AI Security Readiness Quiz

Ten short questions covering data handling, prompt-injection awareness, shadow-AI usage, human review practices, incident escalation, model output validation, vendor risk, governance ownership, logging, and model change management. Returns a score of 0–30 and a band (At-risk / Emergent / Developing / Mature) with interpretation.

When employees use third-party LLMs, what types of data are they actually allowed to paste in?
How well does your team understand prompt-injection and indirect-prompt-injection risks?
How visible is shadow AI usage in your environment?
For decisions informed by AI, what is the human-review posture?
When AI behaves unexpectedly in production, who gets paged and what is the runbook?
How do you validate AI outputs that flow back into your systems or to customers?
How do you assess AI vendors?
Who owns AI governance at your organization?
How are AI prompts and responses logged?
When you upgrade or swap an AI model in production, what controls fire?