The research points to a clear theme: organizations want to embrace AI, but with a structured security approach. A practical path to a “secure yes” to AI includes four key steps:
1. Form a dedicated security team for AI
Create a focused group that brings together security, IT, data, and risk stakeholders. Their role is to:
- Understand how GenAI is being used and developed across the business.
- Identify and prioritize AI-specific risks (data leakage, hallucinations, prompt injection, etc.).
- Set policies and guardrails for AI usage, including BYOAI and third-party tools.
2. Optimize resources to secure GenAI
Align existing security capabilities with AI needs rather than starting from scratch. This typically involves:
- Extending data protection, identity, and access controls to AI workloads.
- Improving visibility into where AI apps, models, and plug-ins are running.
- Addressing shadow IT by giving employees secure, approved AI options.
3. Implement a Zero Trust strategy for AI
Apply Zero Trust principles—“never trust, always verify”—to AI systems:
- Enforce strong identity and access management for AI apps and services.
- Limit permissions and data access for AI components to what is strictly necessary.
- Continuously monitor usage and behavior for anomalies or abuse.
4. Adopt a comprehensive security solution for AI
Finally, organizations are looking at end-to-end security solutions that cover:
- Protection for prompts, responses, training data, and retrieval-augmented generation (RAG) data.
- Controls for models, orchestrators, and plug-ins across the AI stack.
- Support for regulatory compliance, including emerging AI regulations such as the EU AI Act, where violations can reach up to €35 million or 7% of annual turnover.
By following these steps, security and risk leaders can move from blocking or slowing AI initiatives to enabling them, with clearer governance and a more resilient security posture around GenAI.