AI RiskDB · Intelligence behind Surface

Every AI asset in the world, pre-scored for risk.

AIRiskDB is the risk intelligence that powers Surface — over 1M AI assets across 8 categories, each scored on capability, exposure and governance. When an asset appears on an endpoint, its risk is already known, so detection is a lookup, not a research project.

mcp:postgres-prod

MCP server · AIRS profile

7.8
Capability8.6 high
Exposure7.4 high
Governance6.9 medium
EU AI ActNIST AI RMFISO 42001static + dynamic

What AI RiskDB is

The reference intelligence
for AI risk.

AIRiskDB is a continuously-updated database of the world's AI assets — models, agents, MCP servers, datasets, extensions and more — each carrying a risk profile expressed as an AIRS score. AIRiskDB is the SuperAlign component that delivers this intelligence to Surface and Horizon.

Because every asset is scored before it ever reaches your fleet, the platform can issue a verdict the instant an asset is observed — no analyst triage, no waiting on a research backlog.

AI assets tracked

1M+

Across 8 categories

Risk dimension

3

Capability · Exposure · Governance

Verdict on appearance

<25ms

Pre-scored, real-time

Frameworks mapped

5

Crosswalk built in

Scale and coverage

1M+ assets. 8 categories. One score.

The breadth that turns discovery into recognition — most assets your fleet runs are already profiled before you deploy.

Breadth

Over a million models, agents, MCP servers, datasets, tools and extensions — the long tail, not just the household names.

Freshness

New assets and new behaviors are profiled continuously, so the intelligence keeps pace with a field that moves weekly.

Recognition

When Surface sees an asset on an endpoint, Surface already holds its risk profile — detection is instant.

The AIRS model

Three dimensions, scored statically and dynamically.

Every asset is profiled on three axes. The result is a single AIRS score with the dimensions behind it — and it moves as an asset's real-world behavior changes.

AIRS score

7.4

Composite of 3 axes
Axis 01

Capability

What the asset can do and access — autonomy, tool use, code execution, data reach. The more it can do, the more a misstep costs.

Axis 02

Exposure

How far it reaches across systems, identities and data — its blast radius if it behaves unexpectedly or is compromised.

Axis 03

Governance

Its legal and policy standing — provenance, licensing, sanctioning, and alignment with the frameworks you answer to.

Static + dynamic. Static scoring captures provenance and known properties; dynamic scoring adjusts for how an asset actually behaves in the wild — so a quiet model that starts exfiltrating is re-scored, not frozen at install time.

How scoring works

Signals in, a defensible score out.

The internals are SuperAlign IP — but the shape is simple: many signals are distilled into a banded score you can act on and defend to an auditor.

01 · Inputs

Signals

Provenance, capabilities, observed behavior, governance status and threat intelligence across 1M+ assets.

02 · Model

AIRS scoring

Capability, exposure and governance are scored statically and dynamically into one AIRS value.

03 · Output

Banded verdict

A one-decimal score and band — Critical 9.0+ · High 7.0–8.9 · Medium 5.0–6.9 · Low <5.0 — mapped to frameworks.

Scoring methodology is proprietary; this shows the value flow, not the internal mechanics.

The 8 asset categories

Every kind of AI asset, classified and scored.

Models

Foundation and fine-tuned

Hosted and local LLMs, embeddings and multimodal models.

Agents

Autonomous and copilots

Goal-driven agents, coding copilots and task runners.

MCP servers

Tool providers

Model Context Protocol servers exposing tools and data.

Tools and skills

Callable functions

Functions, plugins and skills an agent can invoke.

Datasets

Training & retrieval

Corpora and vector stores feeding models and RAG.

Extensions

Browser and IDE

AI extensions embedded in browsers and developer tools.

AI services

Gen-AI SaaS

Third-party AI applications used across the org.

Identities

Keys and service accounts

Credentials and machine identities that AI assets use.

Category names illustrative; the canonical count is 8.

Framework crosswalk

Risk that doubles as compliance evidence.

Each AIRS dimension maps to the controls you already report against — so a risk score becomes an audit artifact, not extra work.

FrameworkWhat AIRiskDB mapsPrimary dimension
EU AI ActRisk tiering and obligations for AI systems in useGovernance
NIST AI RMFMap / Measure / Manage functions per assetCapability
ISO/IEC 42001AI management system controls and evidenceGovernance
MITRE ATLASAdversarial techniques an asset is exposed toExposure
OWASP LLM Top 10Common LLM/agent risks per asset classExposure

Mappings illustrative — the crosswalk itself is maintained in AIRiskDB.

Example asset risk profiles

What a scored asset looks like.

mcp:unknown-7f

MCP Server · Unsanctioned

9.1
Capability9.0
Exposure9.0
Governance7.0
CriticalBlock

cursor-agent

Coding agent · Sanctioned

6.1
Capability5.0
Exposure2.0
Governance5.0
MediumWarn

llama-3-70b · local

Open model · Governed

3.2
Capability2.0
Exposure2.0
Governance2.0
LowAllow

Illustrative profiles for layout reference.

Pre-scored = real-time

Turns detection into a lookup.

Because AIRiskDB has already scored the world's assets, Horizon doesn't have to reason about an asset from scratch on the endpoint — it consults AI RiskDB and renders a verdict in <25 ms. Signal then attaches that risk context to the permanent record.

Horizon

On-device SLMs combine the live event with the Surface score to classify intent and enforce in real time.

Signal

Every incident is sealed with the asset's risk profile, so the record explains why an action was risky.

Console

Fleet risk rolls up from Surface scores into board-ready reporting and policy.

Verdict path<25 ms
1Surface observes asset on endpoint
2AI RiskDB lookup → AIRS 8.48.4
3Horizon classifies + enforcesWarn
4Signal seals the recordSealed
No research project — the score already exists

AIRiskDB · By the numbers

1M+

AI assets profiled with an AIRS score

canonical

8

Asset categories covered

canonical

3

Risk dimensions per asset

canonical

<25ms

Verdict when an asset appears

canonical

5+

Compliance frameworks crosswalked

illustrative

24h

Median time to profile a new asset

illustrative

95%

Of observed fleet assets already scored

illustrative

0

Analyst research tasks to get a verdict

by design

Canonical metrics are product commitments; figures tagged illustrative are placeholders for your design team to replace with verified data.

Use cases

What teams do with AIRiskDB.

01 · Procurement gating

Score AI before it's approved

Check any model, agent or MCP server against AIRiskDB during review — approve, restrict or reject on evidence, not vibes.

<25 ms · canonical

To a risk verdict for any asset

02 · Fleet benchmarking

Benchmark your AI risk against the world

Compare your fleet's AIRS distribution to the broader population to see where you carry outsized exposure.

1M+ · canonical

assets as the reference baseline

03 · Audit evidence

Turn scores into compliance artifacts

Export AIRS profiles mapped to EU AI Act, NIST AI RMF and ISO 42001 controls as evidence for auditors and the board.

5+ · illustrative

frameworks crosswalked

Score your fleet's AI in 15 minutes.

Deploy Surface and let AI RiskDB put an AIRS score on every asset it finds — then benchmark your AI risk against the world's.

Book a demo