AIES: An Open Standard for Measuring Organizational AI Exposure
Abstract
This paper presents the methodology behind AIES v1.0, an open standard for measuring organizational AI exposure. AIES defines exposure as a measurable surface across seven dimensions: External AI Exposure (EAE), Internal AI Exposure, Inferred (IAE), Third-Party AI Exposure (TPE), Agentic AI Exposure (AAE), Data and Privacy AI Exposure (DPE), Governance Exposure (GVE), and Regulatory Exposure (RGE). Each dimension is rated on a 0 to 100 scale and combined through a weighted composite formulation with bounded cross-dimension amplification for compound-exposure patterns. Composites are percentile-normalized against a peer cohort and assigned to five equal-interval tiers (T1 through T5). The methodology contribution is fourfold: (1) a formal definition of AI exposure as a compositional construct rather than an aggregate score; (2) a seven-dimension decomposition designed to be jointly exhaustive and analytically tractable; (3) a signal-sourcing and provenance discipline (the "public-signal doctrine") that governs what evidence can enter a rating; and (4) a calibration methodology anchored to a scored-incident corpus with AUC-ROC as the primary validation metric. Section 9.4 positions AIES against COSO ERM, ISO 31000, NIST AI RMF, ISO/IEC 42001, MITRE ATLAS, OWASP LLM Top 10, and cybersecurity rating services, and identifies the standard's distinctive contribution as an entity-level, peer-normalized, AI-specific exposure position calibrated against a scored-incident corpus. The paper accompanies the AIES v1.0 open standard (DOI: 10.5281/zenodo.21633110) and the AI Exposure Glossary v1.0 (DOI: 10.5281/zenodo.21731199), together forming the AIES publication family. All three artifacts are released under CC BY 4.0.
// Source
Authors: AI Security Intelligence Standards Team
Institutions: Global Security Intelligence (United Kingdom)