The Operating Discipline for AI Library™

Secure by Design in the Age of AI™

The Product Security Operating Model for the AI Era

Available now

Book 07 of 9 in The Operating Discipline for AI Library™, Book 3 of 5 in AI Risk Governance & Security™. Secure by Design has changed from a compliance posture into a capacity problem. Engineering velocity has increased by an order of magnitude. Security review capacity has not. At the same time, AI introduces a class of vulnerabilities that traditional, deterministic tools are structurally unable to detect. This book introduces The Dual-Impedance Problem and provides the working frameworks executives need to ship AI-enabled products faster and more securely than the organizations they compete with. The complete set of figures from the book is available below, free to download and use within your organization, alongside the thirty-three operating instruments of the Consulting Toolkit, editable and ready to run.

Buy on Amazon → Hardback, paperback, and Kindle editions.
Editions

Hardback, 444 pages, $109.99, ISBN 979-8-9969402-9-5. Paperback, $46.99, ISBN 979-8-9969402-8-8. Kindle edition, $24.99.

Secure by Design in the Age of AI™ book cover
For Librarians

What every Librarian needs to know about this book!

Volume VII of The Operating Discipline for AI Library™ · 444 pages · Hardcover ISBN 979-8-9969402-9-5. The library sell sheet fits on one page and carries the full bibliographic record, ISBNs and list prices for every format, a summary of what is inside, and the collections the book suits.

Download the Library Sell Sheet (PDF) ↓
Executive Briefing
Secure by Design in the Age of AI™
PDF · 26 Slides
Read the Briefing

The executive briefing, in one page at a time.

A condensed visual companion to the book. The Dual-Impedance Problem, the five frameworks that answer it, the gate-versus-verification distinction every customer and auditor now tests for, the Review Capacity Ratio, and the first ninety days sequenced by dependency. Twenty-six slides, built for the practitioner who owns the work and the leadership team that funds it.

AI has changed product security from a quality function into a capacity problem.

Two forces compound at once. Engineering velocity has increased by an order of magnitude while security review capacity has not, opening a widening gap between how fast products are built and how fast they can be reasonably secured. Layered on top of that velocity gap, AI introduces a fundamentally different class of risk: vulnerabilities that exist at the meaning layer, not the syntax layer, where deterministic tooling cannot reliably find them. Most organizations are quietly shipping AI-enabled products faster than they can secure them, and learning about the gap from customers, regulators, or breach disclosures.

This book names that combined condition The Dual-Impedance Problem and treats it as the strategic context every product organization now operates inside. Organizations that solve it use AI to close the security capacity gap and build structural boundaries around AI's new failure modes. Organizations that do not ship faster, accumulate undetected risk, and discover it from the outside.

Is your review sized for the rate you now ship? Start with a conversation.

Every gate was passed. The feature still did something nobody asked for.

The feature shipped on a Thursday. Nine days later a customer’s security team found it would apply a credit to an account it had never been asked about, and the director pulled the release record expecting to find the gate someone had gone around.

Every gate had been passed. The sprint had closed forty-one changes, thirty of them generated with an assistant, and the two reviews the lifecycle required had each taken about eleven minutes. Nothing was skipped. The review had been sized for a quarter, and the engineers now ship in a week.

Every gate passed, and the risk still shipped? That gap is the engagement.

What this book gives you

At its center are five frameworks, one question each: see the whole surface, sort before you design, verify at the rate the product changes, decide, then sustain. They install as working instruments rather than policy: The AI Attack Surface Ledger, one row for every boundary crossing in every product; The AI Feature Tier Map and the Seven Stop Conditions, which decide where scarce human judgment goes; The Two-Lane Assurance Model, which sends rate to the machine and kind to the human; and The Ship Decision Record and the Product Security Case, which produce release evidence rather than remediation evidence. Beside them sits The Review Capacity Ratio, the number that turns a backlog complaint into a decision a CFO can act on.

The frameworks are aligned with the CISA Secure by Design program, OWASP LLM Top 10, NIST SSDF, and emerging AI regulation. They produce decisions defensible to a board, an auditor, or a regulator, not a slide deck.

Rate to the machine, kind to the human. The model starts with one call.

Who it's for

CISOs, CTOs, VPs of Engineering and Product, security architects, board members, and compliance officers in organizations shipping AI-enabled products to enterprise customers or regulated industries. No technical background required for the executive deliverables; engineering-grade depth available for the architects and senior engineers who will own the implementation.

The Consulting Toolkit

Thirty-three working instruments ship with the book as its appendix set, from the Defensible Product Security Baseline Scorecard and the Review Capacity Ratio Worksheet through the AI Attack Surface Ledger, the AI Feature Tier Map, the Lane Assignment Table, the Ship Decision Record, the Product Security Case, the Product Attestation Pack, and the Judgment Budget. Every figure behind them, and every framework diagram from all sixteen chapters, is in the Chapter Graphics Library below, free to download and use within your organization today.

How the book and the Secure by Design in the Age of AI engagement work together

The book is the operating manual, written for the product security leaders who will run the program themselves: the ledger, the tier map, the two lanes, the release gate, and the attestation pack, installed against their own release calendar. The Secure by Design in the Age of AI™ engagement is the execution of that model, designed for organizations that want the baseline scored, the ratio computed, the boundaries drawn, and the first ninety days sequenced inside a defined timeline, not learned, drafted, and refined over two quarters of internal effort.

Teams that want the discipline in book form work from the book. Teams that want the tier map drawn against their own products, the lanes staffed against their own review capacity, and the attestation pack assembled for their own customers, work directly with the firm.

