Scope and threat model.
We sit down with you and map what the AI system actually does, what data it touches, what actions it can take, and where things would hurt your business if they went wrong. We agree on what is in scope and what is off-limits. The output is a short written threat model that everyone signs off on before any testing begins.