Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

MITRE AI maturity scoring: where the governance gap still shows up


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15984
Topic starter  

TL;DR: MITRE’s AI maturity model gives organisations a structured way to score readiness across governance, data, technology, and operating model, but WitnessAI’s analysis makes clear that maturity alone cannot govern prompts, responses, or agent actions in real time. That gap matters because AI adoption is already outpacing control design, making runtime enforcement the decisive layer as agentic and customer-facing systems scale.

NHIMG editorial — based on content published by WitnessAI: MITRE AI maturity model guidance and its limits for runtime control

By the numbers:

Questions worth separating out

Q: What breaks when AI maturity assessments are used as a substitute for runtime control?

A: The assessment becomes a snapshot of readiness rather than a live control, so unauthorised prompts, tool calls, and agent actions can still occur outside policy.

Q: Why do AI tools create new identity governance risks for IAM teams?

A: AI tools create new identity governance risks because they combine fast adoption with broad access paths and subordinate permission objects.

Q: How do security teams know if AI governance is working?

A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent.

Practitioner guidance

  • Define AI action boundaries Map which prompts, tools, data sets, and downstream systems each AI use case can touch, then separate approved from prohibited actions before scaling the workload.
  • Inventory non-human credentials used by AI systems Track every token, service account, API key, and delegated permission used by copilots, agents, and chatbots, including owner, expiry, and revocation path.
  • Add runtime policy to AI workflows Apply intent-based allow, warn, block, and route decisions at the moment an AI system acts, especially where prompts can trigger data access or external tool calls.

What's in the full article

WitnessAI's full article covers the operational detail this post intentionally leaves for the source:

  • The full MITRE AI maturity assessment structure, including the six pillars and 20 dimensions used for scoring.
  • The step-by-step assessment workflow for assembling a cross-functional review and translating scores into a roadmap.
  • The specific relationship between maturity scoring, NIST AI RMF, ISO/IEC 42001, and the EU AI Act.
  • The runtime visibility and enforcement controls WitnessAI describes for AI prompts, responses, and agent actions.

👉 Read WitnessAI’s analysis of the MITRE AI maturity model and runtime AI control gaps →

MITRE AI maturity scoring: where the governance gap still shows up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15569
 

Maturity scoring is a governance signal, not a security control. The MITRE model is valuable because it gives leaders a common language for readiness, but readiness is not enforcement. Organisations can look disciplined on paper while still leaving prompts, tools, and agent actions outside policy coverage. That is why boards should treat maturity outputs as a prioritisation input, not as evidence that AI is safe to scale.

A question worth separating out:

Q: Who is accountable when an AI agent makes an unauthorised change?

A: Accountability should be assigned to the governance model that authorised the delegation, the owner of the workflow, and the team that set the policy boundary. In practice, organisations need clear responsibility for agent configuration, monitoring, and incident response because the machine’s speed does not remove human accountability for the delegated identity.

👉 Read our full editorial: MITRE AI maturity scores are useful, but runtime controls still decide risk



   
ReplyQuote
Share: