Group Purchasing
Group Purchasing

SANS AI Security Maturity Model™ eBook

SANS AI Security Maturity Model™ eBook (PDF, 8.88MB)Published: 11 May, 2026
Created by:

The SANS AI Security Maturity Model™, published 11 May 2026 by Chris Cochran, Field CISO and VP of AI Security at SANS Institute, is the operational companion to the SANS Secure AI Blueprint. It gives security teams and executives a structured path from little or no AI governance to industry-leading, AI-native security, with specific controls, metrics, and actions defined at each stage. The model was developed in alignment with the OWASP AI Exchange and OWASP Agentic Top 10, and maps to NIST AI RMF, the EU AI Act, ISO 42001, and the CSA AI Controls Matrix.

Key components of the model What the AI Security Maturity Model defines and how it's scored:

  • Three pillars structure the model: Protect (securing AI implementations against adversarial attacks, data poisoning, and prompt injection), Utilize (using AI to detect threats, automate response, and strengthen security operations), and Govern (the policy and oversight foundation that enables and constrains the other two).
  • Five maturity stages run from Unaware/Ad Hoc (Stage 1, no formal AI governance) through Reactive/Policy-Emerging (Stage 2), Defined/Risk-Informed (Stage 3), Managed/Integrated (Stage 4), to Optimizing/Adaptive (Stage 5, AI-native security and industry leadership).
  • Every assessment question is scored on a 0-5 evidence scale, and self-reported capabilities without documentary evidence cap at a score of 2, regardless of what's claimed.
  • Two cap rules prevent overstating maturity: overall maturity cannot exceed one stage above the Govern pillar score (the Governance Floor Rule), and cannot exceed one stage above the organization's lowest-scoring pillar (the Minimum Pillar Rule).
  • Pillar weighting is industry-specific: the default profile weights Protect and Govern at 35% each and Utilize at 30%, while a Government/Defense profile weights Govern at 40% and an Education & Research profile weights it at 45%.
  • Recommended target stages vary by organization profile, from Stage 2 for minimal AI usage/basic SaaS features up to Stage 5 for organizations positioning AI security as a competitive differentiator.
  • Non-Human Identity (NHI) management and a documented human owner for every deployed AI agent become mandatory starting at Stage 3.
  • Data classification is a named prerequisite for advancing past Stage 1, since an effective AI policy can't be written without knowing where sensitive data lives.
  • The model distinguishes Security incidents (prompt injection, data exfiltration, model theft, owned by the Security team) from Safety/Reliability incidents (harmful bias, hallucination, legal liability, owned by Legal/Risk).
  • Organizations with high AI adoption but low workforce AI literacy are directed to prioritize Governance maturity to Stage 3 immediately, regardless of their technical threat landscape.
  • The model maps each of its five stages against five external frameworks side by side: NIST AI RMF, the EU AI Act, ISO 42001, the OWASP AI Exchange, and the CSA AI Controls Matrix.
  • The framework introduces the Principle of Least Agency, the agentic analogue to the Principle of Least Privilege, requiring organizations to confirm that agentic autonomy is genuinely necessary before scoping agent permissions and identity.

The model treats governance as a ceiling rather than a checkbox. No matter how advanced an organization's detection or protection capabilities become, its overall score can't outrun its weakest pillar or its Govern score, and self-reported claims without evidence are capped automatically. Combined with industry-specific weighting profiles and named prerequisites at every stage, the framework is built so an organization's claimed maturity has to be backed by documentation, not aspiration. The AI Security Maturity Model is the operational companion to the SANS Secure AI Blueprint and incorporates the SANS Critical AI Security Guidelines v1.3, the OWASP AI Exchange Essentials, NIST AI RMF, MITRE ATLAS™, the EU AI Act, ISO/IEC 42001, CISA's principles for secure AI integration in operational technology, the SANS 2025 AI Survey, the SANS AI Career Framework and Workforce Report, and the CSA AI Controls Matrix and AI Safety Initiative. It was validated through field assessments with practitioners and reviewed by a panel including contributors from the OWASP AI Exchange, Zenity, Microsoft, Cloud Security Alliance, and Aizome.

FAQ

An operational framework, published by SANS Institute's Chris Cochran, that gives organizations a structured, evidence-scored path from no AI governance to AI-native security leadership, covering Protect, Utilize, and Govern. 

Unaware/Ad Hoc, Reactive/Policy-Emerging, Defined/Risk-Informed, Managed/Integrated, and Optimizing/Adaptive, each with defined controls, metrics, and prerequisites for advancing to the next stage. 

Protect (securing AI against attacks), Utilize (using AI to strengthen security operations), and Govern (the policy and oversight foundation for both). 

Each of the three pillars is scored 0-5 based on documented evidence, then weighted according to an industry profile and capped by two rules: overall maturity can't exceed one stage above the Govern score, or one stage above the lowest-scoring pillar. 

It depends on your AI adoption pattern, industry, regulatory environment, and risk tolerance. The model recommends targets ranging from Stage 2 for organizations with minimal AI usage to Stage 5 for AI industry leaders, with most organizations processing regulated data or running customer-facing AI targeting Stage 3 or above. 

Meet Your Author

Chris Cochran
Chris Cochran

Chris Cochran

Chris Cochran is a Marine Corps veteran, cybersecurity leader, and strategist with deep expertise in threat intelligence, security operations, emerging technology, and executive leadership.

Read more about Chris Cochran