← Kris's Lab
AI-SHIELD

AI-SHIELD · Free tool by Kris McCabe

How exposed is your AI, really?

An 18-question maturity assessment across six pillars — Supply chain, Human oversight, Identity & access, Evaluation, Logging, and Data — with evidence-anchored scoring and a governance cap designed to resist self-assessment inflation.

0 of 18 answered

Why not just use what exists

The frameworks are thorough. That's the problem.

Every major AI security framework published in the last two years — NIST's AI RMF, ISO/IEC 42001, the Cloud Security Alliance's 243-control AI Controls Matrix — is built for an organization with a security team and months to run an audit. AI-SHIELD is scoped differently on purpose: eighteen questions a person who actually built or operates the system can answer honestly in fifteen minutes.

FrameworkWhat it actually isTime to a score
NIST AI RMF + GenAI Profile72 subcategories across 19 categoriesWeeks
ISO/IEC 42001Certifiable management system, audit cycleMonths
CSA AI Controls Matrix243 control objectives, 18 domainsWeeks
OWASP LLM / ASI Top 10Ranked vulnerability lists, no scoreN/A
AI-SHIELD18-question self-assessment~15–20 minutes

Six pillars, one word

Each pillar maps to a real, current body of work — condensed into three questions.

Scoring that resists checkbox theater

Three design decisions push back on self-assessment inflation.

1

Answers describe evidence, not feelings

Every level (0–4) describes a concrete, checkable state — a document that exists, a test that ran — not a vibe.

2

One weak pillar caps the whole score

Your Human Oversight & Governance score acts as a ceiling: the overall score can't exceed it by more than one point.

Overall = min( average(S, H, I, E, L, D),  H + 1 )
3

A single zero is flagged regardless of the average

Any question scored 0 — a total absence of a control — surfaces as a named Critical Gap in your results, independent of your overall score.

Five ratings, plainly named

The full framework

All eighteen questions, in detail, with the specific control each one maps to in other frameworks, and why each one matters in plain terms.

Ready to see where you stand?

Name this assessment

Give it a name so you can keep it separate from other systems you assess later — e.g. "Customer support agent, production". Assessing several AI systems separately is more honest than blending them into one score.

How do you primarily use AI?

Select all that apply — most systems aren't just one of these. This sets a short context note under each pillar as you go; it doesn't skip or hide any questions.

Answer all 18 questions to see your results.