Treat models as capability in recon, malware-assist, and vendor tool-use, then give the board questions, evidence, and a 90-day program that does not require a new platform religion.
One PDF board pack for a 30-minute slot. Cheap models and agent tool-use as an operations problem and a supply-chain problem.
This is not a chatbot acceptable-use policy. Staff chatting with a bot is a small slice of the problem, and it is the slice most enterprises have already memo'd. The real issue is operational. Cheap models lower the cost of targeting your people, your facilities, and your vendors. They assist less-skilled actors with malware and tradecraft at a high level you already understand. Agents that can invoke tools (mail, tickets, code, IdP admin, badge APIs) change what "a user" means on your identity plane.
Your MSSP, coding shop, facilities vendor, and marketing agency are already using models on their workflows. Some of those workflows touch your data, your site maps, or your tickets. That is supply chain. It sits inside the boundary. Contracts, logging, data handling, and whether their agents can touch your IdP or SOAR are CISO issues, not innovation-office issues.
The pack is written for a 30-minute board slot. It uses the same Vendor SSO to Facility Access story the Practical Security Kit tabletops, including the optional path where a cheap external model reconned the vendor's people and the site. Identity-as-Perimeter Briefs explain how a stolen session becomes a door. This pack explains how models make that path cheaper, and how your own agents can become the path if nobody constrains tool-use.
Practical security. Enable the business. Do not ban the future. Constrain what an agent may invoke, keep a human in the loop on people and sites, and degrade without the model when it lies.
A 30-minute board-slot clock. Who speaks. What not to do.
Cheap models, agents with tools, vendors on your data.
People, facilities, vendor org charts, OPSEC. Malware and offensive assist at a high level, no recipes. What an agent may invoke versus a chatbot memo.
Vendors using models on your data and sites. MSSP, coding shop, facilities, marketing.
What a good answer looks like. Logging and constraint, mapped lightly to CSF Detect / Respond and to identity. Models fail, hallucinate, and get prompt-injected. Diversity is not redundancy.
Five to seven moves a CISO can staff, plus an appendix that points back to the Kit tabletop and the identity briefs.
CSO/CISOs who have to brief a board that has read a newspaper. CROs. GSOC leads who will be asked to "monitor AI." Security directors who already suspect the facilities vendor's dispatcher is using a public model on work orders.
Teams shopping for a model-safety vendor. Legal teams who need a full acceptable-use policy (write that elsewhere, keep it short, do not confuse it with this pack). Data-science groups who want an LLM architecture review. Anyone looking for exploit steps, jailbreak recipes, or malware coaching. This pack will not provide them.
The Practical Security Kit rehearses the first hour and includes an inject where recon-via-model makes a fake work order look right. Identity-as-Perimeter Briefs are the identity plane those tools and stolen sessions ride. This pack is the board's view of models as capability and as third-party risk. Tabletop roles, terms, and failure modes are the same on purpose. KPIs you brief from the Kit (time to shared picture, vendor access, identity blast radius) are the measures. Do not invent an "AI risk score" to sit beside them.
Turn the operating model into something you can run on Monday: who has authority in the first hour, what a CSO briefs, and a tabletop that crosses cyber, physical, personnel, and a preferred vendor.
If digital compromise can become a badge, a vendor on site, or a muted door, these six pages show the identity seams that made it possible, and the questions to ask on Monday.