Free downloads for this book

The worksheets and templates that ship with this book are free. Enter your email once, click the confirmation link we send you, and every book's downloads unlock across the site, forever.

The Consulting Toolkit

Every operating instrument, editable and ready to run.

The thirty-three operating instruments from the book, free and editable, one for every item in the Appendix. These are the working material of the first ninety days and the operating year that follows, not reading material. The spreadsheets work in Microsoft Excel, Google Sheets, Apple Numbers, and LibreOffice Calc; the fill-in forms open in any word processor.

Recommended Starting Point
The Defensible Product Security Baseline Scorecard

The program’s first artifact. Seven areas, scored on one product, dated and reviewed. Fill it in first: in an afternoon it tells you where the program actually stands, and it produces the baseline every later instrument reads.

Download the Baseline Scorecard →
Chapter Graphics Library

Visual frameworks, ready for your presentations.

Every diagram, framework, and chart from the book is available here as an individual file. Use them in your slide decks, internal memos, board presentations, or training sessions. Free to use within your organization. Browse by chapter, click any image to download.

Appendix
Appendix A: The Defensible Product Security Baseline Scorecard
Appendix A: The Defensible Product Security Baseline Scorecard
Download ↓
Appendix B: The Review Capacity Ratio Worksheet
Appendix B: The Review Capacity Ratio Worksheet
Download ↓
Appendix C: The Accountability and Risk Acceptance Table
Appendix C: The Accountability and Risk Acceptance Table
Download ↓
Appendix D: The Default Authority Profile
Appendix D: The Default Authority Profile
Download ↓
Appendix E: The Lifecycle to Delivery Map
Appendix E: The Lifecycle to Delivery Map
Download ↓
Appendix F: The Intake Record and Discovery Brief
Appendix F: The Intake Record and Discovery Brief
Download ↓
Appendix G: The Prototype Register
Appendix G: The Prototype Register
Download ↓
Appendix H: The Product Side Privacy Plan
Appendix H: The Product Side Privacy Plan
Download ↓
Appendix I: The Seven Stop Conditions Checklist
Appendix I: The Seven Stop Conditions Checklist
Download ↓
Appendix J: The AI Feature Tier Map Worksheet
Appendix J: The AI Feature Tier Map Worksheet
Download ↓
Appendix K: The AI Attack Surface Ledger Template
Appendix K: The AI Attack Surface Ledger Template
Download ↓
Appendix L: The Five AI Trust Boundaries Convention and Reviewer Checklist
Appendix L: The Five AI Trust Boundaries Convention and Reviewer Checklist
Download ↓
Appendix M: The Component Admission Standard Checklist and Exception Form
Appendix M: The Component Admission Standard Checklist and Exception Form
Download ↓
Appendix N: The Threat Model Delta Record and Trigger List
Appendix N: The Threat Model Delta Record and Trigger List
Download ↓
Appendix O: The Generated Test Plan
Appendix O: The Generated Test Plan
Download ↓
Appendix P: The Tool Registry Integrity Checklist
Appendix P: The Tool Registry Integrity Checklist
Download ↓
Appendix Q: The Privacy Implementation Record
Appendix Q: The Privacy Implementation Record
Download ↓
Appendix R: The Lane Assignment Table and Sampling Policy
Appendix R: The Lane Assignment Table and Sampling Policy
Download ↓
Appendix S: The Ship Decision Record
Appendix S: The Ship Decision Record
Download ↓
Appendix T: The Product Security Case Template
Appendix T: The Product Security Case Template
Download ↓
Appendix U: The Three Customer Commitments
Appendix U: The Three Customer Commitments
Download ↓
Appendix V: The System Card Decision and Known Limitations Statement
Appendix V: The System Card Decision and Known Limitations Statement
Download ↓
Appendix W: The Disclosure Policy Safe Harbor and Report Form
Appendix W: The Disclosure Policy Safe Harbor and Report Form
Download ↓
Appendix X: The Behavioral Vulnerability Protocol and Incident Procedure
Appendix X: The Behavioral Vulnerability Protocol and Incident Procedure
Download ↓
Appendix Y: The Post Release Response Ladder
Appendix Y: The Post Release Response Ladder
Download ↓
Appendix Z: The Definition of Secure Done and the Seven Scoping Questions
Appendix Z: The Definition of Secure Done and the Seven Scoping Questions
Download ↓
Appendix AA: The Product Attestation Pack and the Metric Page
Appendix AA: The Product Attestation Pack and the Metric Page
Download ↓
Appendix AB: The Phase by Phase Reference Table
Appendix AB: The Phase by Phase Reference Table
Download ↓
Appendix AC: The Response Pipeline Record and Verdict Feed
Appendix AC: The Response Pipeline Record and Verdict Feed
Download ↓
Appendix AD: The Security Specification
Appendix AD: The Security Specification
Download ↓
Appendix AE: The Model Inventory and Canary Record
Appendix AE: The Model Inventory and Canary Record
Download ↓
Appendix AF: The Laboratory Manifest and Harness Report
Appendix AF: The Laboratory Manifest and Harness Report
Download ↓
Appendix AG: The Judgment Budget
Appendix AG: The Judgment Budget
Download ↓

Publication details

Series
The Operating Discipline for AI Library™, Volume 7
Published
September 8, 2026
Length
444 pages
Publisher
SRJ Consulting & Services Publishing
Editions, ISBNs, and list prices
EditionISBN-13List price
Hardcover979-8-9969402-9-5$109.99
Paperback979-8-9969402-8-8$46.99
Kindle979-8-9981369-6-2$24.99

Buy on Amazon List prices shown. Retailer pricing varies.