
AI in the spotlight: How companies are protecting models, data and AI applications from new threats
AI Security: Governance, Risk Assessment and Protection against New Threats
Successful AI security begins before implementation – with clear governance, regulatory classification and a realistic assessment of risks and business impact. Anyone wishing to use AI securely must think beyond the technical safeguarding of individual models. Organisations face the challenge of assessing AI initiatives in a structured manner: Which AI use cases are critical? What data is being processed? Which regulatory requirements apply – for example, under the EU AI Act or the GDPR? Only on this basis can meaningful technical measures be prioritised and implemented sustainably. Nevertheless, many aspects associated with the new possibilities offered by AI are leading to an increased technical threat landscape. New attack vectors such as prompt injection, data poisoning or model inversion target precisely these vulnerabilities – with potentially serious consequences for data integrity, business processes and corporate reputation. To ensure trust, compliance and stability, the technical safeguarding of models, data and AI infrastructure is essential. “Anyone working with artificial intelligence must consider the issue of cyber security right from the start. Only by designing AI securely can organisations minimise risks, protect corporate assets and sustainably strengthen the trust of customers and partners. This is how AI security becomes a genuine success factor, ” says Alexander Ernst, Director of the Competence Centre, Network & Security at CANCOM.
What organisations should do now, before deploying AI
Step 1: Governance, compliance and risk management
The firststep in any AI security strategy is organisational and regulatory alignment. Roles, responsibilities and guidelines must be defined before AI is deployed in production. This includes, amongst other things, AI governance models, risk and impact assessments, and the integration of AI-related issues into existing ISMS and compliance structures. The first step also involves analysing and identifying existing (shadow) AI tools, which in many organisations are already being used ‘informally’ by staff. These must be identified, regulated and brought under defined access and governance processes.
Step 2: Access control and identity management
To ensure the security of AI systems, consistent access control and well-designed identity management are essential. Access to systems, data and functions should be verified in accordance with the zero-trust principle and authorised on the basis of defined policies. Under this approach, no user, device or service is trusted by default. Role-based access control also ensures that only authorised individuals and systems are granted access to the resources they require. Furthermore, access should be continuously assessed in a context-based manner, subject to strong authentication, and controlled in accordance with the least-privilege principle.
Step 3: Data Security and Model Protection
The protection of data and AI models is a central component of any holistic AI security architecture. Sensitive data and models should be protected during storage, transmission and processing, for example through encryption and rigorous key and secret management. Furthermore, the behaviour of AI systems must be actively managed and secured. Inputs – known as ‘prompts’ – connected data sources and generated outputs should be continuously checked against defined security policies and controlled by security mechanisms such as guardrails and input and output filtering. This specifically reduces risks such as prompt injection, leaks of sensitive data, undesirable content or non-compliant responses. In this way, corporate assets are protected and ethical, legal and regulatory requirements are better met.
Step 4: Monitoring and continuous testing
There can be no AI security without monitoring and regular testing! All actions and interactions with AI models should be logged, documented in a traceable manner and examined in real time for anomalies. Equally important is transparency regarding the AI assets, models, agents and interfaces in use, achieved through inventory management, logging and traceability of usage. This is the only way to identify and assess security risks at an early stage. Targeted security assessments such as AI and LLM penetration tests, red teaming and regular LLM and AI agent audits are just as much a part of this as training with specific tasks to further harden and strengthen the resilience of AI models against potential attacks.
- Anticipate and act
Addressing the issue of AI security at an early stage is well worth the effort: a forward-looking AI security strategy lays the foundation for organisations to deploy AI solutions in a trustworthy, scalable and compliant manner. It proactively mitigates risks such as data loss, hallucinations or manipulation, strengthens the resilience of AI systems and supports compliance with ethical, legal and regulatory requirements. This bolsters the trust of customers, partners and the public. “If the topic of AI security is [also] taken into account from the outset in accordance with the ‘security by design’ principle, AI solutions can be rolled out in a standardised, modular manner across the entire organisation. On the one hand, this prevents costly retrofitting; on the other, it increases the company’s productivity and capacity for innovation. In a competitive market environment, such a head start can prove to be a clear competitive advantage,” says Dustin Wollnik, Business Development Manager for Security at CANCOM. - Your partner for secure and trustworthy AI
With many years’ experience in the fields of cyber security, compliance and data protection, CANCOM supports companies in designing AI initiatives that are compliant, scalable and secure. This includes the analysis and assessment of client-specific AI environments, the joint development of strategies and governance structures, and the implementation of future-proof, flexible solutions.
Holistic AI security: Regulatory, organisational and technical requirements
The requirements of the EU AI Act, the GDPR and ISO standards for AI stipulate that security, traceability and governance must be integral components of every AI solution, from development through to use across the entire AI lifecycle. An AI security strategy must therefore integrate organisational, regulatory and technical aspects right from the start.
From an organisational perspective, new roles, policies and training are required to ensure the responsible use of AI.
From a regulatory perspective, the new requirements must be integrated into existing ISMS structures and governance models.
From a technical perspective, tools specifically designed to address AI risks are required: ranging from dedicated access controls and the protection of data, AI models and AI applications against runtime threats, to the continuous monitoring and assessment of the entire AI ecosystem.