Skip to main content
NexITC
A9 · AI · 2–3 WEEKS · ASSESS

Adversarial testing by hand.
Not a scanner report.

A9 · AI Safety & Red-Teaming Sprint™ attacks your deployed or pre-production AI system by hand for 2–3 weeks and returns the findings your board needs before someone else finds them. Prompt injection, jailbreaks, data exfiltration through the model, tool-abuse paths on agentic systems, and harmful-output classes tested against your actual deployment — not a benchmark suite.

DURATION
2–3 wks
DELIVERABLES
6 named
COMMERCIAL
Fixed fee
A9·PROJECTION / OPEN CRITICAL FINDINGS
A9
BEFORE
12
UNKNOWN · UNTESTED PATHS
A9
AFTER
0
CRITICALS OPEN AT HANDOVER
WK 00
WK 01
WK 02
WK 03
CLOSED
ATTACK CLASSES
8+
FINDINGS
REPRODUCIBLE
CRITICALS OPEN
0
SCENARIO · UAE FEDERAL ENTITY · N=1
ILLUSTRATIVE
§ 00 · THESIS
01
WHY AI SAFETY REVIEWS
MISS WHAT ACTUALLY BREAKS.

Most AI safety work in UAE enterprises today is a policy document, a vendor attestation, and a scanner run against a public payload corpus. None of those things have touched the system as deployed. The assistant that will leak another customer's record does it through your retrieval corpus, not through a benchmark. The agent that will spend beyond its envelope does it through your tool chain, not through a jailbreak from a public list. The failure is specific to how you wired it.

The instinct is to buy a scanner and file the report. That instinct produces a clean report and an unchanged risk. A9 attacks the actual system by hand for two to three weeks — prompt injection through the surfaces your users touch, exfiltration through the corpus you indexed, tool abuse and approval-gate bypass on the agents you deployed, harmful-output classes in the languages your users actually write in. Every finding is reproducible, severity-rated, and paired with a named remediation. The alternative to knowing is a screenshot on social media as the first evidence — and by then the board conversation is no longer about engineering.

STATE · ATTESTED
Policy filed. Vendor attestation on record. Scanner run green. No one has attacked the deployed system on your data, in your languages, through your tools.
STATE · TESTED
Attack surface mapped. Findings reproducible and severity-ranked. Criticals closed and re-tested. Regression pack running on every release.
§ 01 · WORK STREAMS

Six streams,
ending in findings that reproduce.

Scoping, rules of engagement, and surface mapping front-load week 1. Manual attack execution runs through week 2. Remediation planning, re-test, and readout close week 3.

STREAM 01
WK 01

Rules of engagement & surface map

Environment, data sensitivity, blast radius, and stop conditions signed before a single payload is sent. Attack surface mapped across UI, API, retrieval corpus, and tool chain.

STREAM 02
WK 01–02

Prompt injection & jailbreak

Direct and indirect injection through every surface a user or a document can reach, in English and Arabic. System-prompt extraction and instruction override tested against the live configuration.

OUTCOME
0
CRITICALS OPEN
+ REGRESSION PACK OWNED
STREAM 03
WK 02

Data exfiltration paths

Cross-tenant and cross-entitlement retrieval, PII leakage through the indexed corpus, and inference-time disclosure of records the caller is not entitled to see.

STREAM 04
WK 02

Tool abuse & agent control

Tool-invocation abuse, privilege escalation via chained calls, approval-gate bypass, unbounded loops and spend, and whether kill switch and rollback function under load.

STREAM 05
WK 02–03

Harmful output & refusal integrity

Harmful-output classes relevant to your sector and jurisdiction, refusal-boundary consistency, and over-refusal on legitimate requests — safety that blocks the business is also a finding.

STREAM 06
WK 03

Remediation, re-test & readout

Severity-ranked plan with named owners, critical fixes re-tested inside the window, regression pack handed to your team, and a direct readout to the risk committee.

