Blast Radius
What a successor, or an attacker, could reach by pivoting from a single compromised access path into other systems it was never meant to touch; documenting access one system at a time misses it, so the briefing notes, for each high-criticality system, which other systems its access paths can reach.
Defined in 5 GAGE programs, which carry 35 distinct definitions of it. The wording above is taught in AI Governance: Applied Mastery.
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
In this topic's discovery method, a qualitative judgment of how much harm would result if a given system, store, or dataset were compromised, deleted, or found to be wrong, used to set a concern flag independent of how visible or well documented the finding already is. A full quantitative blast-radius analysis, tracing exactly which downstream systems a change would break, is Topic 2.3's owned scope.
What a successor, or an attacker, could reach by pivoting from a single compromised access path into other systems it was never meant to touch; documenting access one system at a time misses it, so the briefing notes, for each high-criticality system, which other systems its access paths can reach.
The scope of harm a single failure could cause given the current phase's restrictions. A well-designed phase one is engineered so that its worst plausible failure has a small blast radius, contained by structural restrictions on the three levers, not merely by hope or by monitoring alone.
The total set of data and actions a manipulated AI could reach; the thing least privilege exists to shrink. The everyday user's key prevention question is "if this AI were following an attacker's instructions, what could it reach?"
The scope of impact when a failure occurs. Containing blast radius (via canary releases, feature flags, and workload isolation) keeps a small failure small; the 2024 CrowdStrike outage is the classic example of an uncontained one.
Where it is taught
The exact lessons this term appears in. The first 7 topics of every program are free with a free account.
- Risk Assessment in AI Decisions · Critical Thinking and Context Engineering, AI Literacy & Professional Conduct
- Basic AI Experimentation with No-Code Tools · Advanced AI Literacy, AI Literacy & Professional Conduct
- When to Delegate to AI Agents vs. Handle Tasks Yourself · Agentic AI and Workforce Integration, AI Literacy & Professional Conduct
- Prompt Injection and Jailbreak Defense · AI Security Fundamentals, AI Literacy & Professional Conduct
- Securing Agent Permissions and Access Boundaries · AI Security Fundamentals, AI Literacy & Professional Conduct
- Agent Governance at Enterprise Scale · Bonus: AI Leadership Accelerator, AI Literacy & Professional Conduct
- Systemic Risk · The Agent, Deconstructed, Agentic AI Governance: Applied Mastery
- The New Risk Factors · Capability and Autonomy, Agentic AI Governance: Applied Mastery
- Containing Third-Party Agents · Bounding by Design, Agentic AI Governance: Applied Mastery
- Ship the Agent in Stages, Never All at Once · Rollout, Monitoring, and Incident Response, Agentic AI Governance: Applied Mastery
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.