Skip to main content
The score is based on three key factors:
  • Tool Usage Volume (T): How many AI tools are being used?
    • The more AI tools in use, the higher the risk exposure.
  • Risk of Exploitation (R): Are these tools vulnerable to attacks?
    • Evaluates how prevalent usage is among employees and whether those tools have known vulnerabilities (v2)
  • Security Controls (S): Are security measures in place? (v2)
    • If access controls, MFA, encryption, monitoring, DLP practices are in place, the risk score decreases
Once calculated, the AI Exposure Score is normalized (0-100 scale) and classified into four risk levels: