Black Bay Security
Get your no-cost assessment deepcurrent login
COMPASS journey map
Black Bay Security

The AI security journey

From first prompt to AI-enabled business, with the data, milestones and measures to prove progress

An expedition guide for organizations starting an AI security program. Five stages and seventeen steps, organized by the seven COMPASS domains, the 18 AI security functions and the 10 questions every leader must answer.

Next stopFind shadow AI.
97%

of organizations with an AI breach lacked AI access controls

IBM, 2025
63%

of breached organizations had no AI governance policy, or were still writing one

IBM, 2025
31%

of breaches now start with vulnerability exploitation, the top initial access vector

Verizon DBIR, 2026
40%+

of agentic AI projects will be canceled by end of 2027, Gartner predicts

Gartner, June 2025

Seven COMPASS domains in orbit around the AI estate they protect

Why the journey starts now

AI adoption is outrunning AI security

The first year of breach data on AI shows the same pattern everywhere: adoption first, governance and access control later. The gap is where attackers are already working, and where the cost shows up.

The AI oversight gap

Share of organizations studied, IBM Cost of a Data Breach 2025 (600 breached organizations, March 2024 to February 2025)

0%25%50%75%100%97%of those breached lacked proper AI access controls97% of those breached lacked proper AI access controls (IBM Cost of a Data Breach 2025)63%of breached organizations had no AI governance policy or were still writing one63% of breached organizations had no AI governance policy or were still writing one (IBM Cost of a Data Breach 2025)20%of organizations reported a breach due to shadow AI (one in five)20% of organizations reported a breach due to shadow AI (one in five) (IBM Cost of a Data Breach 2025)16%of breaches studied involved attackers using AI tools16% of breaches studied involved attackers using AI tools (IBM Cost of a Data Breach 2025)13%of organizations reported breaches of AI models or applications13% of organizations reported breaches of AI models or applications (IBM Cost of a Data Breach 2025)
$670K

higher breach costs where shadow AI use was high

IBM, 2025
$1.9M

average savings with extensive AI and automation in security operations

IBM, 2025
$4.44M

global average cost of a data breach

IBM, 2025
“As AI becomes more deeply embedded across business operations, AI security must be treated as foundational.”
Suja Viswesan, Vice President, Security and Runtime Products, IBMIBM press release, July 30, 2025

The window is closing. Vulnerability exploitation is now the top initial access vector at 31% of breaches (Verizon DBIR 2026), and Gartner expects over 40% of agentic AI projects to be canceled by the end of 2027, in part for inadequate risk controls.

Your navigation kit

Three lenses, one map

Every stop on the road is tagged with the COMPASS domains it builds, the AI security functions it puts to work and the leadership questions it answers. Hover any domain, function or question in the interactive version to light up its steps.

COMPASS: seven domains

Black Bay's seven-domain AI security model, aligned to NIST AI RMF and adapted from Black Bay's COMPASS framework. Plan to implement, design to operate.

Governance, risk and compliance: Policy, ownership, risk tiers, regulatory mapping and audit evidence.GRCSecure AI operations: Logging, detection, response and recovery for AI in production.Secure AIopsModel protection: Model gateway, guardrails, scanning, AI-BOM and red teaming.ModelprotectionSecure development lifecycle: Threat modeling, secure code, CI/CD gates and model validation.SDLCInfrastructure security: GPU fabric, network, cloud, DPU, zero trust and post-quantum.InfrastructureIdentity security: Human and non-human identity, agent credentials, least privilege.IdentityData protection: Discovery, classification, DLP, lineage, encryption and backup.DataprotectionCOMPASSCyber resiliencefoundation
  • Governance, risk and compliancePolicy, ownership, risk tiers, regulatory mapping and audit evidence.
  • Secure AI operationsLogging, detection, response and recovery for AI in production.
  • Model protectionModel gateway, guardrails, scanning, AI-BOM and red teaming.
  • Secure development lifecycleThreat modeling, secure code, CI/CD gates and model validation.
  • Infrastructure securityGPU fabric, network, cloud, DPU, zero trust and post-quantum.
  • Identity securityHuman and non-human identity, agent credentials, least privilege.
  • Data protectionDiscovery, classification, DLP, lineage, encryption and backup.

