From first prompt to AI-enabled business, with the data, milestones and measures to prove progress
An expedition guide for organizations starting an AI security program. Five stages and seventeen steps, organized by the seven COMPASS domains, the 18 AI security functions and the 10 questions every leader must answer.
Next stopFind shadow AI.
97%
of organizations with an AI breach lacked AI access controls
IBM, 2025
63%
of breached organizations had no AI governance policy, or were still writing one
IBM, 2025
31%
of breaches now start with vulnerability exploitation, the top initial access vector
Verizon DBIR, 2026
40%+
of agentic AI projects will be canceled by end of 2027, Gartner predicts
Gartner, June 2025
Seven COMPASS domains in orbit around the AI estate they protect
Why the journey starts now
AI adoption is outrunning AI security
The first year of breach data on AI shows the same pattern everywhere: adoption first, governance and access control later. The gap is where attackers are already working, and where the cost shows up.
The AI oversight gap
Share of organizations studied, IBM Cost of a Data Breach 2025 (600 breached organizations, March 2024 to February 2025)
$670K
higher breach costs where shadow AI use was high
IBM, 2025
$1.9M
average savings with extensive AI and automation in security operations
IBM, 2025
$4.44M
global average cost of a data breach
IBM, 2025
“As AI becomes more deeply embedded across business operations, AI security must be treated as foundational.”
Suja Viswesan, Vice President, Security and Runtime Products, IBMIBM press release, July 30, 2025
The window is closing. Vulnerability exploitation is now the top initial access vector at 31% of breaches (Verizon DBIR 2026), and Gartner expects over 40% of agentic AI projects to be canceled by the end of 2027, in part for inadequate risk controls.
Your navigation kit
Three lenses, one map
Every stop on the road is tagged with the COMPASS domains it builds, the AI security functions it puts to work and the leadership questions it answers. Hover any domain, function or question in the interactive version to light up its steps.
COMPASS: seven domains
Black Bay's seven-domain AI security model, aligned to NIST AI RMF and adapted from Black Bay's COMPASS framework. Plan to implement, design to operate.
Governance, risk and compliancePolicy, ownership, risk tiers, regulatory mapping and audit evidence.
Secure AI operationsLogging, detection, response and recovery for AI in production.
Model protectionModel gateway, guardrails, scanning, AI-BOM and red teaming.
Secure development lifecycleThreat modeling, secure code, CI/CD gates and model validation.
Infrastructure securityGPU fabric, network, cloud, DPU, zero trust and post-quantum.
Identity securityHuman and non-human identity, agent credentials, least privilege.
Data protectionDiscovery, classification, DLP, lineage, encryption and backup.
The 10 questions every leader must answer
The top ten client concerns raised in AI security briefings, grouped into four control areas. A program is ready to scale when it can answer all ten with evidence.
Govern and inventory
Q1Who owns AI risk, and what must be approved before a use case scales?
Q2Do we have a living inventory of every model, agent, vendor, prompt, dataset, RAG source and API?
Protect data and access
Q3Can sensitive data reach prompts, retrieval, logs or outputs without a control in the path?
Q7Which agent actions require least privilege, human approval and a kill switch?
Secure models and agents
Q4Can we prove the provenance, integrity and license of every model, dataset and plug-in?
Q5How do we stop untrusted content from steering our models and tools?
Q6Do we test for jailbreaks, extraction, poisoning and unsafe output before and after release?
Operate and recover
Q8Are GPUs, registries, pipelines and the management plane hardened like production?
Q9Will the SOC see drift, abuse, leakage and tool misuse in production?
Q10Can we contain, roll back and investigate an AI incident within hours?
The 18 AI security functions
Capability areas beneath the seven domains, mapped from the Black Bay AI Security Vendor Catalog v2.0. The color shows each function's primary domain.
