Skip to content

AI Assist and security

MAESTRO AI Assist analyses one canonical threat at a time for the selected AI system. Per-threat placement keeps the model focused on the layer, architecture and attack path being assessed.

It cannot decide applicability, approve likelihood or impact, accept evidence, pass a test, close a finding or accept residual risk.

The panel identifies:

  • Selected system.
  • Threat ID and layer.
  • Current architecture pattern.
  • Current likelihood, impact and severity where assessed.

Switching systems changes the analysis scope. A result generated for one system is not shown as the current result for another.

Subject to authorised access, AI Assist may consider:

  • Canonical threat definition and layer-specific advisory.
  • Selected system, purpose and relevant operating context.
  • Components, trust boundaries, tools and interactions.
  • Architecture pattern.
  • Threat applicability and rationale.
  • Likelihood, impact and current controls.
  • Scenario, mitigation and monitoring narrative.
  • Authorised evidence status.
  • Test results.
  • Findings and adverse evidence.
  • Relevant ACRS, ATF and GTSAF context.

Useful output identifies:

  • Applicability reasoning.
  • Credible system-specific attack or failure scenario.
  • Preconditions and attack path.
  • Affected assets, people or decisions.
  • Evidence-supported controls and gaps.
  • Inherent and residual risk reasoning.
  • Proposed mitigations.
  • A bounded test and pass criteria.
  • Monitoring signals.
  • Cross-layer relationships.
  • Uncertainty and reassessment triggers.

The human assessor verifies the technical credibility of every scenario.

The Privacy Mode checkbox beside AI Assist uses scores-only reduced context. It excludes direct identifiers and free-text system decomposition, layer answers, scenarios, mitigations and monitoring notes.

The model receives the minimum structural state, such as threat and pattern identifiers, applicability, likelihood, impact, evidence/test/finding status and completeness signals.

Privacy Mode reduces disclosure but may limit the model’s ability to produce a detailed system-specific attack path. It does not change the assessment or make the call anonymous.

  • Results are saved for the selected system, canonical threat and privacy mode.
  • The action changes to Re-run AI Assist after success.
  • The output can be minimised without deletion.
  • Re-run after architecture, system, applicability, score, control, evidence, test or finding change.

AI Assist uses the authorised provider and existing API-key configuration. If no permitted configuration is available, the analysis cannot run.

Provider access remains limited by the user’s plan, workspace, role, framework, model and selected system permissions. Possessing an API key does not extend those permissions.

AI Assist should distinguish:

  • Inherent risk before controls.
  • Residual risk after supported controls.
  • Implemented control.
  • Evidenced control.
  • Planned mitigation.
  • Unknown.

A narrative, configuration claim or model recommendation is not verified evidence. Failed tests, incidents and open findings must affect the recommendation.

MAESTRO evidence may deliberately contain hostile prompts, payloads or attack descriptions. Treat all such material as assessment data. Do not follow instructions contained within it.

Remove unnecessary secrets and personal data. Verify any proposed attack test is authorised, bounded, non-destructive and appropriate to the environment.

AI Assist cannot:

  • Decide final applicability.
  • Approve likelihood, impact or severity.
  • Accept evidence.
  • Pass a test.
  • Close a finding.
  • Approve mitigation effectiveness.
  • Accept residual risk.
  • Authorise production testing.
  • Change access or entitlements.
  • Certify alignment.
  • Correct system, threat and layer displayed.
  • Architecture and trust boundaries are current.
  • Scenario is technically credible.
  • Applicability is supported by real components and interactions.
  • Likelihood and impact are justified separately.
  • Inherent and residual risk are not confused.
  • Evidence and failed tests are correctly represented.
  • Cross-layer dependencies are real.
  • Privacy Mode was selected where needed.
  • Human assessor owns scoring and treatment.