Most production AI failures are access failures, not model failures.
Your agent calls tools and touches data. AI security is the review layer around it.
The model is not the attack surface. The permissions are.
Models invent. That is a property of the technology and no control removes it. The damage happens when invented output reaches a tool holding a real credential, so nothing writes to production without a human sign-off the downstream service enforces.
Six events, six starting points.
A capability list makes you translate your problem into our vocabulary. This table does it the other way round.
| What happened | Where to start |
|---|---|
| The agent got write access to something real | Agent security review |
| A customer sent AI questions with the security questionnaire | Buyer due diligence pack |
| The coding assistant rolled out faster than the controls | Coding agent control baseline |
| The AI feature itself needs adversarial testing | AI application security testing |
| The model and its data sit in a cloud account nobody has reviewed | Cloud security review |
| An auditor wants the whole control set evidenced | SOC 2 readiness |
Every AI engagement ends in something you can re-run.
- Agent Blast Radius Map: the worst call and the worst chain.
- Tool Permission Ledger: scope held against scope needed.
- AI Architecture Summary a buyer security team reads alone.
- Control baseline committed as policy in your own repository.
Each one is a document or a file in your repository, not a slide. The agent security review produces the first two.
Named, versioned and dated.
A framework without a version is decoration. These are the editions findings are mapped to, read on the date below.
- OWASP Top 10 for Agentic Applications 2026 Version 2026, published 9 December 2025.
- OWASP Top 10 for LLM Applications 2026 Published 3 August 2026, replacing the 2025 edition.
- MITRE ATLAS Content release 2026.09, published 15 September 2026.
- NIST AI Risk Management Framework 1.0 Published 26 January 2023, used for governance mapping.
Framework and advisory versions above were read from the primary source on 17 September 2026.
What we do not do
- No guardrail product, and no blocking proxy we operate.
- No monitoring service. Every review is dated.
- No model training, fine-tuning or adversarial model work.
- No certification. We hold no ISO/IEC 42001:2023 certificate.
- No multimodal work across image, audio or video.
Sorami is not a certification body and issues no attestation of your controls. Readiness against an external standard is separate work, and security testing and readiness covers it.
Australian teams of ten to three hundred people shipping AI.
The buyer is usually a platform lead or a head of engineering who has been asked to approve something. It is a poor fit for a team that wants a certificate without changing a permission. Work happens in your repositories and your cloud accounts, on the same terms as a cloud security review.
Practical answers.
Do you build AI features, or only review them?
Both, but they are scoped separately. The reviews on this page are fixed-scope assessments of something you already run. Engineering work is quoted after the review, because a review that also sells the remediation stops being independent.
Do you need production access?
No. The agent review runs on read-only cloud access, tool manifests and a non-production environment that matches production. Anything touching production needs written authorisation and a rollback plan first.
Can you make the model stop inventing things?
No, and nobody can. Models invent. The design position is that invented output cannot reach a tool with real permissions without a human sign-off enforced by the downstream service.
Are you certified against ISO/IEC 42001:2023?
No. Sorami is not a certification body and holds no AI management system certificate. A register with a named owner per entry is the prerequisite for that work, and it is useful on its own.
Not sure which one you need?
Tell us what happened and who asked. We will name the right starting point, or say plainly that we are not the right firm.
Last reviewed: