FireTail's AI Findings

Updated: July 30, 2026

FireTail’s Findings feature enables the detection of critical AI security issues and aligns with best practices from leading AI security and governance frameworks, including MITRE ATLAS, ISO/IEC 42001, the OWASP Top 10 for LLM Applications, NIST SP 800-53, the EU AI Act, and the OWASP Agentic AI Top 10.

  • MITRE ATLAS - A knowledge base of adversary tactics and techniques targeting machine learning and AI systems, modeled on the MITRE ATT&CK framework.
  • ISO/IEC 42001 - The international standard for AI management systems (AIMS), setting requirements for establishing, implementing, and continually improving responsible AI governance.
  • OWASP Top 10 for LLM Applications - Outlines the most critical security risks specific to large language model applications, such as prompt injection, sensitive information disclosure, and insecure output handling.
  • NIST SP 800-53 - A catalog of security and privacy controls for information systems, used to map AI findings to established control families.
  • EU AI Act - The European Union's regulatory framework for artificial intelligence, classifying AI systems by risk and setting obligations for their safe, transparent use.
  • OWASP Agentic AI Top 10 - Identifies the top security risks introduced by autonomous, tool-using AI agents, including goal manipulation, unauthorized actions, and excessive agency.

AI security coverage

FireTail's Findings feature also includes AI Findings. The purpose of these findings is to identify risks related to AI models and their outputs. These AI Findings help detect issues such as:

  • Exposure of Personally Identifiable Information (PII) or secrets within AI logs.
  • Generation of toxic or harmful content by AI models.
  • Injection of encoded malicious payloads (e.g., Base64, Hex) in AI outputs.
  • Attempts to bypass safety controls through jailbreak prompts or prompt hijacking.
  • Production of malformed or disruptive content such as raw or escaped ANSI codes.
  • Repetition or leakage of sensitive data from AI training or logs.

How Findings are generated

Findings can be generated in the following ways:

  1. When a specification is uploaded to the FireTail platform.
  2. A GitHub repository is scanned.
  3. Through detections from logs.
  4. Through observations from active scanning.

The file, log or repository is scanned to uncover any vulnerabilities and subsequently, a finding is generated.

Refer to the individual finding pages for detailed descriptions, remediation guidance, and security framework alignment.