AI RiskDB · Intelligence behind Surface
AIRiskDB is the risk intelligence that powers Surface — over 1M AI assets across 8 categories, each scored on capability, exposure and governance. When an asset appears on an endpoint, its risk is already known, so detection is a lookup, not a research project.
mcp:postgres-prod
MCP server · AIRS profile
What AI RiskDB is
AIRiskDB is a continuously-updated database of the world's AI assets — models, agents, MCP servers, datasets, extensions and more — each carrying a risk profile expressed as an AIRS score. AIRiskDB is the SuperAlign component that delivers this intelligence to Surface and Horizon.
Because every asset is scored before it ever reaches your fleet, the platform can issue a verdict the instant an asset is observed — no analyst triage, no waiting on a research backlog.
AI assets tracked
1M+
Across 8 categories
Risk dimension
3
Capability · Exposure · Governance
Verdict on appearance
<25ms
Pre-scored, real-time
Frameworks mapped
5
Crosswalk built in
Scale and coverage
The breadth that turns discovery into recognition — most assets your fleet runs are already profiled before you deploy.
Over a million models, agents, MCP servers, datasets, tools and extensions — the long tail, not just the household names.
New assets and new behaviors are profiled continuously, so the intelligence keeps pace with a field that moves weekly.
When Surface sees an asset on an endpoint, Surface already holds its risk profile — detection is instant.
The AIRS model
Every asset is profiled on three axes. The result is a single AIRS score with the dimensions behind it — and it moves as an asset's real-world behavior changes.
AIRS score
7.4
Capability
What the asset can do and access — autonomy, tool use, code execution, data reach. The more it can do, the more a misstep costs.
Exposure
How far it reaches across systems, identities and data — its blast radius if it behaves unexpectedly or is compromised.
Governance
Its legal and policy standing — provenance, licensing, sanctioning, and alignment with the frameworks you answer to.
Static + dynamic. Static scoring captures provenance and known properties; dynamic scoring adjusts for how an asset actually behaves in the wild — so a quiet model that starts exfiltrating is re-scored, not frozen at install time.
How scoring works
The internals are SuperAlign IP — but the shape is simple: many signals are distilled into a banded score you can act on and defend to an auditor.
01 · Inputs
Provenance, capabilities, observed behavior, governance status and threat intelligence across 1M+ assets.
02 · Model
Capability, exposure and governance are scored statically and dynamically into one AIRS value.
03 · Output
A one-decimal score and band — Critical 9.0+ · High 7.0–8.9 · Medium 5.0–6.9 · Low <5.0 — mapped to frameworks.
Scoring methodology is proprietary; this shows the value flow, not the internal mechanics.
The 8 asset categories
Foundation and fine-tuned
Hosted and local LLMs, embeddings and multimodal models.
Autonomous and copilots
Goal-driven agents, coding copilots and task runners.
Tool providers
Model Context Protocol servers exposing tools and data.
Callable functions
Functions, plugins and skills an agent can invoke.
Training & retrieval
Corpora and vector stores feeding models and RAG.
Browser and IDE
AI extensions embedded in browsers and developer tools.
Gen-AI SaaS
Third-party AI applications used across the org.
Keys and service accounts
Credentials and machine identities that AI assets use.
Category names illustrative; the canonical count is 8.
Framework crosswalk
Each AIRS dimension maps to the controls you already report against — so a risk score becomes an audit artifact, not extra work.
| Framework | What AIRiskDB maps | Primary dimension |
|---|---|---|
| EU AI Act | Risk tiering and obligations for AI systems in use | Governance |
| NIST AI RMF | Map / Measure / Manage functions per asset | Capability |
| ISO/IEC 42001 | AI management system controls and evidence | Governance |
| MITRE ATLAS | Adversarial techniques an asset is exposed to | Exposure |
| OWASP LLM Top 10 | Common LLM/agent risks per asset class | Exposure |
Mappings illustrative — the crosswalk itself is maintained in AIRiskDB.
Example asset risk profiles
mcp:unknown-7f
MCP Server · Unsanctioned
cursor-agent
Coding agent · Sanctioned
llama-3-70b · local
Open model · Governed
Illustrative profiles for layout reference.
Pre-scored = real-time
Because AIRiskDB has already scored the world's assets, Horizon doesn't have to reason about an asset from scratch on the endpoint — it consults AI RiskDB and renders a verdict in <25 ms. Signal then attaches that risk context to the permanent record.
Horizon
On-device SLMs combine the live event with the Surface score to classify intent and enforce in real time.
Signal
Every incident is sealed with the asset's risk profile, so the record explains why an action was risky.
Console
Fleet risk rolls up from Surface scores into board-ready reporting and policy.
AIRiskDB · By the numbers
1M+
AI assets profiled with an AIRS score
canonical
8
Asset categories covered
canonical
3
Risk dimensions per asset
canonical
<25ms
Verdict when an asset appears
canonical
5+
Compliance frameworks crosswalked
illustrative
24h
Median time to profile a new asset
illustrative
95%
Of observed fleet assets already scored
illustrative
0
Analyst research tasks to get a verdict
by design
Canonical metrics are product commitments; figures tagged illustrative are placeholders for your design team to replace with verified data.
Use cases
01 · Procurement gating
Check any model, agent or MCP server against AIRiskDB during review — approve, restrict or reject on evidence, not vibes.
<25 ms · canonical
To a risk verdict for any asset
02 · Fleet benchmarking
Compare your fleet's AIRS distribution to the broader population to see where you carry outsized exposure.
1M+ · canonical
assets as the reference baseline
03 · Audit evidence
Export AIRS profiles mapped to EU AI Act, NIST AI RMF and ISO 42001 controls as evidence for auditors and the board.
5+ · illustrative
frameworks crosswalked
Deploy Surface and let AI RiskDB put an AIRS score on every asset it finds — then benchmark your AI risk against the world's.