F01AI security posture management (AI-SPM)
F02AI governance, risk and compliance
F03Runtime guardrails and LLM firewall
F04Agentic AI, MCP security and agent identity
F05AI usage monitoring, shadow AI and GenAI DLP
F06Data security for AI (DSPM, privacy, lineage)
F07Model supply chain, scanning and AI-BOM
F08Secure development (SAST, SCA, secrets, AI code)
F09API security and AI gateway
F10AI-driven security operations (SOC, XDR, SIEM)
F11Cloud and Kubernetes security for AI
F12Identity, access and non-human identity (IAM, NHI, PAM)
F13AI infrastructure, GPU, confidential computing and agent isolation
F14Deepfake defense, content authenticity and AI fraud
F15AI red teaming, validation and adversarial ML
F16Endpoint, email, OT/IoT and specialty AI security
F17Cyber risk quantification, TPRM and exposure management
F18Post-quantum cryptography and crypto agility
Functions by domain
Primary domain for each function; a working view aligned to COMPASS topics.
Governance, risk and compliance: 3 functions3Secure AI operations: 2 functions2Model protection: 5 functions5Secure development lifecycle: 1 functions1Infrastructure security: 4 functions4Identity security: 2 functions2Data protection: 1 functions118functions
Each stage has a timeframe, a target maturity level, exit criteria and the threats you will meet along the way. Each stop shows the three actions that matter most, how to measure progress and who owns the work.
Starting point
Start here
AI is already inside the enterprise
Today
Level1Unaware
Employees use GenAI in browsers, SaaS and developer tools
Copilots and agents are in pilots without clear owners
Security controls are inherited from traditional IT
Stage 1 of 5
Discover
See everything
1
Level2Unaware to initiating
Days 0 to 30Maturity level 1 to 2: unaware to initiating
Exit criteria: Named owners, interim AI policy, AI inventory v1 and an COMPASS baseline.
Shadow AI and unsanctioned copilotsLLM02 Sensitive information disclosure
01
Stage 1: Discover
Name the owners and charter the AI council
Put accountable leaders and decision rights in place before AI scales further.
Name an executive sponsor and one accountable AI risk owner
Charter a cross-functional council with approval authority
Publish an interim AI acceptable use policy within 30 days
Measure: Share of AI use cases with named business, system and data owners (target 100%)
Owner: CISO with the Chief AI or Data Officer
Hover or tap for how-to, actions and owners
02
Stage 1: Discover
Find shadow AI and build a living inventory
You cannot secure what you cannot see. Discover every model, agent, copilot and MCP server in use.
Turn on GenAI discovery in the SSE, CASB and EDR you already own
Scan cloud accounts with AI security posture management
Give every AI asset an owner or a removal date
Measure: Share of AI assets with an owner; unsanctioned AI apps trending down
Owner: AI security lead
Hover or tap for how-to, actions and owners
03
Stage 1: Discover
Baseline COMPASS maturity and map your tools
Score all seven COMPASS domains, map installed tools to them, and quantify the top risks.
Score each domain on the five-level maturity scale
Map every installed tool as primary or overlap coverage
Quantify the top five AI loss scenarios in dollars
Measure: Maturity score per COMPASS domain, baseline and 18-month target
Owner: CISO
Hover or tap for how-to, actions and owners
“COMPASS gives us a common language and structured approach for managing AI risk.”
CIO, Large Global Financial Company
Stage 2 of 5
Assess and plan
Know what matters
2
Level2Initiating
Days 30 to 90Maturity level 2: initiating
Exit criteria: AI data classified, risk tiers live, one control library and a funded roadmap.
LLM08 Vector and embedding weaknessesOver-broad RAG permissions
04
Stage 2: Assess and plan
Classify data and fence what AI can reach
Most early AI incidents are data incidents. Control what flows into prompts, retrieval, logs and outputs.
Discover and label sensitive data before AI can reach it
Fix over-shared sources feeding copilots and RAG
Enforce GenAI DLP on prompts, uploads and outputs
Measure: Share of RAG and copilot sources permission-reviewed; GenAI DLP events per week
Owner: Data owners with data security
Hover or tap for how-to, actions and owners
05
Stage 2: Assess and plan
Risk-tier every use case and set approval gates
Make the approved path faster than the shadow path, with controls proportional to risk.
Launch one AI intake form and use case registry
Define four risk tiers with required controls for each
Publish approved patterns so low-risk use cases self-approve
Measure: Median approval time by risk tier
Owner: AI governance council
Hover or tap for how-to, actions and owners
06
Stage 2: Assess and plan
Build one control library and the roadmap
Map controls once to NIST AI RMF, ISO/IEC 42001, the EU AI Act, OWASP and MITRE ATLAS.
