AI Agent for Security Posture & Controls
Most security gaps are not unknown risks; they are controls everyone believes are in place. This agent compares what your framework claims against what your configuration and telemetry show, and reports the difference ranked by what an attacker could actually do with it.
What is an AI security analyst?
An AI security analyst is a governed software worker that assesses security posture from observed evidence. It tests whether documented controls are operating using configuration and telemetry, enumerates the assets and accounts each control does not cover, maps coverage against a framework, and ranks the resulting gaps by exposure within the estate.
What it does
What it is not
The control was in the framework and not in the estate
Control assessments are mostly conducted by asking, and the answers are given by people describing the design rather than the deployment. Multi-factor authentication is enabled — except on the four service accounts that could not support it. Logging is comprehensive — except on the segment added during an acquisition.
Design is confused with deployment
A control is documented, approved and genuinely intended, and the exceptions that were granted to ship it are nowhere in the assessment.
Coverage is assessed in aggregate
Endpoint protection sits at ninety-four percent, and the six percent is the part that matters and is never enumerated.
Frameworks are answered, not tested
A control question is answered from the policy that requires the control rather than from evidence that it operates.
Gaps are ranked by severity label
Findings are ordered by a generic rating rather than by what an attacker could reach from where the gap actually sits.
What the estate shows, not what the framework claims
Verification
Read The Configuration, Not The Policy
Deployment over design.
Each control is assessed from the configuration and telemetry that would demonstrate it operating — enrolment records, policy assignments, log arrival, key rotation dates — rather than from the document stating that it is required.
- Assessed from configuration and telemetry
- Exceptions and exemptions enumerated
- Coverage reported as the uncovered set
- Evidence cited for every determination
Not documented state
Coverage
The Six Percent, By Name
Aggregates hide the gap.
Coverage is reported as the specific assets, accounts and segments that fall outside a control rather than as a percentage, because the uncovered set is the finding and a percentage is a way of not stating it.
Named, not counted
Prioritisation
Ranked By What It Reaches
Not by a generic severity.
Gaps are ordered by what they would allow in your estate — what the affected asset can reach, what it holds, whether another control compensates — so remediation effort follows exposure rather than a label.
Estate-specific
How the AI Security Analyst runs a task
- STEP 01
Establish the expected state
The control baseline is taken from your framework, standards and policy so that assessment measures against what your organisation committed to rather than against a generic benchmark that nobody signed up to.
Baseline extractionFramework mapping - STEP 02
Read the actual state
Identity configuration, endpoint enrolment, network segmentation, logging pipelines, backup records and key rotation are read directly, because these show whether a control operates in a way that an attestation cannot.
Configuration readTelemetry inspection - STEP 03
Enumerate the difference
For each control the specific assets, accounts and segments outside it are listed by name together with any recorded exemption, replacing a coverage percentage with the set that a remediation plan can actually work through.
Coverage differencingExemption collection - STEP 04
Weigh the exposure
Each gap is assessed for what it would permit here — what the uncovered asset can reach, what data it holds, whether a compensating control limits the consequence — producing a ranking grounded in your topology.
Reachability analysisCompensating controls - STEP 05
Report with the evidence
Findings are issued with the configuration or telemetry that produced each determination cited, so a control owner can verify the finding directly instead of debating whether the assessment understood their environment.
Evidence citationOwner routing
Systems the AI Security Analyst connects to
Configuration evidence
Technical scanning
Inputs, outputs and runtime
- Ingests
- Control framework and baselineIdentity and endpoint configurationNetwork segmentation dataLogging pipeline stateGranted exemptions
- Produces
- Control determination with evidenceEnumerated uncovered setFramework coverage mapExposure-ranked gap listExemption review
- Triggered by
- Scheduled posture reviewPre-audit preparationAcquisition assessment
- Human oversight
- Control owners decide remediation and risk
- Models
- Open-weight LLMs you host — Llama, Qwen or Mistral class
- Typical latency
- Hours for a full control baseline pass
- Deployment
- On-premise or sovereign cloud with egress control
- Data residency
- Configuration evidence stays in your estate
Where the Security Analyst pays back
Control Effectiveness Review
Test whether each documented control is actually operating across the estate it is supposed to cover.
Framework Coverage Mapping
Map each framework requirement to the evidence demonstrating it, and list the ones with no evidence.
Acquisition Posture Assessment
Compare an acquired environment against your control baseline and enumerate what is missing.
Logging Completeness Audit
Establish which systems are not sending the telemetry that detection rules assume is arriving.
