AI Model Risk Assessment
Score any AI model — including Chinese and open-weight models — before you send it real data. Answer eight questions about how the model is built, hosted, and governed. The tool returns a risk band and the exact controls that lower it.
Answer the questions to score the model
How to read your risk band
This tool screens one model, in one configuration, against the factors that decide whether it is safe for your data. A low band means the setup is defensible with standard controls. An elevated band means the model is usable, but only once the listed mitigations are in place. A high band means the current setup — often a foreign hosted API touching regulated data — should change before you deploy it.
The single biggest lever is the access path. Self-hosting an open-weight model keeps prompts inside your own environment and removes the data-residency and training concerns that come with a hosted API. For the full picture on Chinese and open-weight models, read our Chinese AI model security risks guide.
Want a second opinion on a specific model?
Tell us the model you are weighing and the data you want to run through it. We will map it to your industry rules and hand back a safe, workable setup — or a better-fit alternative.
Book a ConsultationFrequently Asked Questions
- Screen the model on provenance, access path, data residency, training terms, data sensitivity, compliance coverage, and whether you can self-host. This tool scores those factors into a Low, Elevated, or High risk band and lists the specific controls that lower your risk. Use it as a first-pass screen, then confirm the details in the provider contract.
- Chinese AI models can be safe for non-sensitive work, and self-hosting the open weights in your own environment is a real mitigation. The main concern is the hosted API: a China-based provider falls under Chinese law, so sending regulated or client-confidential data to it raises data-jurisdiction risk. This tool flags that combination and points you to safer configurations.
- The highest-risk pattern is sending regulated data to an overseas hosted API that trains on your prompts and offers no BAA, SOC 2, or DPA. Risk drops fast when you self-host open weights, keep data in your own region, and get a written no-training commitment. The score reflects how many of those safeguards are missing.
- Self-host the open weights in your own cloud or on-premise environment so prompts never leave your control. Add access logging, prompt filtering, and a human review step for high-stakes actions. Self-hosting removes the data-residency and training concerns that come with a foreign hosted API, which is why open weights score lower risk in this tool.
- Yes. Self-hosting keeps your data inside your own jurisdiction and infrastructure, which removes the cross-border and training-on-your-data concerns of a hosted API. You still own the operational security, so add logging, patching, and access controls. For regulated data, self-hosting is often the cleanest path to a defensible compliance posture.
This tool provides a general risk screen to help you evaluate AI models and is not legal advice. Always confirm data terms, certifications, and cross-border rules with a qualified professional before deploying a model on business data.