China AI Cybersecurity: An Executive Briefing Framework
Assess enterprise AI security through tool permissions, sensitive data exposure, prompt injection, supplier access and tested incident response.

AI security diligence should examine the permissions attached to a system, not just the model's responses. Map the documents it can read, the tools it can call and the actions it can take without approval. Then ask how the organisation detects misuse and limits the impact of an unsafe instruction.
What to evaluate
Asset map
Identify models, data, prompts, tools, identities, endpoints and external services.
Threat model
Test misuse, injection, leakage, poisoning, model theft and insecure integration.
Controls
Inspect access, isolation, validation, monitoring, red teaming and recovery.
Governance
Connect security ownership with product, legal, risk, procurement and suppliers.
Worked evaluation exercise
The following is an illustrative assessment exercise, not a reported customer result.
In an authorised sandbox, give a document assistant a test file containing instructions that conflict with the user's request. Check whether it treats those instructions as untrusted content and whether any attempted tool action is blocked or logged. Use synthetic records and harmless actions. Ask the operator to demonstrate revoking access and investigating the event. A refusal in one test is useful evidence, but does not establish comprehensive protection.
Questions for the operating team
- Which new privileged path does AI create?
- How is untrusted content separated from instructions?
- Who can suspend a compromised workflow?
Warning signs
- Security described only at the model layer.
- Logs unable to reconstruct tool calls.
- Third-party risk omitted from architecture.
Planning the visit
Use these questions to scope an industry-focused China AI program. Agree which records and operating workflows can be examined before confirming meetings; host participation and access require confirmation. Our research method explains how we structure the brief and follow-up.
References and scope
These references provide policy or risk-management context. They do not independently verify a host's performance or the illustrative exercise above.