Part III · Chapter 19

AI security

AI changes both how attacks are carried out and how they are detected, while the technology itself becomes something that needs protecting and governing. This chapter takes on all three perspectives. AI as a threat vector, AI as defence and AI as an object of regulation, together with the question most organisations find hardest to answer, which AI tools are actually in use internally.

  • CISOs and security leads

Last reviewed

The question of AI security is usually posed as if AI were a new system to protect. This chapter shows that it is broader than that, and that the hardest part is rarely the technology but knowing at all what is already going on inside your own organisation. Most operations use more AI tools than they have decided on, and the difference between those two numbers is the risk picture itself.

It opens with AI as a threat vector, how attackers use the technology to do what they were already doing, only better, cheaper and at greater scale. The gain for the attacker is rarely new capability but increased volume. Then comes AI as a defensive tool, with a sober picture of what it actually adds in detection and analysis and where the claims outrun the effect. After that come the regulatory requirements, the AI Act and its interplay with the Cybersecurity Act, an area introduced in chapter 4 on products, AI and regulation. Risk assessment for AI use gets a substantial section and is the most practical part of the chapter, followed by the security measures that can actually be taken around data, access and follow up. One section connects AI to digital sovereignty, since the models and the infrastructure often sit with a handful of actors. Another deals with what happens when a system takes decisions that have consequences for people, and where responsibility then lands. The last takes on shadow AI as the blind spot it is.

The relevance lies in the pace. AI tools are introduced into operations faster than governance can be built, and anyone waiting for the high risk requirements of the AI Act to take effect before starting will end up doing the mapping under time pressure, with tools already deeply embedded in workflows. Mapping what is actually in use is therefore the first step, and it is rarely as simple as asking.

This page shows what the chapter covers and why governance needs to catch up with use. The risk assessment, the measures and the regulatory boundaries are in chapter 19 of the book.

AI is not a separate world. It is a new lens on the same questions of control, responsibility and trust.

Key insights

  • AI is not a separate security discipline but a new lens on existing questions of control, responsibility and trust.
  • The main AI gain for attackers is scalability. Convincing and personalised attacks can now be produced in volume.
  • Obligations under the AI Act follow the risk level of the use, which makes mapping the use the first step.
  • Shadow AI is the rule rather than the exception. Tools are used in the business long before anyone has decided on them.
  • When an AI system takes a decision, responsibility for that decision must still land on a human being.

Tools that belong to this chapter

The templates and interactive tools are in the Toolbox, free of charge.

Read on

Next step

Where does your organisation stand?

The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.