One consistent, defensible A to F risk grade for every AI, combining technical severity, business context, data sensitivity, and blast radius.

Flat lists and red/yellow/green flags don't tell you where to spend the next hour of security effort.
A model that touches customer PII carries different risk than one summarizing public docs, even if the CVEs look identical.
Auditors want a repeatable methodology, not a spreadsheet built the night before the review.

Every AI resource in your environment gets a live A to F grade you can defend to auditors, leadership, and the board.
| AI Resource | Data Sensitivity | Blast Radius | Grade |
|---|---|---|---|
| ChatGPT (personal) | High | High | F |
| Unknown MCP srv | Critical | Critical | F |
| Cursor + MCP | Medium | High | D |
| Claude Enterprise | Medium | Medium | B |
| Azure OpenAI | Low | Low | A |
I like the red team… feels a little unique… I don't think anybody I've seen or talked to is doing that.
Get one defensible score per AI, mapped to the frameworks your auditors already use.