Step 1: Conduct risk assessment focused on AI security risks
Is this legally binding?
Guidance. Voluntary guidance. Best practice, not obligation, until a contract or a regulator cites it.
Conduct a risk assessment focusing on security risks related to AI systems, based on best practices or the organisation's existing enterprise risk framework; may reference CSA's cyber threat modelling and CII risk assessment guides.
What this connects to
1 relations. Official relations are the ones the source documents state; anything marked GAGE analysis is our reading, not an agency's.
Mapped across from1
- ObligationStep 1: Conduct a risk assessment focused on agentic AI security risksGuidance
Addendum Step 1 extends the Guidelines' risk assessment with autonomy, threat modelling and capability analysis
Verified against the official source on 2026-08-17. GAGE is not affiliated with or endorsed by any agency named here, and nothing on this page is legal advice. How this is built and checked.