Exemption Review
Collect every control exception granted, when it was granted, and whether the reason still applies.
Audit Evidence Preparation
Assemble the configuration evidence for each control ahead of an external assessment.
AI Security Analyst vs chatbots and SaaS copilots
Control assessment has an unusual property: the organisations most confident in their answers are frequently the ones assessing design rather than deployment, because a well-written policy produces a well-answered questionnaire.
| Generic chatbot | SaaS copilot | VDF AI | |
|---|---|---|---|
| Assessment basis | Framework text | Questionnaire | Configuration and telemetry |
| Coverage reporting | Not applicable | A percentage | The uncovered set by name |
| Exemptions | Unknown | Separate register | Collected and reviewed |
| Gap ranking | Generic severity | Vendor score | What it reaches in your estate |
| Evidence | None | Attestation | Cited configuration |
| Changes configuration | No | Sometimes | Never — owners remediate |
| Where the gap list lives | Vendor service | Vendor cloud | Inside your own network |
Governance and controls
A posture report is a ranked list of the ways into your organisation, so it needs the same handling as the estate it describes and the same restraint about acting on what it finds.
Read-only assessment
No configuration is modified
No exploitation attempted
Findings are observed, not tested live
Findings carry evidence
Each determination cites its source
Risk acceptance stays human
Only owners may accept a gap
Report access restricted
Distribution limited to named roles
Exemptions surfaced
Granted exceptions reported, not hidden
Evidence it leaves behind
What changes after rollout
Who runs the AI Security Analyst
Chief information security officer
Can distinguish between controls that are designed and controls that are deployed, and report posture to a board using enumerated exceptions rather than coverage percentages that conceal the interesting part.
Security architect
Sees which segments and account classes consistently fall outside the baseline, which usually points at a structural reason — an acquisition, a legacy platform — rather than at individual oversights.
Compliance and audit lead
Answers framework questions with configuration evidence attached rather than with policy references, which changes the character of an external assessment from discussion to verification.
Questions about the AI Security Analyst
What is an AI security analyst?
It is an agent that assesses security posture from evidence: testing whether each control is actually operating using configuration and telemetry, enumerating the assets it does not cover, mapping coverage to framework requirements, and ranking gaps by exploitable exposure.
How is an AI security analyst different from a generic chatbot?
A chatbot can describe what a control framework requires. This agent reads your configuration and telemetry to establish whether the control is deployed, and names the assets where it is not.
Can an AI security analyst run on-premise on security configuration data?
Yes. A posture assessment is a complete description of where your defences are weakest, which is the single document you would least want to exist outside your own environment.
What does an AI security analyst produce, and in what format?
A control-by-control determination with evidence cited, the enumerated uncovered set for each control, a framework coverage map, and gaps ranked by what they would allow in your estate.
Where does an AI security analyst fit in a governed AI programme?
It assesses; it does not remediate. Changing a configuration, granting an exemption and accepting a risk are decisions owned by the accountable people, with the agent supplying the evidence.
Is this a penetration test?
No. It observes configuration and telemetry to determine whether controls are deployed and operating, and it does not attempt exploitation of anything. Those are complementary activities: a posture assessment tells you which controls are missing across the whole estate, while a penetration test demonstrates what a specific chain of weaknesses allows. Neither substitutes for the other.
How is this different from the SOC analyst agent?
Time horizon and subject. The SOC analyst works on events happening now, deciding whether a signal warrants attention. This agent works on standing state: whether the controls that should prevent those events are in place across the estate. One reduces the time to assess an alert; the other reduces how many alerts there are to assess, by finding the coverage gaps that generate them.
Can it accept a risk or grant an exemption?
No. It collects the exemptions that exist, reports when the stated reason no longer appears to apply, and routes the question to the accountable owner. Risk acceptance is an act with organisational consequences and a named owner, and an agent that could grant one would create exemptions nobody decided to take.
What if our asset inventory is incomplete?
That becomes the first finding, and usually the most consequential one. Coverage cannot be assessed against an unknown denominator, so where configuration sources disagree about what exists — endpoints in the identity platform that are absent from the asset register, segments with log traffic and no owner — those discrepancies are reported before any control determination that depends on them.
How does it rank gaps without knowing our business context?
It uses the context available in the estate: what the uncovered asset can reach across the network, what data classification is attached to it, whether other controls constrain the consequence. Where business criticality is recorded in your inventory it is used; where it is not, the agent says the ranking is based on technical reachability alone rather than presenting it as a business risk assessment.
Find the controls that exist only on paper
See the AI Security Analyst test your control baseline against actual configuration.