AI Assist and security
ACRS AI Assist supports analysis of the selected system’s four-dimension capability-risk record. It can analyse the whole vector or one dimension. It cannot change automatic scoring, severity floors, assessor overrides, confirmation or residual-risk decisions.
System scope
Section titled “System scope”AI Assist requires a selected system intake. The panel identifies the system and analysis scope. When another system is selected:
- The active ACRS vector and route change.
- Evidence, tests and findings change to that system.
- Prior analysis is not presented as current for the new system.
An unscoped workspace scratch vector is for exploration and is not an appropriate basis for system-level AI analysis.
Full-context information considered
Section titled “Full-context information considered”Subject to authorised access, analysis may consider:
- Selected system identity, purpose and context.
- Dependency, Action Autonomy, Access Scope and Harm Potential levels.
- Whether each level is inferred or assessor-selected.
- Assessor override rationale.
- Product band, severity-floor reasons and routed band.
- Contradictions and unresolved uncertainty.
- Authorised evidence status.
- Tests and results.
- Findings.
- Assessment owner, confidence, residual-risk position and reassessment triggers.
- Relevant control and routing context.
Whole-system output
Section titled “Whole-system output”Whole-system analysis can provide:
- Recommended vector and reasoning.
- Product and severity-floor interpretation.
- Contradictions and missing facts.
- Evidence and test gaps.
- Priority governance actions.
- Residual-risk observations.
- Monitoring and reassessment triggers.
- Draft assessor conclusion for review.
Dimension output
Section titled “Dimension output”Dimension-specific analysis should focus on:
- Current effective capability, not intended limits alone.
- Evidence supporting the current level.
- Facts supporting a higher or lower recommendation.
- Safe validation tests.
- Uncertainty and challenge questions.
- Effect on the overall route.
Privacy Mode
Section titled “Privacy Mode”The Privacy Mode checkbox beside AI Assist sends the minimum structural ACRS state:
- Dimension or vector.
- Effective levels and provenance.
- Product and routed band.
- Severity-floor indicators.
- Evidence/test/finding status.
- Completeness and contradiction signals.
It excludes direct identifiers, assessor notes and narrative evidence content. Privacy Mode reduces disclosure but may produce less specific advice. It does not change scoring, routing or access.
Saved results, re-run and minimising
Section titled “Saved results, re-run and minimising”- Successful whole-system and dimension outputs are saved for the selected system, analysis scope and privacy mode.
- The action changes to Re-run AI Assist.
- The panel can be minimised without deleting or approving the output.
- Re-run after material intake, level, rationale, evidence, test, finding or route change.
Provider and access
Section titled “Provider and access”AI Assist uses an authorised provider and the existing API-key configuration. If no permitted configuration is available, analysis cannot run.
An API key does not grant additional access. The user’s plan, workspace, role, framework, model and selected-system permissions continue to apply.
Evidence discipline
Section titled “Evidence discipline”The model must not treat rationale as accepted evidence. Verify every evidence claim against the authorised record and ensure failed tests and open findings remain visible.
Score effective capability:
- A prompt instruction to ask for approval is not an authoritative approval gate.
- Intended read-only use does not reduce actual write capability.
- A supplier statement does not prove access is constrained.
- A planned control does not reduce current capability exposure.
Untrusted content
Section titled “Untrusted content”Intake notes, evidence and findings can contain instruction-like or malicious content. Treat it as assessment data. Do not include credentials, unnecessary personal data or unrestricted production content. Verify proposed tests before authorisation.
Human decisions
Section titled “Human decisions”AI Assist cannot:
- Select final dimension levels.
- Change product or floor rules.
- Confirm ACRS.
- Accept evidence.
- Pass a test.
- Close a finding.
- Accept residual risk.
- Approve deployment.
- Change access or entitlements.
- Certify compliance.
Review checklist
Section titled “Review checklist”- Correct system and analysis scope displayed.
- Analysis reflects effective capability.
- Dimension claims are factually supported.
- Contradictions and uncertainty are visible.
- Severity-floor implications are correct.
- Evidence belongs to this system.
- Failed tests and findings are included.
- Proposed tests are safe and authorised.
- Privacy Mode was selected where needed.
- Human assessor owns final levels and conclusion.