The 10 questions every leader must answer

The top ten client concerns raised in AI security briefings, grouped into four control areas. A program is ready to scale when it can answer all ten with evidence.

Govern and inventory

  1. Q1Who owns AI risk, and what must be approved before a use case scales?
  2. Q2Do we have a living inventory of every model, agent, vendor, prompt, dataset, RAG source and API?

Protect data and access

  1. Q3Can sensitive data reach prompts, retrieval, logs or outputs without a control in the path?
  2. Q7Which agent actions require least privilege, human approval and a kill switch?

Secure models and agents

  1. Q4Can we prove the provenance, integrity and license of every model, dataset and plug-in?
  2. Q5How do we stop untrusted content from steering our models and tools?
  3. Q6Do we test for jailbreaks, extraction, poisoning and unsafe output before and after release?

Operate and recover

  1. Q8Are GPUs, registries, pipelines and the management plane hardened like production?
  2. Q9Will the SOC see drift, abuse, leakage and tool misuse in production?
  3. Q10Can we contain, roll back and investigate an AI incident within hours?

The 18 AI security functions

Capability areas beneath the seven domains, mapped from the Black Bay AI Security Vendor Catalog v2.0. The color shows each function's primary domain.

  1. F01AI security posture management (AI-SPM)
  2. F02AI governance, risk and compliance
  3. F03Runtime guardrails and LLM firewall
  4. F04Agentic AI, MCP security and agent identity
  5. F05AI usage monitoring, shadow AI and GenAI DLP
  6. F06Data security for AI (DSPM, privacy, lineage)
  7. F07Model supply chain, scanning and AI-BOM
  8. F08Secure development (SAST, SCA, secrets, AI code)
  9. F09API security and AI gateway
  10. F10AI-driven security operations (SOC, XDR, SIEM)
  11. F11Cloud and Kubernetes security for AI
  12. F12Identity, access and non-human identity (IAM, NHI, PAM)
  13. F13AI infrastructure, GPU, confidential computing and agent isolation
  14. F14Deepfake defense, content authenticity and AI fraud
  15. F15AI red teaming, validation and adversarial ML
  16. F16Endpoint, email, OT/IoT and specialty AI security
  17. F17Cyber risk quantification, TPRM and exposure management
  18. F18Post-quantum cryptography and crypto agility

Functions by domain

Primary domain for each function; a working view aligned to COMPASS topics.

Governance, risk and compliance: 3 functions3Secure AI operations: 2 functions2Model protection: 5 functions5Secure development lifecycle: 1 functions1Infrastructure security: 4 functions4Identity security: 2 functions2Data protection: 1 functions118functions
GRC (3)Secure AI ops (2)Model protection (5)SDLC (1)Infrastructure (4)Identity (2)Data protection (1)
The route

Five stages, seventeen steps

Each stage has a timeframe, a target maturity level, exit criteria and the threats you will meet along the way. Each stop shows the three actions that matter most, how to measure progress and who owns the work.

Starting point

Start here

AI is already inside the enterprise
Today
Level1Unaware
  • Employees use GenAI in browsers, SaaS and developer tools
  • Copilots and agents are in pilots without clear owners
  • Security controls are inherited from traditional IT
Stage 1 of 5

Discover

See everything
1
Level2Unaware to initiating
Days 0 to 30Maturity level 1 to 2: unaware to initiating

Exit criteria: Named owners, interim AI policy, AI inventory v1 and an COMPASS baseline.

Shadow AI and unsanctioned copilotsLLM02 Sensitive information disclosure
01
Stage 1: Discover

Name the owners and charter the AI council

Put accountable leaders and decision rights in place before AI scales further.

  • Name an executive sponsor and one accountable AI risk owner
  • Charter a cross-functional council with approval authority
  • Publish an interim AI acceptable use policy within 30 days
Measure: Share of AI use cases with named business, system and data owners (target 100%)
Owner: CISO with the Chief AI or Data Officer
GRCF02Q1
Hover or tap for how-to, actions and owners
02
Stage 1: Discover

Find shadow AI and build a living inventory

You cannot secure what you cannot see. Discover every model, agent, copilot and MCP server in use.

  • Turn on GenAI discovery in the SSE, CASB and EDR you already own
  • Scan cloud accounts with AI security posture management
  • Give every AI asset an owner or a removal date
Measure: Share of AI assets with an owner; unsanctioned AI apps trending down
Owner: AI security lead
GRCSecure AI opsF01F05Q2
Hover or tap for how-to, actions and owners
03
Stage 1: Discover

Baseline COMPASS maturity and map your tools

Score all seven COMPASS domains, map installed tools to them, and quantify the top risks.

  • Score each domain on the five-level maturity scale
  • Map every installed tool as primary or overlap coverage
  • Quantify the top five AI loss scenarios in dollars
Measure: Maturity score per COMPASS domain, baseline and 18-month target
Owner: CISO
GRCF17Q1 to Q10
Hover or tap for how-to, actions and owners
“COMPASS gives us a common language and structured approach for managing AI risk.”
CIO, Large Global Financial Company
Stage 2 of 5

Assess and plan

Know what matters
2
Level2Initiating
Days 30 to 90Maturity level 2: initiating

Exit criteria: AI data classified, risk tiers live, one control library and a funded roadmap.

LLM08 Vector and embedding weaknessesOver-broad RAG permissions
04
Stage 2: Assess and plan

Classify data and fence what AI can reach

Most early AI incidents are data incidents. Control what flows into prompts, retrieval, logs and outputs.

  • Discover and label sensitive data before AI can reach it
  • Fix over-shared sources feeding copilots and RAG
  • Enforce GenAI DLP on prompts, uploads and outputs
Measure: Share of RAG and copilot sources permission-reviewed; GenAI DLP events per week
Owner: Data owners with data security
Data protectionF06F05Q3
Hover or tap for how-to, actions and owners
05
Stage 2: Assess and plan

Risk-tier every use case and set approval gates

Make the approved path faster than the shadow path, with controls proportional to risk.

  • Launch one AI intake form and use case registry
  • Define four risk tiers with required controls for each
  • Publish approved patterns so low-risk use cases self-approve
Measure: Median approval time by risk tier
Owner: AI governance council
GRCF02Q1Q7
Hover or tap for how-to, actions and owners
06
Stage 2: Assess and plan

Build one control library and the roadmap

Map controls once to NIST AI RMF, ISO/IEC 42001, the EU AI Act, OWASP and MITRE ATLAS.

  • Use NIST AI RMF as the spine and crosswalk the rest
  • Assign an owner and evidence source to every control
  • Approve a phased 36-month roadmap and business case
Measure: Share of controls with an owner and an automated evidence source
Owner: GRC and compliance
GRCF02F17Q1
Hover or tap for how-to, actions and owners
Stage 3 of 5

Design and protect

Build the guardrails
3
Level3Defined
Days 90 to 180Maturity level 3: defined

Exit criteria: Agents have identities, a gateway is in the path, supply chain and release gates enforced.

LLM01 Prompt injectionASI03 Identity and privilege abuseLLM03 Supply chain
07
Stage 3: Design and protect

Give every agent an identity and least privilege

When AI can act, identity becomes the control point. Treat every agent as a governed non-human identity.

  • Register each agent as a distinct identity with an owner
  • Replace static keys with short-lived, scoped tokens
  • Require human approval for high-risk actions, with a kill switch
Measure: Share of agents with scoped, short-lived credentials; standing privileges removed
Owner: Identity and access team
IdentityF12F04Q7Q5
Hover or tap for how-to, actions and owners
08
Stage 3: Design and protect

Put an AI gateway and guardrails in the path

Inspect prompts, outputs and tool calls inline, on paths applications cannot bypass.

  • Route model traffic through egress and ingress AI gateways
  • Govern the tool-call plane with an MCP and agent gateway
  • Enforce the path in the network and log with correlation IDs
Measure: Share of model and tool traffic through a gateway; bypass attempts detected
Owner: Security architecture with the platform team
Model protectionSecure AI opsF03F09Q5
Hover or tap for how-to, actions and owners
09
Stage 3: Design and protect

Secure the model and AI supply chain

Treat models, datasets, embeddings, plug-ins and MCP servers as supply chain dependencies.

  • Stand up an approved model registry and block direct pulls
  • Scan, sign and verify every model and dataset
  • Pin dependencies and publish an AI-BOM per system
Measure: Share of production models with verified provenance and signature
Owner: AI and ML platform team
Model protectionSDLCF07Q4
Hover or tap for how-to, actions and owners
10
Stage 3: Design and protect

Shift left: threat model and gate every release

Traditional AppSec misses AI-specific attacks. Test for them before anything reaches production.

  • Threat model with STRIDE and MITRE ATLAS
  • Scan code, secrets and AI-generated code on every pull request
  • Gate releases on jailbreak, injection and leakage tests
Measure: Share of AI releases passing automated evaluation gates
Owner: Application security and product engineering
SDLCF08F15Q6
Hover or tap for how-to, actions and owners
11
Stage 3: Design and protect

Harden AI infrastructure and isolate agents

Protect GPU clusters, registries and pipelines like the production systems they are.

  • Segment training, inference and data tiers
  • Lock down the GPU management plane, BMC and firmware
  • Run agent code execution in sandboxes or micro-VMs
Measure: Critical misconfigurations on AI infrastructure; share of agent execution sandboxed
Owner: Infrastructure and network teams
InfrastructureF11F13Q8
Hover or tap for how-to, actions and owners
“Identity is the weakest seam in enterprise AI deployment.”
Todd NeilsonPrincipal AI-Security Advisor, Black BayBlack Bay AI Security practice thesis, 2026
Stage 4 of 5

Operate and monitor

Run it like production
4
Level4Managed
Months 6 to 18Maturity level 4: managed

Exit criteria: SOC coverage for every AI system, continuous red teaming and tested playbooks.

ASI10 Rogue agentsLLM04 Data and model poisoningASI06 Memory and context poisoning
12
Stage 4: Operate and monitor

Wire AI telemetry into the SOC

AI risk changes after deployment. Give the SOC the signals and playbooks to see it.

  • Stream gateway, guardrail and agent logs into the SIEM
  • Detect injection, extraction, leakage and anomalous tool use
  • Baseline agent behavior as non-human identities
Measure: Share of AI systems with SOC coverage; mean time to detect AI incidents
Owner: Security operations
Secure AI opsF10Q9
Hover or tap for how-to, actions and owners
13
Stage 4: Operate and monitor

Red team continuously

Every model swap, prompt change or new tool resets your assurance. Keep testing.

  • Automate adversarial testing against production models and agents
  • Test agentic risks: goal hijack, tool misuse, memory poisoning
  • Feed findings into guardrails and release gates
Measure: Open critical AI findings and mean time to close
Owner: Offensive security (AI red team)
Model protectionF15Q6
Hover or tap for how-to, actions and owners
14
Stage 4: Operate and monitor

Rehearse AI incident response and rollback

Build and practice playbooks for leakage, poisoning, agent misexecution and deepfake fraud.

  • Predefine containment: revoke, disable, quarantine, roll back
  • Preserve prompts, outputs, retrieval traces and tool logs
  • Run tabletops with security, legal, privacy and communications
Measure: Time to contain in tabletop; share of AI scenarios with a tested playbook
Owner: Incident response lead
Secure AI opsF10F14Q10
Hover or tap for how-to, actions and owners
“Plan to implement, design to operate.”
Black Bay COMPASSAI Readiness Model for Operational ResilienceBlack Bay COMPASS framework
Stage 5 of 5

Optimize and scale

Make secure the fast path
5
Level5Optimized
Months 18 to 36Maturity level 5: optimized

Exit criteria: Continuous compliance, a paved road for agents and a post-quantum roadmap.

ASI09 Human-agent trust exploitationHarvest now, decrypt later
15
Stage 5: Optimize and scale

Automate compliance and report risk in dollars

Move from point-in-time audits to continuous evidence and board reporting in business terms.

  • Automate evidence from gateways, pipelines and identity systems
  • Report AI risk to the board in dollars and trends
  • Add AI clauses to third-party contracts
Measure: Audit preparation time; share of controls continuously monitored
Owner: GRC and enterprise risk
GRCF02F17Q1
Hover or tap for how-to, actions and owners
16
Stage 5: Optimize and scale

Pave the road with a secure AI platform

Make the secure path the fast path: self-service agents with identity, policy and observability built in.

  • Publish golden paths for copilots, RAG apps and agents
  • Issue identity and policy-as-code at registration
  • Measure idea-to-production time for governed agents
Measure: Time from idea to governed production agent
Owner: Platform engineering
SDLCIdentityF03F04F09F12Q2Q5Q7
Hover or tap for how-to, actions and owners
17
Stage 5: Optimize and scale

Future-proof for post-quantum and the next wave

Build crypto agility and extend COMPASS to physical AI, OT and whatever comes next.

  • Inventory cryptography protecting weights, data and agent channels
  • Plan migration to NIST FIPS 203, 204 and 205
  • Re-baseline COMPASS maturity every year
Measure: Share of cryptographic assets inventoried; migration milestones met
Owner: Security architecture (cryptography and OT)
InfrastructureF18F16F14Q8
Hover or tap for how-to, actions and owners
Arrival checkpoint

Ten questions, answered with evidence

Maturity level 5: optimized
Arrive
Level5Optimized

Every AI use case, model and agent is owned, inventoried, protected, monitored and recoverable, and leadership can answer each question below with evidence.

Q1Q2Q3Q4Q5Q6Q7Q8Q9Q10
Measure the climb

Maturity you can show the board

Track progress on the Black Bay five-level AI security maturity model. Programs that follow a framework keep climbing; programs built from point tools tend to stall at level 2, where coverage is fragmented and enforcement uneven.

Maturity trajectory over 36 months

Illustrative target path by stage, compared with an ad hoc program

12345Stage1 Unaware2 Initiating3 Defined4 Managed5 Optimized03612182436Months from program startMonth 0: level 1.3Month 1: level 1.8Month 3: level 2.4Month 6: level 3.1Month 12: level 3.6Month 18: level 4.0Month 24: level 4.4Month 36: level 4.8COMPASS-guided programAd hoc controlsplateau at level 2
COMPASS-guided programAd hoc controlsStage bands 1 to 5

Illustrative. Replace with the client's COMPASS assessment scores at each stage exit.

Baseline versus 18-month target

Maturity by COMPASS domain, scale 1 to 5

12345● GRC● Secure AI ops● Model protection● SDLC● Infrastructure● Identity● Data protectionGovernance, risk and compliance: target 4Governance, risk and compliance: baseline 2Secure AI operations: target 4Secure AI operations: baseline 2Model protection: target 3.5Model protection: baseline 1Secure development lifecycle: target 4Secure development lifecycle: baseline 2Infrastructure security: target 4Infrastructure security: baseline 3Identity security: target 4Identity security: baseline 2Data protection: target 4Data protection: baseline 2
Typical starting baselineTarget at month 18

Illustrative example of a common starting profile. Score the client in step 03.

Coverage and cadence

Every domain, on a timeline

No single step or product covers COMPASS end to end. The heat map shows where each step builds a domain as the primary owner or as support; the timeline shows how the workstreams overlap from build to run.

COMPASS coverage by step

Solid cell: primary domain. Faded cell: supporting domain. Click a cell in the interactive version to open that step.

● GRC● Secure AI ops● Model protection● SDLC● Infrastructure● Identity● Data protection01 Owners and AI councilStep 1 Owners and AI council: Governance, risk and compliance, primaryStep 1 Owners and AI council: Secure AI operations, not addressedStep 1 Owners and AI council: Model protection, not addressedStep 1 Owners and AI council: Secure development lifecycle, not addressedStep 1 Owners and AI council: Infrastructure security, not addressedStep 1 Owners and AI council: Identity security, not addressedStep 1 Owners and AI council: Data protection, not addressed02 Shadow AI and inventoryStep 2 Shadow AI and inventory: Governance, risk and compliance, primaryStep 2 Shadow AI and inventory: Secure AI operations, primaryStep 2 Shadow AI and inventory: Model protection, not addressedStep 2 Shadow AI and inventory: Secure development lifecycle, not addressedStep 2 Shadow AI and inventory: Infrastructure security, supportingStep 2 Shadow AI and inventory: Identity security, not addressedStep 2 Shadow AI and inventory: Data protection, supporting03 COMPASS baselineStep 3 COMPASS baseline: Governance, risk and compliance, primaryStep 3 COMPASS baseline: Secure AI operations, supportingStep 3 COMPASS baseline: Model protection, supportingStep 3 COMPASS baseline: Secure development lifecycle, supportingStep 3 COMPASS baseline: Infrastructure security, supportingStep 3 COMPASS baseline: Identity security, supportingStep 3 COMPASS baseline: Data protection, supporting04 Data classification for AIStep 4 Data classification for AI: Governance, risk and compliance, supportingStep 4 Data classification for AI: Secure AI operations, not addressedStep 4 Data classification for AI: Model protection, not addressedStep 4 Data classification for AI: Secure development lifecycle, not addressedStep 4 Data classification for AI: Infrastructure security, not addressedStep 4 Data classification for AI: Identity security, supportingStep 4 Data classification for AI: Data protection, primary05 Risk tiers and approval gatesStep 5 Risk tiers and approval gates: Governance, risk and compliance, primaryStep 5 Risk tiers and approval gates: Secure AI operations, not addressedStep 5 Risk tiers and approval gates: Model protection, not addressedStep 5 Risk tiers and approval gates: Secure development lifecycle, not addressedStep 5 Risk tiers and approval gates: Infrastructure security, not addressedStep 5 Risk tiers and approval gates: Identity security, not addressedStep 5 Risk tiers and approval gates: Data protection, supporting06 Control library and roadmapStep 6 Control library and roadmap: Governance, risk and compliance, primaryStep 6 Control library and roadmap: Secure AI operations, supportingStep 6 Control library and roadmap: Model protection, supportingStep 6 Control library and roadmap: Secure development lifecycle, not addressedStep 6 Control library and roadmap: Infrastructure security, not addressedStep 6 Control library and roadmap: Identity security, not addressedStep 6 Control library and roadmap: Data protection, not addressed07 Agent identityStep 7 Agent identity: Governance, risk and compliance, not addressedStep 7 Agent identity: Secure AI operations, not addressedStep 7 Agent identity: Model protection, supportingStep 7 Agent identity: Secure development lifecycle, not addressedStep 7 Agent identity: Infrastructure security, supportingStep 7 Agent identity: Identity security, primaryStep 7 Agent identity: Data protection, not addressed08 AI gateway and guardrailsStep 8 AI gateway and guardrails: Governance, risk and compliance, not addressedStep 8 AI gateway and guardrails: Secure AI operations, primaryStep 8 AI gateway and guardrails: Model protection, primaryStep 8 AI gateway and guardrails: Secure development lifecycle, not addressedStep 8 AI gateway and guardrails: Infrastructure security, supportingStep 8 AI gateway and guardrails: Identity security, not addressedStep 8 AI gateway and guardrails: Data protection, supporting09 Model supply chainStep 9 Model supply chain: Governance, risk and compliance, not addressedStep 9 Model supply chain: Secure AI operations, not addressedStep 9 Model supply chain: Model protection, primaryStep 9 Model supply chain: Secure development lifecycle, primaryStep 9 Model supply chain: Infrastructure security, supportingStep 9 Model supply chain: Identity security, not addressedStep 9 Model supply chain: Data protection, not addressed10 Threat models and release gatesStep 10 Threat models and release gates: Governance, risk and compliance, not addressedStep 10 Threat models and release gates: Secure AI operations, not addressedStep 10 Threat models and release gates: Model protection, supportingStep 10 Threat models and release gates: Secure development lifecycle, primaryStep 10 Threat models and release gates: Infrastructure security, not addressedStep 10 Threat models and release gates: Identity security, not addressedStep 10 Threat models and release gates: Data protection, not addressed11 AI infrastructure hardeningStep 11 AI infrastructure hardening: Governance, risk and compliance, not addressedStep 11 AI infrastructure hardening: Secure AI operations, not addressedStep 11 AI infrastructure hardening: Model protection, not addressedStep 11 AI infrastructure hardening: Secure development lifecycle, not addressedStep 11 AI infrastructure hardening: Infrastructure security, primaryStep 11 AI infrastructure hardening: Identity security, supportingStep 11 AI infrastructure hardening: Data protection, supporting12 SOC telemetry for AIStep 12 SOC telemetry for AI: Governance, risk and compliance, not addressedStep 12 SOC telemetry for AI: Secure AI operations, primaryStep 12 SOC telemetry for AI: Model protection, supportingStep 12 SOC telemetry for AI: Secure development lifecycle, not addressedStep 12 SOC telemetry for AI: Infrastructure security, not addressedStep 12 SOC telemetry for AI: Identity security, supportingStep 12 SOC telemetry for AI: Data protection, not addressed13 Continuous red teamingStep 13 Continuous red teaming: Governance, risk and compliance, not addressedStep 13 Continuous red teaming: Secure AI operations, supportingStep 13 Continuous red teaming: Model protection, primaryStep 13 Continuous red teaming: Secure development lifecycle, supportingStep 13 Continuous red teaming: Infrastructure security, not addressedStep 13 Continuous red teaming: Identity security, not addressedStep 13 Continuous red teaming: Data protection, not addressed14 AI incident responseStep 14 AI incident response: Governance, risk and compliance, supportingStep 14 AI incident response: Secure AI operations, primaryStep 14 AI incident response: Model protection, not addressedStep 14 AI incident response: Secure development lifecycle, not addressedStep 14 AI incident response: Infrastructure security, not addressedStep 14 AI incident response: Identity security, not addressedStep 14 AI incident response: Data protection, supporting15 Compliance automationStep 15 Compliance automation: Governance, risk and compliance, primaryStep 15 Compliance automation: Secure AI operations, supportingStep 15 Compliance automation: Model protection, not addressedStep 15 Compliance automation: Secure development lifecycle, not addressedStep 15 Compliance automation: Infrastructure security, not addressedStep 15 Compliance automation: Identity security, not addressedStep 15 Compliance automation: Data protection, not addressed16 Secure AI platformStep 16 Secure AI platform: Governance, risk and compliance, supportingStep 16 Secure AI platform: Secure AI operations, supportingStep 16 Secure AI platform: Model protection, supportingStep 16 Secure AI platform: Secure development lifecycle, primaryStep 16 Secure AI platform: Infrastructure security, supportingStep 16 Secure AI platform: Identity security, primaryStep 16 Secure AI platform: Data protection, supporting17 Post-quantum and next waveStep 17 Post-quantum and next wave: Governance, risk and compliance, supportingStep 17 Post-quantum and next wave: Secure AI operations, not addressedStep 17 Post-quantum and next wave: Model protection, not addressedStep 17 Post-quantum and next wave: Secure development lifecycle, not addressedStep 17 Post-quantum and next wave: Infrastructure security, primaryStep 17 Post-quantum and next wave: Identity security, not addressedStep 17 Post-quantum and next wave: Data protection, supportingSteps where the domain is primary6433221

