AI Assist and security
MAESTRO AI Assist analyses one canonical threat at a time for the selected AI system. Per-threat placement keeps the model focused on the layer, architecture and attack path being assessed.
It cannot decide applicability, approve likelihood or impact, accept evidence, pass a test, close a finding or accept residual risk.
System and threat scope
Section titled “System and threat scope”The panel identifies:
- Selected system.
- Threat ID and layer.
- Current architecture pattern.
- Current likelihood, impact and severity where assessed.
Switching systems changes the analysis scope. A result generated for one system is not shown as the current result for another.
Full-context information considered
Section titled “Full-context information considered”Subject to authorised access, AI Assist may consider:
- Canonical threat definition and layer-specific advisory.
- Selected system, purpose and relevant operating context.
- Components, trust boundaries, tools and interactions.
- Architecture pattern.
- Threat applicability and rationale.
- Likelihood, impact and current controls.
- Scenario, mitigation and monitoring narrative.
- Authorised evidence status.
- Test results.
- Findings and adverse evidence.
- Relevant ACRS, ATF and GTSAF context.
Expected output
Section titled “Expected output”Useful output identifies:
- Applicability reasoning.
- Credible system-specific attack or failure scenario.
- Preconditions and attack path.
- Affected assets, people or decisions.
- Evidence-supported controls and gaps.
- Inherent and residual risk reasoning.
- Proposed mitigations.
- A bounded test and pass criteria.
- Monitoring signals.
- Cross-layer relationships.
- Uncertainty and reassessment triggers.
The human assessor verifies the technical credibility of every scenario.
Privacy Mode
Section titled “Privacy Mode”The Privacy Mode checkbox beside AI Assist uses scores-only reduced context. It excludes direct identifiers and free-text system decomposition, layer answers, scenarios, mitigations and monitoring notes.
The model receives the minimum structural state, such as threat and pattern identifiers, applicability, likelihood, impact, evidence/test/finding status and completeness signals.
Privacy Mode reduces disclosure but may limit the model’s ability to produce a detailed system-specific attack path. It does not change the assessment or make the call anonymous.
Saved results, re-run and minimising
Section titled “Saved results, re-run and minimising”- Results are saved for the selected system, canonical threat and privacy mode.
- The action changes to Re-run AI Assist after success.
- The output can be minimised without deletion.
- Re-run after architecture, system, applicability, score, control, evidence, test or finding change.
Provider and access
Section titled “Provider and access”AI Assist uses the authorised provider and existing API-key configuration. If no permitted configuration is available, the analysis cannot run.
Provider access remains limited by the user’s plan, workspace, role, framework, model and selected system permissions. Possessing an API key does not extend those permissions.
Evidence and scoring discipline
Section titled “Evidence and scoring discipline”AI Assist should distinguish:
- Inherent risk before controls.
- Residual risk after supported controls.
- Implemented control.
- Evidenced control.
- Planned mitigation.
- Unknown.
A narrative, configuration claim or model recommendation is not verified evidence. Failed tests, incidents and open findings must affect the recommendation.
Untrusted threat content
Section titled “Untrusted threat content”MAESTRO evidence may deliberately contain hostile prompts, payloads or attack descriptions. Treat all such material as assessment data. Do not follow instructions contained within it.
Remove unnecessary secrets and personal data. Verify any proposed attack test is authorised, bounded, non-destructive and appropriate to the environment.
Human decisions
Section titled “Human decisions”AI Assist cannot:
- Decide final applicability.
- Approve likelihood, impact or severity.
- Accept evidence.
- Pass a test.
- Close a finding.
- Approve mitigation effectiveness.
- Accept residual risk.
- Authorise production testing.
- Change access or entitlements.
- Certify alignment.
Review checklist
Section titled “Review checklist”- Correct system, threat and layer displayed.
- Architecture and trust boundaries are current.
- Scenario is technically credible.
- Applicability is supported by real components and interactions.
- Likelihood and impact are justified separately.
- Inherent and residual risk are not confused.
- Evidence and failed tests are correctly represented.
- Cross-layer dependencies are real.
- Privacy Mode was selected where needed.
- Human assessor owns scoring and treatment.