When AI Invents a Software Package
Slopsquatting can turn a package name invented by AI into malicious code, but current evidence supports controls more strongly than claims of prevalence.
AI risk underwriting for institutions
AetherLab helps institutions evaluate, mitigate and underwrite AI risk. Turn technical findings into actionable evidence, apply controls where needed, and make better-informed risk decisions.
Non-Compliant· threat 0.94Compliant· threat 0.06Every AI system that touches money, customers, or regulated content has to get past someone responsible for the risk: a merchant-risk team, an underwriter, a procurement review, or an audit. Those teams need to understand the risk, determine what can be mitigated, and decide what they are willing to take on.
The result is a queue: AI products waiting on payment approval, insurance coverage, procurement sign-off, or an audit, with no shared standard of evidence between the builder and the institution. AetherLab is the infrastructure that clears that queue.
One workflow from AI risk assessment to underwriting evidence. AdversarialScan identifies what breaks, Guardrails mitigate and control the risk, and Evidence Pack turns the findings into evidence institutions can use to make underwriting decisions.
Most AI security tools stop at a list of findings. AetherLab connects each finding to its economic impact, the protection that contains it, and the measured lift after deployment. Finance can read the loop, and so can risk.
Identify the failures and vulnerabilities that matter.
Translate technical risk into exposure, consequence and severity.
Apply controls against the risks that can be addressed.
Document the risk, mitigation and remaining exposure for the underwriting decision.
Payment ecosystems, insurers, enterprise procurement, AI builders facing enterprise reviews, and platforms with real content risk. Different seats, one shared need: evidence.
If your team evaluates, deploys, or answers for AI systems, the same workflow applies. Tell us what you are reviewing.
Talk to us →Each finding connects technical risk, business impact and the controls that address it, giving underwriting teams evidence they can use in real risk decisions.
AdversarialScan tests what image models generate and what vision models understand, with the same rigor it brings to text and conversation. These are the failure modes that decide payment and platform approvals.
Every engagement starts from the failures that would be a business problem for you, whatever they are. Findings come back severity-scored by exploitability and exposure, so your team fixes what matters first.
Customers run 225+ custom policy rules, and pricing stays flat at any count. Thorough policy should not be rationed.
AdversarialScan is driven by an engine we built and keep building: it models the system under test and generates adaptive attack campaigns toward your break-goals. We do not publish the methodology. Adversaries read papers too.
Each production check returns a threat score and a written rationale, where fast classifiers return a bare number. Your logs answer "why was this blocked" before anyone has to ask.
In the field
A top 10 high risk payment processor requires AetherLab Guardrails for designated AI merchants. Customers have chosen AetherLab over Amazon Bedrock Guardrails and Hive AI.
Operating record
Built by
Verdict infrastructure sits in the critical path of customer traffic. Ours is engineered for the bad day, not the demo.
Each check is adjudicated by multiple models. No single model failure, provider outage, or bad response decides a verdict on its own.
Redundant components back each other up. When a dependency has a bad day, checks continue on the remaining layers instead of failing all at once.
AetherLab has served production traffic every hour for the last 90 days. We state that as a measured record, not as an SLA.
The question is never whether a system can break. It is how badly. Findings are severity-graded, and policies are enforceable on any data that flows through your product, AI-generated or not.
Guardrails are one pip install aetherlab away. Use check_prompt and check_media for scalar checks, or post simple items plus shared settings to the guardrail-specific batch routes for server-side bulk moderation and backfills.
curl -sS -X POST \
https://api.aetherlab.co/v1/guardrails/prompt/batches \
-H "x-api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"items": [
"historical text to screen",
"a second prompt to review"
],
"settings": {
"blacklisted_keyword": "guaranteed returns",
"reasoning_mode": "medium"
}
}'Slopsquatting can turn a package name invented by AI into malicious code, but current evidence supports controls more strongly than claims of prevalence.
Tell us what you're evaluating. AetherLab will assess the AI risk, identify what can be mitigated, and provide evidence your risk team can act on.
Leave your email and we'll walk you through what an Evidence Pack contains for your use case: severity-scored findings, business-impact mapping, and the approval record.