Use NIST AI RMF as the spine and crosswalk the rest
Assign an owner and evidence source to every control
Approve a phased 36-month roadmap and business case
Measure: Share of controls with an owner and an automated evidence source
Owner: GRC and compliance
Hover or tap for how-to, actions and owners
Stage 3 of 5
Design and protect
Build the guardrails
3
Level3Defined
Days 90 to 180Maturity level 3: defined
Exit criteria: Agents have identities, a gateway is in the path, supply chain and release gates enforced.
LLM01 Prompt injectionASI03 Identity and privilege abuseLLM03 Supply chain
07
Stage 3: Design and protect
Give every agent an identity and least privilege
When AI can act, identity becomes the control point. Treat every agent as a governed non-human identity.
Register each agent as a distinct identity with an owner
Replace static keys with short-lived, scoped tokens
Require human approval for high-risk actions, with a kill switch
Measure: Share of agents with scoped, short-lived credentials; standing privileges removed
Owner: Identity and access team
Hover or tap for how-to, actions and owners
08
Stage 3: Design and protect
Put an AI gateway and guardrails in the path
Inspect prompts, outputs and tool calls inline, on paths applications cannot bypass.
Route model traffic through egress and ingress AI gateways
Govern the tool-call plane with an MCP and agent gateway
Enforce the path in the network and log with correlation IDs
Measure: Share of model and tool traffic through a gateway; bypass attempts detected
Owner: Security architecture with the platform team
Hover or tap for how-to, actions and owners
09
Stage 3: Design and protect
Secure the model and AI supply chain
Treat models, datasets, embeddings, plug-ins and MCP servers as supply chain dependencies.
Stand up an approved model registry and block direct pulls
Scan, sign and verify every model and dataset
Pin dependencies and publish an AI-BOM per system
Measure: Share of production models with verified provenance and signature
Owner: AI and ML platform team
Hover or tap for how-to, actions and owners
10
Stage 3: Design and protect
Shift left: threat model and gate every release
Traditional AppSec misses AI-specific attacks. Test for them before anything reaches production.
Threat model with STRIDE and MITRE ATLAS
Scan code, secrets and AI-generated code on every pull request
Gate releases on jailbreak, injection and leakage tests
Measure: Share of AI releases passing automated evaluation gates
Owner: Application security and product engineering
Hover or tap for how-to, actions and owners
11
Stage 3: Design and protect
Harden AI infrastructure and isolate agents
Protect GPU clusters, registries and pipelines like the production systems they are.
Segment training, inference and data tiers
Lock down the GPU management plane, BMC and firmware
Run agent code execution in sandboxes or micro-VMs
Measure: Critical misconfigurations on AI infrastructure; share of agent execution sandboxed
Owner: Infrastructure and network teams
Hover or tap for how-to, actions and owners
“Identity is the weakest seam in enterprise AI deployment.”
Todd NeilsonPrincipal AI-Security Advisor, Black BayBlack Bay AI Security practice thesis, 2026
Stage 4 of 5
Operate and monitor
Run it like production
4
Level4Managed
Months 6 to 18Maturity level 4: managed
Exit criteria: SOC coverage for every AI system, continuous red teaming and tested playbooks.
ASI10 Rogue agentsLLM04 Data and model poisoningASI06 Memory and context poisoning
12
Stage 4: Operate and monitor
Wire AI telemetry into the SOC
AI risk changes after deployment. Give the SOC the signals and playbooks to see it.
Stream gateway, guardrail and agent logs into the SIEM
Detect injection, extraction, leakage and anomalous tool use
Baseline agent behavior as non-human identities
Measure: Share of AI systems with SOC coverage; mean time to detect AI incidents
Owner: Security operations
Hover or tap for how-to, actions and owners
13
Stage 4: Operate and monitor
Red team continuously
Every model swap, prompt change or new tool resets your assurance. Keep testing.
Automate adversarial testing against production models and agents
Test agentic risks: goal hijack, tool misuse, memory poisoning
Feed findings into guardrails and release gates
Measure: Open critical AI findings and mean time to close
Owner: Offensive security (AI red team)
Hover or tap for how-to, actions and owners
14
Stage 4: Operate and monitor
Rehearse AI incident response and rollback
Build and practice playbooks for leakage, poisoning, agent misexecution and deepfake fraud.
Predefine containment: revoke, disable, quarantine, roll back
Preserve prompts, outputs, retrieval traces and tool logs
Run tabletops with security, legal, privacy and communications
Measure: Time to contain in tabletop; share of AI scenarios with a tested playbook
Owner: Incident response lead
Hover or tap for how-to, actions and owners
“Plan to implement, design to operate.”
Black Bay COMPASSAI Readiness Model for Operational ResilienceBlack Bay COMPASS framework
Stage 5 of 5
Optimize and scale
Make secure the fast path
5
Level5Optimized
Months 18 to 36Maturity level 5: optimized
Exit criteria: Continuous compliance, a paved road for agents and a post-quantum roadmap.
ASI09 Human-agent trust exploitationHarvest now, decrypt later
15
Stage 5: Optimize and scale
Automate compliance and report risk in dollars
Move from point-in-time audits to continuous evidence and board reporting in business terms.
Automate evidence from gateways, pipelines and identity systems
Report AI risk to the board in dollars and trends
Add AI clauses to third-party contracts
Measure: Audit preparation time; share of controls continuously monitored
Owner: GRC and enterprise risk
Hover or tap for how-to, actions and owners
16
Stage 5: Optimize and scale
Pave the road with a secure AI platform
Make the secure path the fast path: self-service agents with identity, policy and observability built in.
Publish golden paths for copilots, RAG apps and agents
Issue identity and policy-as-code at registration
Measure idea-to-production time for governed agents
Measure: Time from idea to governed production agent
Owner: Platform engineering
Hover or tap for how-to, actions and owners
17
Stage 5: Optimize and scale
Future-proof for post-quantum and the next wave
Build crypto agility and extend COMPASS to physical AI, OT and whatever comes next.
Inventory cryptography protecting weights, data and agent channels
Plan migration to NIST FIPS 203, 204 and 205
Re-baseline COMPASS maturity every year
Measure: Share of cryptographic assets inventoried; migration milestones met
Owner: Security architecture (cryptography and OT)
Hover or tap for how-to, actions and owners
Arrival checkpoint
Ten questions, answered with evidence
Maturity level 5: optimized
Arrive
Level5Optimized
Every AI use case, model and agent is owned, inventoried, protected, monitored and recoverable, and leadership can answer each question below with evidence.
Q1Q2Q3Q4Q5Q6Q7Q8Q9Q10
Measure the climb
Maturity you can show the board
Track progress on the Black Bay five-level AI security maturity model. Programs that follow a framework keep climbing; programs built from point tools tend to stall at level 2, where coverage is fragmented and enforcement uneven.
Maturity trajectory over 36 months
Illustrative target path by stage, compared with an ad hoc program
12345Stage1 Unaware2 Initiating3 Defined4 Managed5 Optimized03612182436Months from program startMonth 0: level 1.3Month 1: level 1.8Month 3: level 2.4Month 6: level 3.1Month 12: level 3.6Month 18: level 4.0Month 24: level 4.4Month 36: level 4.8COMPASS-guided programAd hoc controlsplateau at level 2
COMPASS-guided programAd hoc controlsStage bands 1 to 5
Illustrative. Replace with the client's COMPASS assessment scores at each stage exit.
Baseline versus 18-month target
Maturity by COMPASS domain, scale 1 to 5
12345● GRC● Secure AI ops● Model protection● SDLC● Infrastructure● Identity● Data protectionGovernance, risk and compliance: target 4Governance, risk and compliance: baseline 2Secure AI operations: target 4Secure AI operations: baseline 2Model protection: target 3.5Model protection: baseline 1Secure development lifecycle: target 4Secure development lifecycle: baseline 2Infrastructure security: target 4Infrastructure security: baseline 3Identity security: target 4Identity security: baseline 2Data protection: target 4Data protection: baseline 2
Typical starting baselineTarget at month 18
Illustrative example of a common starting profile. Score the client in step 03.
Coverage and cadence
Every domain, on a timeline
No single step or product covers COMPASS end to end. The heat map shows where each step builds a domain as the primary owner or as support; the timeline shows how the workstreams overlap from build to run.
