Skip to content

Enterprise AI security overview

  • Draft
  • v0.3.0
  • Security architects and engineers
  • Reviewed 2026-09-28

AI security builds on established cybersecurity, privacy, resilience and supply-chain practice. It adds controls for three things that traditional systems do not have:

  • models that behave probabilistically
  • natural-language interfaces that mix instructions with data
  • agents that act on a model's output

Security objectives

  • Preserve confidentiality, integrity, availability and authenticity, and use data only for its authorized purpose.
  • Stop AI components from becoming a way around access control.
  • Keep models and agents inside explicit capability boundaries.
  • Identify untrusted content, and keep its provenance through every transformation.
  • Detect and contain misuse, compromise, unsafe behavior and supplier failure.
  • Keep enough evidence to investigate incidents, without retaining sensitive data longer than needed.

Security pages

Page Covers
Threat model Assets, trust boundaries, and threats mapped to OWASP and MITRE ATLAS identifiers
Zero-trust AI Enforcing controls outside the model, agent identity, tool controls, MCP authorization
Data protection Where AI copies data, retrieval authorization, securing training and operational data
AI supply chain Inventory, AI bills of materials, model signing, supplier risk
AI incident response Incident types, response steps, regulatory reporting, information sharing

Control domains

Domain Where it is covered
Identity and access Zero-trust AI
Segmentation and isolation Zero-trust AI, threat model
Secure development AI supply chain, NIST SP 800-218A
Model and data supply chain AI supply chain
Input and output protection Threat model
Context and memory isolation Data protection
Tool execution Zero-trust AI
Privacy Data protection
Observability and incident response AI incident response
Continuity and secure retirement AI supply chain (supplier exit), data protection (deletion)

Reference sources

Source Use it for
OWASP GenAI Security Project Top 10 lists for LLM and agentic applications, incident response guide
MITRE ATLAS Adversary tactics and techniques against AI systems
NIST AI 100-2e2025 Adversarial machine learning taxonomy
Deploying AI Systems Securely (April 2024) Joint government guidance on deploying AI systems
AI Data Security (May 2025) Joint government guidance on data used to train and run AI

For the frameworks these controls support, see the compliance mappings.