Pillar 4 governance produces an inventory of district-licensed AI tools and their available content controls.
How does this affect our E-Rate certification?
E-Rate participants annually certify CIPA compliance. The framework supports the certification posture by producing documented evidence that AI-generated content is being filtered in addition to traditional URL-based content. The framework does not change the certification itself.
What about staff use of AI tools that produce content not appropriate for student access?
CIPA applies to student access on school networks; staff AI use raises distinct questions addressed through the district’s AI Acceptable Use Policy and staff conduct policies. Pillar 4 governance addresses staff AI use policy alongside CIPA-specific student content protection.
Topic · 5 questions

E-Rate and AI Funding

Read the full E-Rate and AI Funding page →

Can E-Rate fund a managed SOC service for our district?
Depending on funding year and the specific configuration, managed internal broadband services that include 24/7 SOC monitoring as a service feature may be eligible under Category 2. Armorstack assists with the eligibility determination, the Form 470 competitive bidding process, and the Form 471 funding request.
What about vCISO services under E-Rate?
Pure consulting services are generally not E-Rate eligible. vCISO services delivered as part of a broader managed internal broadband service may be eligible to the extent they support the eligible service. The eligibility determination depends on the specific service configuration.
Can E-Rate fund the AI Risk Assessment?
The 30-day AI Risk Assessment is offered at no cost to qualifying districts, so E-Rate funding is not required. For districts pursuing the framework implementation following the assessment, E-Rate eligibility is evaluated for each service component during scoping.
How does Armorstack’s E-Rate vendor registration affect our process?
Armorstack is an FCC-licensed wholesale telecommunications carrier with USAC SPIN registration. This status enables Armorstack to compete for E-Rate funded service procurements through the standard Form 470 competitive bidding process and to provide E-Rate eligible services under the standard E-Rate compliance posture.
What if our district has not yet filed Form 470 for this funding year?
The Form 470 must be posted on the USAC system for at least 28 days before competitive bidding can close. Armorstack supports districts who need to file Form 470 for the upcoming funding window. Filing timelines are calibrated to the USAC funding year schedule.
Topic · 5 questions

The AI Vendor Click-Wrap Crisis

Read the full The AI Vendor Click-Wrap Crisis page →

How does the framework address vendor click-wrap updates?
Pillar 4 governance produces a vendor monitoring posture that includes scheduled review of vendor terms changes, automated alerting on vendor email notifications of terms updates, and an internal sign-off workflow before staff accept materially-changed terms. The posture is designed to be operationally implementable by a small IT team.
What can K-12 districts do when AI vendor terms change without notice?
For districts in NAIC, COPPA, or FERPA-relevant scenarios, terms changes that affect student data handling can be grounds for vendor termination under the original BAA or services agreement. Pillar 4 produces termination-rights language for vendor agreements and escalation procedures for vendor terms violations.
How does this affect our existing vendor management program?
Most mid-market organizations have established vendor risk management programs centered on initial vendor onboarding and annual reassessment. The click-wrap crisis requires more frequent monitoring — effectively continuous — of vendor terms. The framework’s Pillar 4 extends the existing program with continuous-monitoring tooling and processes.
Can model contract language help?
Yes. Pillar 4 produces model contract language for AI vendors that prohibits clickthrough modification of materially-significant terms (training data use, security obligations, breach notification, indemnification). The language is drafted to be amendment-friendly for existing relationships and primary-language for new procurement.
What about state-level vendor data protection requirements?
Many states have enacted vendor data protection requirements (Illinois SOPPA, similar state student-data laws, state CCPA-equivalents, NAIC Insurance Data Security Model Law). Pillar 4 governance cross-references vendor terms against state requirements applicable to your operating territory.
Topic · 5 questions

Google Workspace for Education AI Controls

Read the full Google Workspace for Education AI Controls page →

How do we audit what Google Workspace AI features are enabled in our district?
The Workspace Admin console contains an Apps area with Gemini settings showing the current configuration. The framework’s Pillar 1 discovery work audits these settings against district policy and produces a configuration recommendation.
Does Google use student-uploaded content to train AI models?
Google’s terms for Workspace for Education specify training-data usage by edition and by feature. Pillar 4 governance reviews the current Google terms applicable to your district edition and produces clarity on what content is and is not used for training under your specific contract.
What about Gemini features for under-13 students?
Google has specific configuration options for under-13 student accounts that affect Gemini availability. Pillar 4 governance addresses configuration of these options to align with district COPPA posture and parental consent policies.
How does Gemini in Classroom affect FERPA?
Gemini features in Google Classroom may process student work and assignment data classified as education records under FERPA. The framework addresses Gemini in Classroom under the FERPA school official analysis and produces configuration recommendations aligned to district FERPA posture.
What about Workspace Marketplace third-party AI apps?
Workspace Marketplace apps with AI features that integrate via OAuth represent a separate inventory layer that the district’s Workspace audit may not capture. Pillar 1 discovery enumerates Marketplace apps and their AI features in addition to native Google AI features.

Apply for the AI Risk Assessment

Open to the first 50 qualifying mid-market organizations through July 24, 2026. No cost, no contract requirement.

Questions about this page? Call 877-890-5508 or email [email protected].