Workstreams across 36 months

Thick bar: build. Thin bar: run and improve. Background bands mark the five stages.

12345StageGovernance and riskGovernance and risk: build, months 0 to 3Governance and risk: run and improve, months 3 to 36Visibility and inventoryVisibility and inventory: build, months 0 to 3Visibility and inventory: run and improve, months 3 to 36Data protection for AIData protection for AI: build, months 1 to 6Data protection for AI: run and improve, months 6 to 36Agent identityAgent identity: build, months 3 to 9Agent identity: run and improve, months 9 to 36Gateway and guardrailsGateway and guardrails: build, months 3 to 9Gateway and guardrails: run and improve, months 9 to 36Supply chain and SDLCSupply chain and SDLC: build, months 3 to 12Supply chain and SDLC: run and improve, months 12 to 36SOC and incident responseSOC and incident response: build, months 6 to 18SOC and incident response: run and improve, months 18 to 36Continuous red teamingContinuous red teaming: build, months 6 to 36Compliance automationCompliance automation: build, months 12 to 36Platform and post-quantumPlatform and post-quantum: build, months 18 to 3603612182436Months from program start

Timing assumes a large enterprise with an executive sponsor in place; adjust to the client's baseline.

Stage exit gates

  1. 1Discover, days 0 to 30. Named owners, interim AI policy, AI inventory v1 and an COMPASS baseline.
  2. 2Assess and plan, days 30 to 90. AI data classified, risk tiers live, one control library and a funded roadmap.
  3. 3Design and protect, days 90 to 180. Agents have identities, a gateway is in the path, supply chain and release gates enforced.
  4. 4Operate and monitor, months 6 to 18. SOC coverage for every AI system, continuous red teaming and tested playbooks.
  5. 5Optimize and scale, months 18 to 36. Continuous compliance, a paved road for agents and a post-quantum roadmap.
Regulatory mile markers

The dates on the road

Build the control library once and map it to every framework. The EU Digital Omnibus on AI moved high-risk obligations to December 2027 and August 2028; transparency duties still apply from August 2026. NIST's post-quantum transition plan remains an initial public draft.

2 Feb 2025
EU AI Act

Prohibited AI practices and AI literacy duties apply

2 Aug 2025
EU AI Act

General-purpose AI model obligations apply

Dec 2025
OWASP

Top 10 for agentic applications published

2 Aug 2026
EU AI Act

Article 50 transparency obligations apply

In effect now
2 Dec 2027
EU AI Act

Annex III high-risk obligations apply after the Digital Omnibus deferral

2 Aug 2028
EU AI Act

Annex I high-risk obligations for AI in regulated products

After 2030
NIST IR 8547 (draft)

Quantum-vulnerable algorithms deprecated

After 2035
NIST IR 8547 (draft)

Quantum-vulnerable algorithms disallowed

Destination

An AI-enabled business

Controlled autonomy: more AI throughput with a smaller blast radius.

3 to 5 days

per agent with ad hoc security: manual identity tickets, approvals and no policy-as-code

versus
About 30 min

from idea to a governed production agent on an COMPASS-aligned platform

Black Bay COMPASS Day 2 example: developer sets up an agent with identity, scope, CI/CD scanning, gateway and observability.

Examiner-ready from day one

Every agent is born with an identity, access controls and a full audit trail.

Developer velocity without friction

Self-service provisioning replaces ticket queues and approvals that take weeks.

Shadow AI designed out

When the secure path is the fast path, teams stop routing around it.

Model risk managed at scale

Gateways, guardrails and prompt-level observability scale from 5 agents to 500.

“Organizations need security that can keep up with the speed, complexity and sensitivity of modern AI pipelines.”
Arik Roztal, Global Head of AI Cybersecurity Business Development, NVIDIA
Travel with a guide

How Black Bay helps along the way

Black Bay combines consulting-grade strategy with the engineering depth to design, validate and deliver each stage, so the roadmap turns into working controls.

Advisory

AI Security Assessment, COMPASS maturity scoring and the AI Governance Workshop to start stages 1 and 2.

Architecture review

Gateways, guardrails and vendor combinations reviewed against your deployment architecture before production.

deepcurrent GRC

Findings become owned remediation tasks with live dashboards, so progress is tracked between assessments across every COMPASS domain.

Tabletop exercises

Facilitated tabletop exercises against AI-augmented adversaries to rehearse stage 4 playbooks.