Index / Methodology

How the index is scored

The index turns a short questionnaire into one exposure score across five weighted signals. The scoring is transparent, and the full question set publishes with the assessment.

The five signals

Your answers are scored across five signals. Each carries a weight set by how much that control, present or absent, moves real exposure. A visibility gap raises the score more than an audit gap, which is why the two are not weighted the same.

AI visibility
A live inventory of every AI tool, agent, and connected account in use, corporate and personal, or a set of blind spots you are guessing at.
25
Data movement
Whether sensitive content is caught the moment it moves toward an AI tool, before it lands in a model.
25
Identity and ownership
Whether every AI action ties back to the person driving it, with their role, status, and an accountable owner.
20
Evidence and audit
Whether you keep a per-prompt record that would hold up in front of an auditor.
15
Remediation reach
Whether you can act through the stack you already run, revoke, quarantine, uninstall, without standing up a new agent.
15

How the score is calculated

Each answer is worth exposure points from 0 to 100, where 0 means the control is fully in place and 100 means it is absent. A signal subscore is the average of its questions. The index is the weighted sum of the five subscores, so it also runs 0 to 100, and higher means more exposed.

index = visibility×0.25 + data movement×0.25 + identity×0.20 + evidence×0.15 + remediation×0.15
Higher score means more exposed. Lower is better.

This is a self-reported, directional read, not an audit. It is built to be consistent, so the number you record this quarter is comparable to the one you record next.

The five exposure bands

The score places an organization in one of five bands. The bands run from controls holding across the board to little visibility or control at all.

Contained
0 to 20. Controls hold across the five signals. Keep them current as AI use grows.
Guarded
21 to 40. The basics are in place. A few gaps are worth closing before they widen.
Elevated
41 to 60. Real exposure sits in more than one signal. This is where most teams are today.
Exposed
61 to 80. Sensitive data can move through AI with little to stop it. Work the weakest signals first.
Critical
81 to 100. There is little visibility or control over AI-era data movement. Start with the fundamentals.

Where the numbers come from

Every statistic on this site is attributed to a primary source, and we cite only major research organizations and established players in the field. We do not cite security startups or vendors marketing a competing product. The figures behind the index today are drawn from:

Where a number appears on this site, its source appears next to it. We never invent a figure or round past what the source says.

Who is behind the index

The AI Insider Risk Index is built and maintained by Anzenna, an AI security company. We say that plainly because a benchmark is only useful if you can trust it. The scoring never asks about or rewards any vendor's product, Anzenna's included. More on how we handle this is on the about page.

Score your exposure

Fifteen questions, about ten minutes, no registration to see your result.

Take the assessment