EXPLICITLY NOT COVERED
Building the guardrails
A9 names and sizes the remediation and re-tests the criticals. Engineering the guardrail layer, evaluation harness, or AgentOps controls runs through the relevant build engagement.
Conventional infrastructure penetration testing
A9 tests the AI system — model, prompts, corpus, tools, agents. Network and infrastructure penetration testing sits with the cybersecurity portfolio, not here.
Continuous evaluation after handover
The regression pack is designed for your team to run every release. Where that needs to be operated for you, C2 CoE-as-a-Service™ takes it on.
§ 02 · TIMELINE

Three weeks maximum.
Two minimum. Three phases.

Phase count is fixed. Duration flexes with attack surface, environment access, and agent complexity. Milestones are signed gates — not aspirations.

WK 01WK 02WK 03Phase 1 · RoE & surface mapPhase 2 · Attack executionPhase 3 · Remediation & re-testRoE signed · surface mappedEND WK 01 · GATE 01Findings reproducedEND WK 02 · GATE 02Criticals closed · pack handed overEND WK 03 · GATE 03OPERATING RHYTHMDaily standup · Same-day critical disclosure · Practice Lead present at each gateNAMED ACCOUNTABILITYPractice Lead — AI (CEO escalation available)
§ 03 · METHODOLOGY

The sprint,
run on attacks not attestations.

Every A9 engagement follows a fixed methodology tuned to your deployment in the first three days. Not a questionnaire; not a corpus replay. The sequence that produces reproducible findings a risk committee and an engineer can both act on.

METHODOLOGY · SIX STEPS
SEQUENCED · GATED · REPRODUCIBLE
This is the methodology applied on every A9 engagement — adapted to your deployment pattern, languages, and agent topology, not reinvented per engagement.
01
Rules of engagement signed first
Environment, data sensitivity, blast radius, escalation contacts, and stop conditions agreed and signed before the first payload. Same-day disclosure for anything critical, regardless of sprint phase.
02
Attack surface mapping against the real deployment
Every surface a user, a document, or an upstream system can reach — UI, API, retrieval corpus, ingestion paths, tool chain, and agent memory. Mapped from the deployment, not the architecture diagram.
03
Automated baseline sweep
Known-payload tooling run first to clear the obvious and set a floor. This is the least valuable part of the sprint and we treat it as such — it exists so manual time is spent where tooling cannot reach.
04
Manual adversarial execution
Adversarial testing by hand against your actual system, in the languages your users write in, using your data shapes and your entitlement model. This is where the material findings come from and where the majority of sprint hours go.
05
Reproduction and severity rating
Every candidate finding reproduced at least twice before it enters the log, with exact input sequence, environment, and timestamp. Severity rated against impact and reachability, with the reasoning written down. Unreproducible behaviour goes to observations, not findings.
06
Remediation plan, re-test, regression handover
Named remediation per finding with effort sizing and owner. Criticals re-tested inside the sprint window. Regression pack handed to your team so the same attacks run on every future release.
!
DISCLOSURE · INDEPENDENCE
A9 is an assessment, not a guardrail-product sale. NexITC has no vendor economics riding on the findings and no obligation attached to the remediation plan — your team or another party can execute it. We do not pad severity counts to justify the engagement, and we report over-refusal and safety theatre as findings alongside exploitable weaknesses.
§ 04 · EVIDENCE PACK

From attested safe
to tested and closed.

A typical pre-engagement state has a policy, a vendor attestation, and a green scanner report — against a system nobody has attacked. The engagement produces the evidence pack under a risk position the board can actually hold.

WITHOUT · T=0
TYPICAL STATE
STATE_01
AI usage policy filed
NOT TESTED
STATE_02
Vendor safety attestation
THEIR SYSTEM · NOT YOURS
STATE_03
Scanner run green
PUBLIC PAYLOAD CORPUS
STATE_04
Agent tool access unbounded
NO APPROVAL GATE TEST
DECISION QUALITY
Attestation + green scan + hope that nobody looks harder than the scanner did
OPERATIONAL REALITY
  • Indirect injection through indexed documents never tested
  • Cross-entitlement retrieval unverified against the real corpus
  • Kill switch and rollback never exercised under load
  • First evidence of failure arrives as a screenshot on social media
A9 · ATTACK
WITH · POST-HANDOVER
TARGET-STATE
PLATFORM_01
Reproducible Finding Log & Severity Model
Exact Payloads · Environment · Twice-Reproduced · Rated with Reasoning
PLATFORM_02
Remediation Plan & Regression Pack
Owners · Effort Sizing · Criticals Re-Tested · Release-Gate Test Suite
↓ MAPPED · ATTACKED · REPRODUCED · CLOSED ↓
EXISTING DEPLOYMENT · UNCHANGED BY TESTING
Testing is bounded by signed rules of engagement with stop conditions and same-day critical disclosure
STEADY-STATE OUTCOME
  • Zero critical findings open at handover
  • Every finding reproducible by your own engineers
  • Agent tool access, approval gates, and kill switch verified
  • Regression pack running on every release, owned internally

Reference pattern. Some engagements return few exploitable findings and several over-refusal findings — a system that is safe and unusable is also a reported outcome. We do not manufacture severity to justify the sprint.

§ 05 · REPRESENTATIVE SCENARIO

A UAE federal entity,
agent assistant attacked.

Representative pattern for a UAE federal entity of this scale — a citizen-facing assistant with tool access, live for four months, never adversarially tested. Ranges reflect target outcomes NexITC underwrites in scope for this class of engagement. N=1 — illustrative composite, not a specific client.

SCENARIO / A9 / UAE FEDERAL ENTITY · AGENTIC ASSISTANT
DURATION · 03 WKS
FINDINGS LOGGED
17
All reproduced at least twice
CRITICAL FINDINGS
30
Closed and re-tested in-sprint
REGRESSION PACK
OWNED
Running on every release within 30 days
SITUATION

A UAE federal entity had a citizen-facing assistant live for four months with tool access to a case-management system and a document corpus spanning multiple service lines. Safety assurance consisted of a vendor attestation and a quarterly scanner run. No adversarial testing had been performed against the deployment, and the Agentic AI Mandate control expectations had not been evidenced.

ENGAGEMENT

3-week A9. Week 1 rules of engagement signed against a production-parity environment and surface mapping across web, API, ingestion, and the tool chain. Week 2 manual adversarial execution in English and Arabic — indirect injection through the indexed corpus, cross-entitlement retrieval, tool-invocation abuse, and approval-gate bypass. Week 3 severity rating, remediation planning with named owners, critical re-test, and risk-committee readout.

OUTCOME

Seventeen findings logged, all reproduced. Three criticals: indirect injection through an uploaded document class that reached the case-management tool, cross-entitlement retrieval on a legacy corpus segment, and an approval gate the agent could bypass through a chained call. All three closed and re-tested inside the window. Mandate control mapping evidenced for the federal checkpoint. Regression pack adopted into the release gate within 30 days.

§ 06 · DELIVERABLES

Six artifacts,
each with signed acceptance.

Every deliverable has documented acceptance criteria signed at engagement kickoff. Nothing more, nothing less.

D_01

Rules of Engagement & Attack Surface Map

Signed scope, blast radius, stop conditions, and escalation contacts — with every reachable surface mapped from the deployment rather than the architecture diagram.

D_02

Reproducible Finding Log

Every finding with exact input sequence, observed output, environment, timestamp, and twice-verified reproduction. Unreproducible behaviour is filed as observations, not findings.

D_03

Severity & Reachability Model

Severity rated on impact and reachability with the reasoning written down, so your risk committee can challenge the rating rather than accept a colour.

