ModulesSAI-110
SAI-110 table of contents
Trust Boundaries and Threat Modelling
Model data flows, actors, assets, attack surfaces, trust zones, and risk scenarios for private AI workloads.
Learning outcomes
What you should be able to do
- Draw system and data-flow boundaries
- Identify AI-specific threats and abuse paths
- Translate threat scenarios into control requirements
Curriculum
Work through 4 sections in order.
The chapters are individually addressable documentation pages. You can link directly to a concept from another program, architecture decision, or implementation guide.
Threat-modelling foundations
Define the system and its trust boundaries before describing threats.
Introduction to AI threat modelling
Use threat modelling to identify credible failure, misuse, compromise, and abuse scenarios before selecting controls.
Define the AI system
Set the intended purpose, actors, assets, dependencies, lifecycle, and system boundary before selecting controls.
Trust boundaries and data flows
Map where trust changes and where data, artifacts, requests, identities, tools, and evidence cross a boundary.
Assets, actors, and scenarios
Identify what matters, where it is exposed, who or what can act, and how harm could occur.
AI assets and attack surfaces
Inventory the data, models, prompts, artifacts, identities, tools, interfaces, infrastructure, and evidence that require protection.
Threat actors and abuse cases
Model external, insider, supplier, user, model, and automated-agent actions without assuming one universal attacker.
Develop AI threat scenarios
Build traceable scenarios across ingestion, retrieval, inference, tools, supply chains, operations, and evidence.
Prioritize and control
Rank credible scenarios and connect them to testable controls, evidence, and residual-risk decisions.
Prioritize threats and residual risk
Rank scenarios using explicit likelihood, impact, exposure, detectability, control strength, and uncertainty criteria.
Write effective control objectives
Translate sovereignty goals into testable statements of what must be allowed, prevented, approved, observed, retained, and recovered.
Evidence by design
Design evidence alongside controls so important decisions, releases, configurations, and operating events can be verified.
Apply and assess
Complete a structured threat model and verify its traceability and decision quality.
AI threat-model workshop
Produce an asset inventory, attack-surface map, prioritized scenarios, control plan, evidence plan, and residual-risk register.
SAI-110 knowledge check
Verify that threat scenarios are complete, traceable, prioritized, and connected to controls and evidence.
Practical completion package
- Scoped AI system and asset inventory
- Trust-boundary and attack-surface map
- Threat-actor and abuse-case register
- Prioritized threat-scenario register
- Control, evidence, and residual-risk plan
Current release boundary
This public curriculum teaches a structured AI threat-modelling method. It is not a penetration test, production security approval, or guarantee that every threat has been identified. Practical assurance requires system-specific review and testing.