SovAIHub
ModulesSAI-110
SAI-110 table of contents
Tutorial2 min readContent reviewed

AI threat-model workshop

Produce an asset inventory, attack-surface map, prioritized scenarios, control plan, evidence plan, and residual-risk register.

Last content review 2026-08-03Included in SAI-110

Workshop objective

Create a traceable threat model for the synthetic private knowledge assistant introduced in SAI-100. Use synthetic documents and fictional identities. Do not test production systems.

Download SAI-110 threat-register templateA CSV register for traceable scenarios, controls, evidence, residual risk, owners, and state.

Step 1: Confirm scope

Review the system definition, prohibited uses, actors, lifecycle, context diagram, trust zones, and numbered flows. Record exclusions and the person authorized to accept them.

Exit check: reviewers agree on what system and version is being modelled.

Step 2: Inventory assets and surfaces

Use AI assets and attack surfaces. Include documents, permissions, index, prompts, model, packages, identities, gateways, operators, evidence, backups, and recovery capability.

Exit check: each high-value asset has an owner, required property, location, boundary, interface, and recovery need.

Step 3: Model actors and abuse cases

Include an external actor, authorized user, privileged operator, compromised service identity, supplier or artifact source, and unintended misuse case. Remove actors that cannot reach any surface.

Exit check: each abuse case identifies starting access, action, boundary, asset, and consequence.

Step 4: Develop scenarios

Create at least eight end-to-end scenarios across:

  • Artifact or model supply chain.
  • Document ingestion and retrieval permissions.
  • Prompt, context, and output handling.
  • Identity, gateway, or routing bypass.
  • Resource exhaustion or service disruption.
  • Privileged operation and evidence integrity.
  • Backup, restore, update, or retirement.

Exit check: every scenario references diagram flow IDs and asset IDs.

Step 5: Prioritize and treat

Apply the same impact, feasibility, reach, detectability, recoverability, control-strength, and uncertainty definitions to every scenario. Select treatment for the highest-priority scenarios.

Exit check: planned controls have not been counted as implemented controls.

Step 6: Define tests and evidence

For the five highest-priority scenarios, define:

  • A negative test for the prohibited or unsafe path.
  • A positive test for approved behavior.
  • Expected policy decision and system response.
  • Required version identifiers.
  • Evidence produced, protected, and reviewed.
  • Containment and recovery action.

Workshop package

Deliver:

  1. Scope, assumptions, and exclusions.
  2. Asset-to-attack-surface inventory.
  3. Actor and abuse-case register.
  4. Prioritized threat-scenario register.
  5. Control and verification plan.
  6. Residual-risk register.
  7. Threat-driven readiness backlog.

The workshop is an educational design review. It is not a penetration test or production security authorization.