D_04 · CORE

Agentic Control Assessment

Tool abuse, privilege escalation via chained calls, approval-gate bypass, spend and loop bounds, kill switch and rollback under load — mapped to UAE Agentic AI Mandate control expectations.

D_05

Remediation Plan

Named remediation per finding with owner and effort sizing, ordered by severity and reachability. Executable by your team or another party — no dependency on NexITC.

D_06 · GATE-READY

Regression Test Pack

The attack set that found your findings, packaged for your team to run on every release — payloads, expected refusals, entitlement probes, and agent-control assertions. Designed to be owned internally on day one rather than to create a retainer dependency. The pack your release gate runs without us, and the one your auditor accepts as evidence that safety coverage did not decay after the sprint closed.

HANDOVER
WK 03
§ 07 · OUTCOMES

Six outcome metrics,
measured pre and post.

Success is not "the red team happened." It is measured against six specific outcomes captured at engagement start and re-measured at handover and the 30-day check-in.

THE CRITICAL-CLOSURE JOURNEY · REPRESENTATIVE
Twelve unknown paths to zero open criticals.
0CRITICALS OPEN
12963012Unknown pathsPRE-ENGAGEMENT12Surface mappedEND WK 015Criticals triagedEND WK 020Criticals closedHANDOVER
01 · CRITICALS OPEN
0
Zero critical findings open at handover, each re-tested in-sprint.
02 · REPRODUCIBILITY
100%
Every logged finding reproduced at least twice before entering the log.
03 · ATTACK CLASSES
8+
Injection, exfiltration, tool abuse, refusal integrity and more, tested by hand.
04 · DISCLOSURE
SAME-DAY
Critical findings disclosed the day they are confirmed, not at readout.
05 · REGRESSION PACK
OWNED
Adopted into your release gate and run by your team within 30 days.
06 · MANDATE MAPPING
EVIDENCED
Agent controls mapped to UAE Agentic AI Mandate expectations for federal entities.
§ 08 · FIT

Honest scoping.

A9 is a fit when specific conditions are met. It is not a fit when other conditions are — and "there is nothing deployed yet to attack" is a legitimate not-a-fit answer we surface before scoping, not after.

PREREQUISITES
Move fast when these five conditions are in place at kickoff.
01
A deployed or production-parity AI system

Testing runs against a real deployment. A design document or a vendor demo cannot be attacked, and testing a materially different staging build produces coverage nobody should rely on.

02
Authority to sign rules of engagement

An accountable owner must sign scope, blast radius, and stop conditions. Without that signature the sprint cannot start on day one.

03
Engineering contact available for reproduction

Findings are reproduced with your team present where possible. An engineer reachable within the day keeps critical disclosure from stalling.

04
Tool and entitlement inventory available

On agentic systems, the tool chain and entitlement model must be documented or discoverable. Undocumented tool access extends Phase 1.

05
Appetite to act on critical findings inside the window

Re-test is part of the sprint. If remediation cannot be scheduled inside three weeks, criticals close after handover and the outcome metric changes accordingly.

NOT SUITABLE IF
Four patterns indicate a different engagement is a better fit.
Nothing is built yet

That's A5 AI Use-Case Due Diligence™ — feasibility, data readiness, risk, and KPI baseline before build commitment.

You need the guardrail layer engineered

A9 finds and sizes; it does not build. Guardrail engineering runs through the relevant build engagement or C2 CoE-as-a-Service™.

You need network or infrastructure penetration testing

A9 tests the AI system specifically. Conventional penetration testing belongs in the cybersecurity portfolio.

You need an attestation letter rather than findings

Hard scope conversation. A9 produces findings and a remediation plan, not a certificate. If a certificate is the requirement, we will say so rather than sell the sprint.

§ 09 · COMMERCIAL

Fixed fee.
Milestone-based. No surprises.

Every A-tier engagement is scoped and priced upfront against defined deliverables. Milestones tied to signed gates. Change orders negotiated through the Practice Lead, not surfaced as invoice surprises.

