Executive AI Risk Summary

Acme Corp · Q4 2025 · Prepared for Board Risk Committee

ATAS
AI Threat Awareness & Security Readiness
Report ID
ATAS-EXEC-1970-Q4-0142
Executive Report

AI Security Readiness Summary

Acme Corporation Generated January 1, 1970Reporting period: Q4 2025
Confidential · Board Use
Overall Readiness
68
out of 100
↑ +6 vs last quarter

Executive Summary

Acme Corp's AI security readiness improved by 6 points this quarter to a composite score of 68/100, placing the organization above the industry average (54) but below the 80 target set by the Board Risk Committee. Gains were driven by org-wide policy attestation and the rollout of role-based training, which lifted training completion to 68%.

Three departments — Finance, Customer Support and Sales — remain elevated risk, and the simulation failure rate (27%) exceeds our 20% benchmark. The two highest-impact threat vectors observed this period are data leakage to public AI tools and deepfake-enabled executive fraud. The 30/60/90-day roadmap on the final page prioritizes containment of both.

Readiness Score
68/100
+6
Employees Trained
342/500
+58
Sim Failure Rate
27%
-4 pts
High-Risk Depts
4
-1

Top 5 Organizational AI Risks

  1. 1
    Employees pasting customer data into external AI tools
    Customer Support, Sales
    Critical
  2. 2
    Finance team vulnerable to AI-generated invoice fraud
    Finance
    High
  3. 3
    HR lacks fake candidate / synthetic identity detection training
    HR & Recruiting
    High
  4. 4
    Engineering team needs prompt injection awareness
    Engineering, AppSec
    Medium
  5. 5
    Executives need deepfake verification protocol
    Executive Team
    Critical

Most Vulnerable Departments

Finance
High
Readiness: 58/100·Completion: 72%·Sim Fail: 38%
→ Deploy invoice-fraud simulation
HR
High
Readiness: 62/100·Completion: 74%·Sim Fail: 31%
→ Assign fake candidate training
Customer Support
High
Readiness: 51/100·Completion: 65%·Sim Fail: 34%
→ Enforce data-leakage policy
Sales
Critical
Readiness: 45/100·Completion: 56%·Sim Fail: 36%
→ Phishing simulation + AI policy
Executive Team
Critical
Readiness: 76/100·Completion: 88%·Sim Fail: 24%
→ Deepfake verification protocol

Simulation Performance

27% failure rate

Across 4 simulations run this quarter (AI spear phishing, deepfake voice, vendor invoice manipulation, sensitive data paste), the org-wide failure rate was 27% — above the 20% benchmark. Highest failures concentrated in Finance and HR, consistent with attacker targeting patterns.

Employees
28%
Finance
38%
HR
31%
Executives
24%

Data Leakage Risk

Medium

SSO and egress logs show high public-tool usage from departments without enterprise AI licenses. 42 instances of sensitive-pattern input (PII, source code, financial data) were flagged in the last 30 days. A single uncontrolled paste exposes regulated data to a third-party model provider.

Flagged events
42
Depts affected
6
PII incidents
11
Source-code leaks
7

Shadow AI Risk

High

Discovery scan identified 42 unsanctioned AI tools and browser extensions in use across 6 departments. Shadow AI bypasses data governance, logging and retention controls, and is the fastest-growing source of AI incidents — and the hardest to detect after the fact.

Unsanctioned tools
42
Active users
187
High-risk tools
10
Sanctioned coverage
61%

Technical AI Security Readiness

Medium

Copilot adoption is high across Engineering, but only 38% of engineers have completed the Secure AI Coding track. No prompt-injection tests are in CI, and LLM-backed services ship without a dedicated AppSec review gate. OWASP LLM Top 10 coverage is incomplete.

Secure-coding cert.
38%
LLM services in prod
9
AppSec gated
3/9
Prompt-inj tests
0

Risk Distribution

Shadow AI24%
Data Leakage22%
AI Phishing18%
Deepfake Fraud14%
Prompt Injection12%
Policy Noncompliance10%

Recommended Actions

  • Mandate enterprise AI tooling org-wide; block public LLM endpoints at the egress proxy
  • Deploy deepfake verification protocol (out-of-band callback) for all executive comms
  • Run quarterly AI phishing simulations with department-level remediation tracking
  • Add prompt-injection regression tests to engineering CI for every LLM-backed service
  • Tie annual AI policy attestation to performance review and access provisioning
  • Establish #ai-incidents response channel with 1-hour SLA and named on-call owner

30 / 60 / 90-Day Remediation Roadmap

0–30 Days
Containment
  • Block public LLM endpoints on managed devices
  • Mandate AI policy attestation org-wide
  • Deploy ChatGPT Enterprise SSO + audit pipeline
  • Launch AI Phishing simulation to all employees
31–60 Days
Hardening
  • Roll out role-based modules to Finance, HR, Engineering
  • Implement deepfake verification protocol for executives
  • Add prompt-injection tests to AppSec CI
  • Establish #ai-incidents reporting channel
61–90 Days
Operationalize
  • Quarterly executive readiness review
  • Tabletop exercise: AI-assisted BEC
  • Publish internal Safe AI Usage playbook v2
  • Re-baseline org readiness score (target ≥ 78)
ATAS · Confidential · Prepared for the Acme Corp Board Risk Committee · January 1, 1970 · ATAS-EXEC-1970-Q4-0142