Menu

5 shifts that turn an enterprise AI rollout into a security problem

Security teams spent two decades learning to defend a perimeter they could draw. Firewalls, endpoint agents, identity providers, a list of sanctioned applications: the model assumed you knew what was running inside the building. Artificial intelligence has quietly dissolved that assumption, and most of the dissolution happened without a purchase order.

The uncomfortable part is that the breach path rarely begins with an intruder. It begins with a competent employee trying to finish a task faster. That is the case made by the CEO of XFactorAi, and as John Margerison has argued about the security exposure created by shadow AI, the tools that carry corporate data outside the estate are walked in by staff rather than smuggled in by attackers.

Boards asking whether their AI programme is secure are usually asking about the model. The exposure sits somewhere else entirely.

The perimeter now runs through the browser tab

Shadow AI is not a policy violation of the old kind. Copying a customer list into an unsanctioned chatbot leaves no malware, trips no signature and produces no alert, because the traffic looks like ordinary web browsing to an ordinary consumer service.

The precedent is well documented. CNBC reported in May 2023 that Samsung barred staff from using generative AI tools including ChatGPT after sensitive material was entered into the chatbot, a decision taken by one of the most security-conscious manufacturers on earth. Two and a half years later, the same behaviour is available inside every browser, every phone and a growing number of desktop applications that ship an assistant by default.

Blocking domains addresses roughly the version of the problem that existed in 2023.

Enterprises are shipping AI faster than they can control access to it

Once AI moves from consumer tools into sanctioned deployments, the risk changes shape rather than shrinking. A retrieval system with access to a document store inherits every permissions error in that store, and answers questions the underlying access controls would have refused.

IBM’s 2025 Cost of a Data Breach research, summarised in the company’s announcement that 13 per cent of organisations reported breaches of AI models or applications, found that 97 per cent of those reporting such a breach lacked proper AI access controls. That ratio matters more than the headline percentage. It says the compromises are not exotic model attacks. They are ordinary authorisation failures happening in a layer nobody has assigned to an owner.

Most enterprises can name the person accountable for database permissions. Very few can name the person accountable for what a copilot is allowed to read.

Untrusted input is now executable

Traditional application security draws a hard line between code and content. Large language models erase it, because instructions and data arrive through the same channel. A malicious sentence buried in a supplier’s invoice, a web page or an email signature can redirect an agent that was asked to summarise it.

The UK’s National Cyber Security Centre has escalated its warnings on this, and Infosecurity Magazine’s report on the NCSC's alarm over prompt injection attacks records a national technical authority describing a weakness with no clean fix available. That is an unusual admission. It also has a hard consequence for architecture: any agent granted the ability to act, rather than merely to answer, must be treated as a system that will eventually follow an attacker’s instructions.

Enterprises are currently granting those permissions on the assumption that the model will behave.

The exposure arrives inside software you already approved

The security review most organisations run assumes AI enters through a project. It increasingly enters through a version upgrade. Customer relationship platforms, ticketing systems, collaboration suites and document stores have all added assistants, connectors and agent frameworks to products that passed procurement years ago, under contracts that said nothing about model training or data residency.

This is where the third-party risk function tends to break down. A vendor questionnaire completed in 2023 describes a product that no longer exists, and the integration tokens that let one AI feature read from three systems create precisely the lateral movement path that segmentation was built to prevent. Compromise the assistant and you inherit its connections.

Renewal, in this environment, is a security event.

Detection and forensics have not caught up

Every previous shift in the attack surface was eventually met by tooling that made it visible. That has not happened here, and the gap is what should worry an audit committee most.

When something goes wrong with an AI system, the investigative questions are unusually hard to answer. Which prompt caused the disclosure. What the retrieval layer returned at the time. Whether the same input would reproduce the outcome, given that it may not. Conventional logging captures the API call and discards the context, so the evidence needed to scope an incident is frequently gone before anyone knows there was one.

An organisation that cannot reconstruct what an agent did also cannot tell a regulator, a customer or an insurer what was lost.

The strategic error is treating this as a technical control problem to be solved after deployment. Access decisions, logging depth and the boundary between advisory and acting systems are design choices, and they are cheapest to make before the first agent goes live. Enterprises now approving their second wave of AI projects have a narrow window to build in the accountability the first wave skipped, and the second wave will be the one with permission to act.

No comments

Leave a Reply

Most Shared Posts

Write For Us