Skip to main content
The score is based on three key factors:
  • Tool Usage Volume (T) – How many AI tools are being used?
    • The more AI tools in use, the higher the risk exposure.
  • Risk of Exploitation (R) – Are these tools vulnerable to attacks?
    • Evaluates how prevalent usage is amongst employees and 
    • Whether those tools have known vulnerabilities (v2)
  • Security Controls (S) – Are security measures in place? (v2)
    • If access controls, MFA, encryption, monitoring, DLP practices are in place, the risk score decreases
Once calculated, the AI Exposure Score is normalized (0-100 scale) and classified into four risk levels:
Score RangeRisk LevelMeaning
0-20Low (Green)Minimal AI risk exposure, strong security controls.
21-50Moderate (Yellow)Some AI risk, but manageable with improvements
51-80High (Orange)Significant AI exposure, potential security risks.
81-100Critical (Red)Major AI security gaps, immediate action required.
I