AIVendor.Risk
A governance dashboard for CISOs and AI risk officers that ingests official cyber-capability evaluations (UK AISI, CAISI, NIST) plus red-team reports and turns them into a normalized risk score for every AI model and vendor in your stack.
CISOs, AI governance leads, and procurement teams at mid-to-large enterprises evaluating which LLMs and AI agents to deploy
- Normalized 0-100 risk score per model covering cyber exploit capability, jailbreak resistance, and safeguard strength, sourced from official evaluations
- Vendor watchlist alerts when a new evaluation (e.g. CAISI Kimi K3 release) drops and shifts a vendor's score
- Procurement-ready PDF reports that map model risk to your existing AI policy and flag models that fail your threshold
- Audit log of every model your organization uses, with last-evaluation date and known capability gaps
Reports like the CAISI Kimi K3 assessment are landing every few weeks now that frontier labs ship faster than security teams can review them; nobody has built the layer that turns these technical PDFs into a procurement-grade score.
Multiple authoritative sources (PwC, TrustCloud's CISOs Guide to AI Governance, SecureByDezign) explicitly frame AI vendor risk management as a top CISO priority, with NIST itself publishing the UK AISI/CAISI Kimi K3 evaluation as a procurement-relevant artifact.The 2025 CISOs' Guide to AI Governance ↗UK AISI / CAISI Preliminary Assessment of Kimi K3's Cyber Capabilities ↗AI Vendor Risk Management: What CISOs Must Demand Before Signing the Contract ↗
Crowded incumbent field — Credo AI explicitly sells 'Govern AI Everywhere across models, GenAI, agents, and vendors,' and Holistic AI, ModelOp, OneTrust AI Governance, FairNow, and Vanta all compete in AI governance/vendor inventory.Credo AI vs. Holistic AI: Built for the Boardroom, Not Just the Lab ↗Top 5 AI Governance Platforms for 2026 ↗
Enterprise governance tools sell to CISOs at $20k–$100k+/yr with EU AI Act and NIST AI RMF deadlines creating compliance urgency; PwC has built a dedicated responsible-AI-TPRM practice signaling willingness to pay.Responsible AI and third-party risk management: PwC ↗Credo AI vs Holistic AI (2026): Pricing & Features ↗
Regulatory durability is strong: UK AISI publishes periodic capability evaluations (May update covers five LLMs), EU AI Act is phasing in through 2026, and NIST AI RMF is the de facto US framework — a multi-year compliance wave.Advanced AI evaluations at AISI: May update ↗UK AI Safety Institute Framework ↗
Ingesting public AISI/CAISI/NIST PDFs is straightforward, but the hard part — normalizing heterogeneous red-team reports into a trusted score and selling into security/procurement orgs with SOC 2, SSO, and integrations — is moderate-to-hard build for a small team.AI Security Institute (AISI) ↗