COMMERCIAL MODEL
ENGAGEMENT MODEL
Fixed fee, milestone-based
PAYMENT SCHEDULE
Milestone-based

Payment schedule aligned to engagement phases and defined delivery milestones agreed upfront.


INCLUDED IN SCOPE
  • All 6 named deliverables with acceptance criteria
  • Weekly executive sponsor review
  • Practice Lead present at every phase gate
  • Executive readout at handover
  • Evidence pack and stakeholder map
  • 30/60/90-day post-handover check-ins
01

Scoped upfront

No hourly billing. No open-ended scope. Everything priced against deliverables signed at kickoff.

02

Milestone-gated

Payment tied to phase gates, not calendar. If a gate slips, invoicing slips with it.

03

Change orders authorised

Practice Lead has authority to negotiate scope amendments in the same conversation, not through a separate commercial cycle.

§ 10 · QUESTIONS

Five, most asked.

Q_01How is this different from an automated LLM security scanner?

A scanner runs a fixed corpus of known payloads and produces a report. A9 is adversarial testing by hand against your actual system — your prompts, your retrieval corpus, your tools, your data, your users.

The findings that matter are almost never in the payload corpus; they are in the specific way your system was wired. We run automated tooling as a baseline sweep, then spend the majority of the sprint on manual attack paths the tooling cannot reach.

Q_02Do you test agentic systems and tool access?
Yes, and on agentic deployments this is usually where the material findings are. We test tool-invocation abuse, privilege escalation through chained tool calls, approval-gate bypass, unbounded loops and spend, and whether the kill switch and rollback actually work under load. This aligns to the control expectations set out for federal entities under the UAE Agentic AI Mandate, and the findings map to those controls explicitly.
Q_03Will you test against production?
Where the risk is acceptable and a rules-of-engagement document is signed, yes — because pre-production environments routinely differ in exactly the ways that matter. Where production testing is not acceptable, we test a faithful staging deployment and mark every finding with an environment-parity note so nobody mistakes staging coverage for production assurance.
Q_04What does a finding look like?
Reproducible. Each finding carries the exact input sequence, the observed output, the environment and timestamp, the severity rating with reasoning, the affected control, and a named remediation with effort sizing. If we cannot reproduce it twice, it goes in the observations section rather than the finding log — we do not pad severity counts.
Q_05What comes after A9?
Remediation on the severity-ranked plan, then re-test. Where guardrail engineering, evaluation harnesses, or AgentOps controls need to be built, that runs through the relevant build engagement or C2 CoE-as-a-Service™ for continuous evaluation. The regression test pack A9 hands over is designed to be run by your team every release, not only by us.
§ 11 · NAMED ACCOUNTABILITY

One name.
Six accountabilities.

Specialist consulting means the person who scopes the work is the person who delivers it — with escalation to CEO on any material issue within 24 hours.

THE ROLE

Practice Lead — AI

Present at every phase gate, every scope decision, every difficult conversation. Available for 30/60/90-day post-handover check-ins as part of the engagement.

SIX ACCOUNTABILITIES
01
Commercial arrangement

Including scope amendments.

02
Deliverables acceptance

Signs off all 6 deliverables.

03
Weekly reviews

With executive sponsor.

04
Change orders

Authorised to negotiate.

05
Escalation path

CEO within 24 hours.

06
Post-handover

30/60/90-day check-ins.

§ 13 · BOOK A CLINIC

30 minutes.
One deployed system.

Bring the system you would least like to see on social media. The clinic establishes the attack surface, whether production or parity testing is feasible, what the rules of engagement would need to cover, and whether three weeks is the right shape. If your deployment is not yet testable, we will say that rather than scope around it.

CLINIC · A9
  • Attack surface and agent topology sizing
  • Environment and rules-of-engagement feasibility
  • Mandate control-mapping scope check
  • Fit assessment against alternatives
Practice Lead — AI attends every clinic.