Securing enterprise AI: an effort–impact prioritization framework
A reference architecture answers what controls a governed AI agent needs. This framework answers the question a customer actually decides on: in what order, and is it worth it?
How to read the two axes
Customer-side effort measures what the customer must do, not what the consultant builds — low means configure a bought component, high means re-plumbing systems or discovering information that does not yet exist. Enterprise consequence measures severity if the control is absent, weighted by irreversibility, breadth of exposure and regulatory liability.
Master mapping
Foundations: policy and entitlement model, identity propagation (on-behalf-of), data classification. Core: database read enforcement (RLS and masking), permission-aware RAG retrieval, action controls with human-in-the-loop and limits, non-human identity governance. Quick wins: LLM firewall or gateway, PII redaction and output DLP, observability and audit lineage. Opportunistic: trained refusal disposition — never an enforcement boundary.
Consequence anchors
Impact ratings are anchored to IBM Cost of a Data Breach 2025 (global average $4.44M; US $10.22M). Missing action controls produce irreversible loss at machine speed — a telecom SIM-swap failure produced a $33M arbitration award. Missing read enforcement produces mass PII/PHI disclosure; healthcare has been the highest-cost sector for 14+ years at about $7.42M.
Sequenced roadmap
Phase 0 assessment (2–4 weeks, low customer effort). Phase 1 quick wins plus foundation kickoff (4–8 weeks). Phase 2 enforcement on one lighthouse use case (6–12 weeks). Phase 3 scale and govern, ending with the customer owning the policy model.
Hidden effort drivers
Identity propagation through shared service accounts and connection pools; undocumented entitlement discovery; classification debt; RAG ACL drift; legacy coarse authorization; and unclear ownership of the policy model across security, data, platform and application teams.
Frequently asked
- Why rank controls by customer effort rather than by architecture?
- Because the architecture diagram does not tell a sponsor what to fund first. Effort is driven by the state of the existing estate, not by the vendor's product.
- Can we start with the quick wins alone?
- Yes — a gateway, DLP and audit lineage typically get an initiative past its first security review within weeks. They are necessary but never sufficient: they do not enforce who may do what.
- What does a Phase 0 assessment deliver?
- In two to four weeks: a data-estate and IAM-maturity map, an entitlement-gap analysis, a threat model, a build-vs-buy recommendation, and a prioritized roadmap sequenced by effort and consequence.