SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsKey components of the model What the AI Security Maturity Model defines and how it's scored:
The model treats governance as a ceiling rather than a checkbox. No matter how advanced an organization's detection or protection capabilities become, its overall score can't outrun its weakest pillar or its Govern score, and self-reported claims without evidence are capped automatically. Combined with industry-specific weighting profiles and named prerequisites at every stage, the framework is built so an organization's claimed maturity has to be backed by documentation, not aspiration. The AI Security Maturity Model is the operational companion to the SANS Secure AI Blueprint and incorporates the SANS Critical AI Security Guidelines v1.3, the OWASP AI Exchange Essentials, NIST AI RMF, MITRE ATLAS™, the EU AI Act, ISO/IEC 42001, CISA's principles for secure AI integration in operational technology, the SANS 2025 AI Survey, the SANS AI Career Framework and Workforce Report, and the CSA AI Controls Matrix and AI Safety Initiative. It was validated through field assessments with practitioners and reviewed by a panel including contributors from the OWASP AI Exchange, Zenity, Microsoft, Cloud Security Alliance, and Aizome.
An operational framework, published by SANS Institute's Chris Cochran, that gives organizations a structured, evidence-scored path from no AI governance to AI-native security leadership, covering Protect, Utilize, and Govern.
Unaware/Ad Hoc, Reactive/Policy-Emerging, Defined/Risk-Informed, Managed/Integrated, and Optimizing/Adaptive, each with defined controls, metrics, and prerequisites for advancing to the next stage.
Protect (securing AI against attacks), Utilize (using AI to strengthen security operations), and Govern (the policy and oversight foundation for both).
Each of the three pillars is scored 0-5 based on documented evidence, then weighted according to an industry profile and capped by two rules: overall maturity can't exceed one stage above the Govern score, or one stage above the lowest-scoring pillar.
It depends on your AI adoption pattern, industry, regulatory environment, and risk tolerance. The model recommends targets ranging from Stage 2 for organizations with minimal AI usage to Stage 5 for AI industry leaders, with most organizations processing regulated data or running customer-facing AI targeting Stage 3 or above.


Chris Cochran is a Marine Corps veteran, cybersecurity leader, and strategist with deep expertise in threat intelligence, security operations, emerging technology, and executive leadership.
Read more about Chris Cochran




















