Pick a risk in your stack, whether it lives in the input, output, model, infrastructure, or agentic layer, and see which controls apply across OWASP, MITRE, and the major compliance frameworks. These are the same risks Nemesis tests for.
The five layers of AI security. Input covers what reaches the model, including prompts, RAG context, and files. Output covers what the model returns and how it gets handled downstream. Model covers the model itself along with its training and embedding data. Infrastructure covers the API, keys, hosting, and rate limits around it. Agentic covers the tools, autonomy, and multi-step actions an agent can take.