COMPASS coverage by step
Solid cell: primary domain. Faded cell: supporting domain. Click a cell in the interactive version to open that step.
● GRC● Secure AI ops● Model protection● SDLC● Infrastructure● Identity● Data protection01 Owners and AI councilStep 1 Owners and AI council: Governance, risk and compliance, primaryStep 1 Owners and AI council: Secure AI operations, not addressedStep 1 Owners and AI council: Model protection, not addressedStep 1 Owners and AI council: Secure development lifecycle, not addressedStep 1 Owners and AI council: Infrastructure security, not addressedStep 1 Owners and AI council: Identity security, not addressedStep 1 Owners and AI council: Data protection, not addressed02 Shadow AI and inventoryStep 2 Shadow AI and inventory: Governance, risk and compliance, primaryStep 2 Shadow AI and inventory: Secure AI operations, primaryStep 2 Shadow AI and inventory: Model protection, not addressedStep 2 Shadow AI and inventory: Secure development lifecycle, not addressedStep 2 Shadow AI and inventory: Infrastructure security, supportingStep 2 Shadow AI and inventory: Identity security, not addressedStep 2 Shadow AI and inventory: Data protection, supporting03 COMPASS baselineStep 3 COMPASS baseline: Governance, risk and compliance, primaryStep 3 COMPASS baseline: Secure AI operations, supportingStep 3 COMPASS baseline: Model protection, supportingStep 3 COMPASS baseline: Secure development lifecycle, supportingStep 3 COMPASS baseline: Infrastructure security, supportingStep 3 COMPASS baseline: Identity security, supportingStep 3 COMPASS baseline: Data protection, supporting04 Data classification for AIStep 4 Data classification for AI: Governance, risk and compliance, supportingStep 4 Data classification for AI: Secure AI operations, not addressedStep 4 Data classification for AI: Model protection, not addressedStep 4 Data classification for AI: Secure development lifecycle, not addressedStep 4 Data classification for AI: Infrastructure security, not addressedStep 4 Data classification for AI: Identity security, supportingStep 4 Data classification for AI: Data protection, primary05 Risk tiers and approval gatesStep 5 Risk tiers and approval gates: Governance, risk and compliance, primaryStep 5 Risk tiers and approval gates: Secure AI operations, not addressedStep 5 Risk tiers and approval gates: Model protection, not addressedStep 5 Risk tiers and approval gates: Secure development lifecycle, not addressedStep 5 Risk tiers and approval gates: Infrastructure security, not addressedStep 5 Risk tiers and approval gates: Identity security, not addressedStep 5 Risk tiers and approval gates: Data protection, supporting06 Control library and roadmapStep 6 Control library and roadmap: Governance, risk and compliance, primaryStep 6 Control library and roadmap: Secure AI operations, supportingStep 6 Control library and roadmap: Model protection, supportingStep 6 Control library and roadmap: Secure development lifecycle, not addressedStep 6 Control library and roadmap: Infrastructure security, not addressedStep 6 Control library and roadmap: Identity security, not addressedStep 6 Control library and roadmap: Data protection, not addressed07 Agent identityStep 7 Agent identity: Governance, risk and compliance, not addressedStep 7 Agent identity: Secure AI operations, not addressedStep 7 Agent identity: Model protection, supportingStep 7 Agent identity: Secure development lifecycle, not addressedStep 7 Agent identity: Infrastructure security, supportingStep 7 Agent identity: Identity security, primaryStep 7 Agent identity: Data protection, not addressed08 AI gateway and guardrailsStep 8 AI gateway and guardrails: Governance, risk and compliance, not addressedStep 8 AI gateway and guardrails: Secure AI operations, primaryStep 8 AI gateway and guardrails: Model protection, primaryStep 8 AI gateway and guardrails: Secure development lifecycle, not addressedStep 8 AI gateway and guardrails: Infrastructure security, supportingStep 8 AI gateway and guardrails: Identity security, not addressedStep 8 AI gateway and guardrails: Data protection, supporting09 Model supply chainStep 9 Model supply chain: Governance, risk and compliance, not addressedStep 9 Model supply chain: Secure AI operations, not addressedStep 9 Model supply chain: Model protection, primaryStep 9 Model supply chain: Secure development lifecycle, primaryStep 9 Model supply chain: Infrastructure security, supportingStep 9 Model supply chain: Identity security, not addressedStep 9 Model supply chain: Data protection, not addressed10 Threat models and release gatesStep 10 Threat models and release gates: Governance, risk and compliance, not addressedStep 10 Threat models and release gates: Secure AI operations, not addressedStep 10 Threat models and release gates: Model protection, supportingStep 10 Threat models and release gates: Secure development lifecycle, primaryStep 10 Threat models and release gates: Infrastructure security, not addressedStep 10 Threat models and release gates: Identity security, not addressedStep 10 Threat models and release gates: Data protection, not addressed11 AI infrastructure hardeningStep 11 AI infrastructure hardening: Governance, risk and compliance, not addressedStep 11 AI infrastructure hardening: Secure AI operations, not addressedStep 11 AI infrastructure hardening: Model protection, not addressedStep 11 AI infrastructure hardening: Secure development lifecycle, not addressedStep 11 AI infrastructure hardening: Infrastructure security, primaryStep 11 AI infrastructure hardening: Identity security, supportingStep 11 AI infrastructure hardening: Data protection, supporting12 SOC telemetry for AIStep 12 SOC telemetry for AI: Governance, risk and compliance, not addressedStep 12 SOC telemetry for AI: Secure AI operations, primaryStep 12 SOC telemetry for AI: Model protection, supportingStep 12 SOC telemetry for AI: Secure development lifecycle, not addressedStep 12 SOC telemetry for AI: Infrastructure security, not addressedStep 12 SOC telemetry for AI: Identity security, supportingStep 12 SOC telemetry for AI: Data protection, not addressed13 Continuous red teamingStep 13 Continuous red teaming: Governance, risk and compliance, not addressedStep 13 Continuous red teaming: Secure AI operations, supportingStep 13 Continuous red teaming: Model protection, primaryStep 13 Continuous red teaming: Secure development lifecycle, supportingStep 13 Continuous red teaming: Infrastructure security, not addressedStep 13 Continuous red teaming: Identity security, not addressedStep 13 Continuous red teaming: Data protection, not addressed14 AI incident responseStep 14 AI incident response: Governance, risk and compliance, supportingStep 14 AI incident response: Secure AI operations, primaryStep 14 AI incident response: Model protection, not addressedStep 14 AI incident response: Secure development lifecycle, not addressedStep 14 AI incident response: Infrastructure security, not addressedStep 14 AI incident response: Identity security, not addressedStep 14 AI incident response: Data protection, supporting15 Compliance automationStep 15 Compliance automation: Governance, risk and compliance, primaryStep 15 Compliance automation: Secure AI operations, supportingStep 15 Compliance automation: Model protection, not addressedStep 15 Compliance automation: Secure development lifecycle, not addressedStep 15 Compliance automation: Infrastructure security, not addressedStep 15 Compliance automation: Identity security, not addressedStep 15 Compliance automation: Data protection, not addressed16 Secure AI platformStep 16 Secure AI platform: Governance, risk and compliance, supportingStep 16 Secure AI platform: Secure AI operations, supportingStep 16 Secure AI platform: Model protection, supportingStep 16 Secure AI platform: Secure development lifecycle, primaryStep 16 Secure AI platform: Infrastructure security, supportingStep 16 Secure AI platform: Identity security, primaryStep 16 Secure AI platform: Data protection, supporting17 Post-quantum and next waveStep 17 Post-quantum and next wave: Governance, risk and compliance, supportingStep 17 Post-quantum and next wave: Secure AI operations, not addressedStep 17 Post-quantum and next wave: Model protection, not addressedStep 17 Post-quantum and next wave: Secure development lifecycle, not addressedStep 17 Post-quantum and next wave: Infrastructure security, primaryStep 17 Post-quantum and next wave: Identity security, not addressedStep 17 Post-quantum and next wave: Data protection, supportingSteps where the domain is primary6433221
Workstreams across 36 months
Thick bar: build. Thin bar: run and improve. Background bands mark the five stages.
