Playbook
The 15-chapter playbook
Read chapters 1–5 in order. After that, jump to whichever chapter answers a question you have today.
- →
Chapter 01
Introduction — why AI red teaming, and how it's different
Why an AI red team is now a distinct, defensible function inside regulated enterprises, and how it differs from traditional offensive security.
- →
Chapter 02
Engagement types — when to use which
The seven engagement types this framework supports, when each is appropriate, what each produces.
- →
Chapter 03
Charter — mission, scope, authority, exclusions
How to write an AI Red Team Charter that survives CISO, CRO, audit, and regulator scrutiny.
- →
Chapter 04
Governance — RACI, oversight, reporting, escalation
How to govern an AI red team function so it survives regulator scrutiny and integrates with three-lines-of-defense.
- →
Chapter 05
Rules of Engagement — anatomy of a good ROE
What a Rules of Engagement document must contain for an AI red team engagement at a regulated enterprise.
- →
Chapter 06
Scoping — from system inventory to engagement
How to scope an engagement when you have an AI System Inventory and limited test capacity.
- →
Chapter 07
Tooling — build vs buy, AI-augmented offensive testing
How to choose AI red team tools, and where to draw the line between building in-house and buying.
- →
Chapter 08
Execution — phases, evidence, safe handling of dangerous outputs
How to actually execute an AI red team engagement, with attention to evidence integrity and safe handling of harmful outputs.
- →
Chapter 09
Reporting — three-tier deliverables that get acted on
Three deliverables per engagement, each calibrated to a different audience.
- →
Chapter 10
Metrics — engagement, program, board
Three layers of metrics for an AI red team program — engagement, program, board.
- →
Chapter 11
Purple team — operationalizing findings with blue team and AI engineering
How to convert AI red team findings into durable improvements through collaboration with detection engineering and AI engineering.
- →
Chapter 12
Compliance mapping — how findings become audit evidence
Tying AI red team output directly to audit evidence requirements and regulatory expectations.
- →
Chapter 13
Third-party engagements — when to commission, how to oversee
When external testers add value, how to choose them, and how to oversee the engagement.
- →
Chapter 14
Incidents — what to do when red team finds a real-world live issue
What changes when an engagement uncovers a live, in-production issue with customer or regulator impact.
- →
Chapter 15
Program maturity — Crawl, Walk, Run, Lead
A four-stage maturity model for an AI red team program, with practical signals for each level.