One published scale, one grade per resource, and a breakdown you can hand to an auditor.
Flat lists and red, amber and green flags do not tell a team where to spend the next hour. Every finding of a given colour looks like every other finding of that colour, so triage falls back to whoever asked most recently. Omdia's February 2026 State of the SOC survey, commissioned by Microsoft and based on 300 security operations professionals, found that analysts pivot across an average of 10.9 consoles, an estimated 46 percent of alerts prove to be false positives, and 42 percent are never investigated at all. A scoring system that produces one more undifferentiated queue has added work, not judgement.
A model that can read customer records carries different risk from one that summarises published documentation, even when their vulnerability profiles are identical. A score that cannot see that difference will rank the two the same. It will be wrong in the one case anybody asks about afterwards.
Auditors want a repeatable methodology, not a spreadsheet built the night before the review.
Three more measured facts explain why this ends up in front of an auditor rather than only in front of a security team. Across the hundred most used generative AI SaaS applications, 82 percent are classified as medium, high or critical risk by an independent telemetry vendor, so the population being graded is not evenly distributed and the position of the cut lines matters. Only four in ten organisations have a formal AI governance framework in place at all. And among organisations that suffered a breach, 68 percent lacked AI governance to manage AI or to detect shadow AI, up from 63 percent the year before. Read that last figure carefully. Its population is organisations that were already breached, not all organisations.
Risk classification of the top 100 generative AI SaaS applications: Cyberhaven Labs, 2026 AI Adoption and Risk Report, April 2026. The classification is Cyberhaven's own, not AIBound's.
Formal AI governance framework: Protiviti AI Pulse Survey, fourth edition, May 2026. n equals approximately 345 C suite executives, board members and IT leaders.
Governance absence among breached organisations: IBM, Cost of a Data Breach Report 2026, July 2026. n equals 602 organisations that experienced a breach.
A grade is defensible only if the things it is made of are written down. AIBound weighs a defined set of inputs for every AI resource it grades. Each is defined below, with what it changes and where it is read from.
Definition: The vulnerability and exposure profile of the resource itself.
What it changes: It sets the floor. This is the input every scanner already produces, and on its own it is the input that misranks.
Read from: Vulnerability and exposure data for the resource.
Definition: What the resource is used for, by whom, and how heavily.
What it changes: It separates two resources whose vulnerability profiles are identical. Without it, the two rank the same.
Read from: Observed usage across the environment.
Definition: The classification of what the resource can read or receive.
What it changes: It moves a grade further than any other input once the classification is high, because it is the input that decides how bad the worst case is.
Read from: The data classes the resource is connected to. Rendered on the platform as Low, Medium, High, Critical.
Definition: How far the resource can reach through the identity it operates as.
What it changes: It decides how far the worst case travels. Two resources with the same data sensitivity separate here.
Read from: The AI identity graph. Rendered on the platform as Low, Medium, High, Critical.
Grades are mapped to the EU AI Act and to the NIST AI Risk Management Framework. Mapping means a grade can be reported against those frameworks. It is not a certification, and neither framework operates one.
This is the scale. It is published so a reader can look up a letter and see what produced it, and so the same facts produce the same letter every time. That property, not the letter itself, is what an auditor is examining.
Two of the demonstrated rows reach F by different routes. One is a sanctioned tool reached through a personal account, so the tool is known and the place it is used is not governed. The other is a server nobody has identified, so neither is known. A single letter compresses both. That compression is what a grade is for, and it is also the thing a grade cannot do, which is why a score breakdown sits underneath every letter rather than beside it.
Risk grades and agent trust letters are treated as separate scales on this page.
The published scale runs A, B, C, D and F.
Every AI resource in your environment gets a live A to F grade you can defend to auditors, leadership, and the board.
| AI Resource | Data Sensitivity | Blast Radius | Grade |
|---|---|---|---|
| ChatGPT (personal) | High | High | F |
| Unknown MCP srv | Critical | Critical | F |
| Cursor + MCP | Medium | High | D |
| Claude Enterprise | Medium | Medium | B |
| Azure OpenAI | Low | Low | A |
Two columns, not the whole method. The panel above renders data sensitivity and blast radius because those are the two inputs that resolve to the four point scale shown here. The rest of what produces the letter sits in the definitions above and the full scale below.
Same sensitivity, different grade. Cursor plus MCP and Claude Enterprise are both Medium on data sensitivity. They separate on reach alone, and that separation is the whole argument for weighting reach at all.
Two routes to the same letter. A known tool in an ungoverned place and an unknown tool are different problems that arrive at the same grade. The grade tells you the size. The breakdown tells you which one you have.
What a reader can check. If a row here and the published scale disagree, the scale is wrong, not the row. That is the property that makes a letter arguable rather than asserted, and it is the only reason to publish a scale at all.
Grades are re-scored continuously as usage, data and permissions change. The distinction matters more to the audit conversation than to the security one. An assessment is true on the day it was signed. A score is true now.
Usage moves a grade. A resource used by a dozen people and the same resource used by several hundred are not the same exposure, and nobody has to touch the tool for that to change.
Data moves a grade. The classification of what a resource can reach changes whenever its connections change, and connections change without anyone raising a procurement decision.
Permissions move a grade. A resource that quietly inherits a broader identity has a broader blast radius the same day. This is the change least likely to generate a ticket, which is why it is the one worth watching automatically.
For context on how long an unnoticed change can sit before anyone acts on it, organisations took an average of 247 days to identify and contain a breach in the most recent measurement, a rise that reversed five years of decline. That figure is about breaches, not about grades. It is here because a grade calculated on an assessment cycle opens a gap of its own, between the last signature and today, and an auditor's second question is always about that gap. Continuous re-scoring closes it by construction rather than by promise.
Mean time to identify and contain a breach: IBM, Cost of a Data Breach Report 2026, July 2026. n=602 organisations that experienced a breach.
AIBound deploys read only and without installing endpoint agents, connecting directly to the identity, cloud and SaaS platforms your AI estate already runs on. Because nothing is installed on individual devices, there is no rollout to coordinate team by team with IT, and the live inventory begins populating as soon as the connections are authorized.
No. AIBound reads your AI estate through existing identity, cloud and API connections rather than installing software on individual devices. That agentless model is also what keeps the inventory current, since a new AI tool shows up because a new connection or credential exists, not because a device happened to check in.
AIBound tracks the AI your organisation already knows about alongside the AI it does not: sanctioned tools, unsanctioned shadow AI, and the identities, agents and MCP connections tied to them. A governance report is only as complete as the inventory behind it, which is why coverage extends past whatever is already on an approved list.
AIBound connects to the identity providers, cloud platforms and SaaS applications already in use, the same connections that already govern access across the organisation. Reporting is generated from that live connection layer, so a board report reflects the inventory as it exists in production rather than a static export prepared for the meeting.
Grades are mapped to the EU AI Act and to the NIST AI Risk Management Framework. Mapping means a grade can be reported against the structure those frameworks use. It is not certification. The NIST AI Risk Management Framework, document NIST AI 100-1, is published by NIST in its own words as "intended for voluntary use" and operates no certification or attestation scheme, so "mapped to" is accurate and "attested against" would not be.
I like the red team. Feels a little unique. I do not think anybody I have seen or talked to is doing that.
One defensible letter per resource, mapped to the frameworks your auditors already use, with the scale published in full.