Artificial intelligence has become a strategic capability for companies today, regardless of the industry. Businesses have integrated generative AI, predictive analytics, copilots, and intelligent agents into their daily workflows to automate processes, interact with customers, and accelerate decision-making.
However, security is a critical aspect that requires attention. It is not merely a matter of protecting an AI model; one must also safeguard the data it consumes, the applications integrating it, the identities interacting with it, the cloud infrastructure where it operates, and the decisions it may execute.
At least 63% of the companies surveyed by IBM for the Cost of a Data Breach Report 2025 still lacked AI governance policies to manage its use or prevent the proliferation of “shadow AI”.
Furthermore, 97% of organizations that reported an AI-related security incident lacked adequate AI access controls.
This situation presents a clear picture: scaling AI without security introduces a new layer of business risk.
Table of Contents
The new security perimeter includes AI
Many traditional cybersecurity systems were designed primarily to protect applications, networks, devices, identities, and data; however, AI implementation introduces an additional layer: models capable of interpreting information, generating content, making decisions and, in the case of agents, executing actions.
In this context, the risks naturally shift for companies implementing AI solutions.
According to the OWASP Top 10 for LLM applications, new threats include prompt injection, sensitive information disclosure, supply chain vulnerabilities, data poisoning, and excessive autonomy.
Therefore, AI security cannot be limited to simply adding a filter at the end of the development process; it must be incorporated from the design stage and maintained throughout the system’s entire lifecycle.
AI governance: the first security control
AI governance is the primary factor to consider when ensuring security.
A robust AI governance plan defines who may use AI, the applicable use cases, the data that can be processed, authorized vendors, decisions requiring human oversight, and actions an agent may execute autonomously.
The NIST AI Risk Management Framework (AI RMF) offers a sound approach to managing AI risks across the stages of design, development, deployment, evaluation, and use. It also provides a security and resilience perspective that can complement existing cybersecurity and privacy frameworks.
Organizations need to move beyond generic “responsible AI use” policies toward more concrete operational controls.
When creating an AI governance framework, the following must be considered, at a minimum:
Inventory of AI models, applications, and use cases.
- Risk classification based on impact and sensitivity.
- Identity and access controls.
- Policies for confidential data and intellectual property.
- Assessments of vendors and external models.
- Human oversight for critical processes.
- Monitoring, auditing, and incident response.
- Periodic review of models and applications.
Cloud security becomes inseparable from AI security
Many AI implementations rely on cloud infrastructure, model APIs, managed services, vector databases, and data platforms. This increasingly links cloud security with AI security.
A secure implementation must control which data can leave the corporate environment, which services can access that data, and the specific permissions granted to each application or agent.
This is crucial in regulated sectors like the financial industry, where an AI application might, for instance, access and interact with financial information, personal data, customer histories, or transactional systems.
Financial institutions must adopt specific controls to manage risks associated with GenAI, particularly regarding data and its secure use.
Certain elements must be built into the financial system’s architecture from the outset, such as segmentation, encryption, secrets management, the principle of least privilege, identity controls, and continuous monitoring.
From governance to secure implementation
The first step is to identify what information each system in your company consumes, since not every AI requires access to all data. The principle of least privilege must be applied to models and agents.
Secondly, identities must be managed. What does this mean? It means that the permissions granted to each agent must be explicit, limited, and auditable, for instance, specifying that one agent may use APIs, while another queries databases or executes processes on a user’s behalf.
The third element is monitoring. Organizations must be able to answer questions such as: Which model generated this response? What data did it use? Which user initiated the interaction? Which tools did the agent consult? What action did it execute, and why?
Without traceability, investigating an AI-related incident can become a significantly more complex task.
A security framework must evolve with technology
Security must be viewed and managed as a continuous system, as no single control can address all AI risks.
NIST recommends addressing AI risks throughout the system’s lifecycle, while ISO/IEC 42001 establishes requirements for implementing and continuously improving an AI management system within organizations.
This enables the development of a strategy that integrates governance, security, compliance, and operations, rather than treating them as separate initiatives.
Furthermore, organizations must periodically assess new threats, as the AI supply chain and the various stages of the lifecycle can introduce vulnerabilities requiring specific controls, the European Union Agency for Cybersecurity warned.
Security must scale ahead of AI
Before scaling AI, organizations must ask themselves whether security can keep pace.
There must be a combination of AI governance, AI security, and cloud security, underpinned by clear policies, secure architectures, identity controls, continuous monitoring, and ongoing risk assessment.
While many financial institutions might view responsible AI adoption as a slower process, it should be seen in this light: it means growing with confidence.
As AI evolves from assistants that generate responses into agents capable of executing actions, security shifts from a secondary technical consideration to a strategic imperative; therefore, it is crucial to accord it the importance it deserves.