# Survey instrument

The ten questions of the AI Security Decisions Survey, wave 1, as respondents
saw them: the question wording, the answer type and whether an answer was
required, and every answer option in the order it was shown.

The authors of the AI Defense Matrix renamed two asset classes after this survey ran. AI Gateways and Routers is now AI Traffic. AI Orchestration Tools is now AI Coding and Orchestration Tools, with a different scope. The questions below keep the names respondents saw.

## Q1. Which best describes your role?

Multi-select, required, fixed order; description: "Choose multiple if it necessary, but try to pick only one."

- CISO or most senior security leader
- Security director or deputy reporting to the CISO
- Security architect or engineer
- Application or product security
- Governance, risk, or compliance
- Security operations or incident response
- Other (please specify)

## Q2. In a few words: what AI security risk is most on your mind right now?

Open text, optional; description: "All we need are a few words, so don't overthink it. Imagine a word cloud... what are the first few words that come to mind?"

Free text. No answer options were shown.

## Q3. How is your organization using AI today? Select all that apply.

Checkboxes, required, fixed order.

- Employees use third-party AI assistants or copilots
- Business applications we buy include embedded AI features
- We build products or internal tools using external AI models (APIs)
- We fine-tune or train our own models
- We host or run models on infrastructure we control
- We run AI agents that can use tools, credentials, or systems on their own
- We are evaluating AI but have no significant use yet
- Not sure
- Other (please specify)
- None of the above

## Q4. Which of these AI-related assets are part of your organization's attack surface today, meaning present in your environment or used on your behalf? Select all that apply.

Checkboxes, required, fixed order frozen across waves; description: "Count an asset whether or not you have secured it. The next questions use this same list."

- AI-Workload Platforms: the compute and serving infrastructure models run on (inference servers, vector databases)
- AI Orchestration Tools: the application layer connecting models to tools and data (agent frameworks, agent harnesses, MCP clients)
- AI-Generated Code: code produced by AI assistants and coding agents
- AI Gateways and Routers: the network path to AI services (LLM routers, MCP gateways)
- AI Model: the model itself, self-hosted or consumed as a service, including its weights
- Training Data: datasets used to train or fine-tune models
- Runtime AI Data: prompts, responses, RAG content, and agent memory flowing through AI at runtime
- AI Agent Identities: AI agents and other non-human identities, and the credentials they act with
- Not sure
- Other (please specify)
- None of the above

## Q5. For which of these AI-related assets has your organization implemented at least one dedicated security control? Select all that apply.

Checkboxes, required, fixed order frozen across waves; the eight options repeat the Q4 glosses; description: "These are the same eight assets, but if you didn't include it above in your attack surface, then presumably, you don't have a control for it and it shouldn't be selected here. Only select the assets where you have an attack surface and a control. The published findings will show which of these assets your peers are protecting first."

- AI-Workload Platforms: the compute and serving infrastructure models run on (inference servers, vector databases)
- AI Orchestration Tools: the application layer connecting models to tools and data (agent frameworks, agent harnesses, MCP clients)
- AI-Generated Code: code produced by AI assistants and coding agents
- AI Gateways and Routers: the network path to AI services (LLM routers, MCP gateways)
- AI Model: the model itself, self-hosted or consumed as a service, including its weights
- Training Data: datasets used to train or fine-tune models
- Runtime AI Data: prompts, responses, RAG content, and agent memory flowing through AI at runtime
- AI Agent Identities: AI agents and other non-human identities, and the credentials they act with
- Not sure
- Other (please specify)
- None of the above

## Q6. The previous two questions used a list of eight AI asset classes. How well does that list match the way your organization groups its AI security work?

Single choice, required, fixed order.

- Very well
- Mostly, with some gaps
- Only partly
- Not well. We group this work differently
- We haven't organized AI security work into categories yet
- Not sure

## Q7. What, if anything, would you change about that list of eight asset classes? A missing category, an unclear name, or categories you would split or combine.

Paragraph text, optional; description: "We will use your answers to revise the framework."

Free text. No answer options were shown.

## Q8. Who is primarily accountable for AI security decisions in your organization?

Single choice, required, fixed order.

- CISO or central security leadership
- A dedicated AI security leader or team
- Platform or engineering leadership
- Data science or AI/ML leadership
- Risk, compliance, or legal leadership
- Shared accountability with no single primary owner
- No clear accountability yet
- Not sure
- Other (please specify)
- None of the above

## Q9. Which approaches has your organization used to add AI security controls? Select all that apply.

Checkboxes, required, fixed order.

- Extended security tools or processes we already own
- Adopted AI-security-specific products
- Built controls in-house
- Relied on protections built into AI or cloud providers' offerings
- Added policies or training but no technical controls yet
- We have not added AI-specific controls yet
- Not sure
- Other (please specify)
- None of the above

## Q10. How many employees does your organization have?

Single choice, required, fixed order.

- Fewer than 100
- 100 to 999
- 1,000 to 9,999
- 10,000 or more
- Prefer not to say
