Direct answer
An AI SDLC security review (also called AIDLC or AI-DLC security review) is an independent assessment of how artificial intelligence affects both your product and your development process. It examines LLM features for prompt injection and data leakage, and reviews how teams use AI coding assistants such as Copilot or Cursor — so security keeps pace with AI-assisted delivery.
What does an AI SDLC security review cover?
It typically covers two surfaces in one engagement.
AI in the product: chatbots, agents, RAG pipelines, tool-calling, fine-tuning, and model hosting. Reviewers look for prompt injection (direct and indirect), insecure output handling, over-privileged tools, weak tenant isolation in embeddings or memory, and retention of prompts in provider logs.
AI in the SDLC: coding assistants, agentic workflows, MCP or IDE integrations, and policy for what source code or secrets may enter AI tools. The goal is practical governance — not banning tools that engineers already use.
Which standards and frameworks apply?
Useful anchors include the OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework themes, and the UK Code of Practice for the Cyber Security of AI (DSIT / NCSC). A good review maps findings to these references so product, security, and legal stakeholders share a common language.
When should a team commission one?
Commission an AI SDLC review when you are shipping customer-facing LLM features, connecting models to internal tools or data, rolling out coding assistants org-wide, or preparing for customer security questionnaires that ask about AI. It is most valuable before patterns harden into production debt — not only after an incident.
What outputs should you expect?
Expect a prioritised findings list with evidence, a threat-informed view of AI trust boundaries, concrete control recommendations (prompt/output handling, retrieval filtering, tool allow-lists, coding-assistant policy), and a short roadmap. Sample depth is illustrated in our fictional threat model and executive summary examples.
Related service
If you need this work delivered, see AI SDLC Security Review or start a conversation.