12345StageGovernance and riskGovernance and risk: build, months 0 to 3Governance and risk: run and improve, months 3 to 36Visibility and inventoryVisibility and inventory: build, months 0 to 3Visibility and inventory: run and improve, months 3 to 36Data protection for AIData protection for AI: build, months 1 to 6Data protection for AI: run and improve, months 6 to 36Agent identityAgent identity: build, months 3 to 9Agent identity: run and improve, months 9 to 36Gateway and guardrailsGateway and guardrails: build, months 3 to 9Gateway and guardrails: run and improve, months 9 to 36Supply chain and SDLCSupply chain and SDLC: build, months 3 to 12Supply chain and SDLC: run and improve, months 12 to 36SOC and incident responseSOC and incident response: build, months 6 to 18SOC and incident response: run and improve, months 18 to 36Continuous red teamingContinuous red teaming: build, months 6 to 36Compliance automationCompliance automation: build, months 12 to 36Platform and post-quantumPlatform and post-quantum: build, months 18 to 3603612182436Months from program start
Timing assumes a large enterprise with an executive sponsor in place; adjust to the client's baseline.
Stage exit gates
1Discover, days 0 to 30. Named owners, interim AI policy, AI inventory v1 and an COMPASS baseline.
2Assess and plan, days 30 to 90. AI data classified, risk tiers live, one control library and a funded roadmap.
3Design and protect, days 90 to 180. Agents have identities, a gateway is in the path, supply chain and release gates enforced.
4Operate and monitor, months 6 to 18. SOC coverage for every AI system, continuous red teaming and tested playbooks.
5Optimize and scale, months 18 to 36. Continuous compliance, a paved road for agents and a post-quantum roadmap.
Regulatory mile markers
The dates on the road
Build the control library once and map it to every framework. The EU Digital Omnibus on AI moved high-risk obligations to December 2027 and August 2028; transparency duties still apply from August 2026. NIST's post-quantum transition plan remains an initial public draft.
2 Feb 2025
EU AI Act
Prohibited AI practices and AI literacy duties apply
2 Aug 2025
EU AI Act
General-purpose AI model obligations apply
Dec 2025
OWASP
Top 10 for agentic applications published
2 Aug 2026
EU AI Act
Article 50 transparency obligations apply
In effect now
2 Dec 2027
EU AI Act
Annex III high-risk obligations apply after the Digital Omnibus deferral
2 Aug 2028
EU AI Act
Annex I high-risk obligations for AI in regulated products
After 2030
NIST IR 8547 (draft)
Quantum-vulnerable algorithms deprecated
After 2035
NIST IR 8547 (draft)
Quantum-vulnerable algorithms disallowed
Destination
An AI-enabled business
Controlled autonomy: more AI throughput with a smaller blast radius.
3 to 5 days
per agent with ad hoc security: manual identity tickets, approvals and no policy-as-code
versus
About 30 min
from idea to a governed production agent on an COMPASS-aligned platform
Black Bay COMPASS Day 2 example: developer sets up an agent with identity, scope, CI/CD scanning, gateway and observability.
Examiner-ready from day one
Every agent is born with an identity, access controls and a full audit trail.
Developer velocity without friction
Self-service provisioning replaces ticket queues and approvals that take weeks.
Shadow AI designed out
When the secure path is the fast path, teams stop routing around it.
Model risk managed at scale
Gateways, guardrails and prompt-level observability scale from 5 agents to 500.
“Organizations need security that can keep up with the speed, complexity and sensitivity of modern AI pipelines.”
Arik Roztal, Global Head of AI Cybersecurity Business Development, NVIDIA
Travel with a guide
How Black Bay helps along the way
Black Bay combines consulting-grade strategy with the engineering depth to design, validate and deliver each stage, so the roadmap turns into working controls.
Advisory
AI Security Assessment, COMPASS maturity scoring and the AI Governance Workshop to start stages 1 and 2.
Architecture review
Gateways, guardrails and vendor combinations reviewed against your deployment architecture before production.
deepcurrent GRC
Findings become owned remediation tasks with live dashboards, so progress is tracked between assessments across every COMPASS domain.
Tabletop exercises
Facilitated tabletop exercises against AI-augmented adversaries to rehearse stage 4 playbooks.