Enterprise AI security overview AI security builds on established cybersecurity, privacy, resilience and supply-chain practice. It adds controls for three things that traditional systems do not have:
models that behave probabilistically natural-language interfaces that mix instructions with data agents that act on a model's output Security objectives Preserve confidentiality, integrity, availability and authenticity, and use data only for its authorized purpose. Stop AI components from becoming a way around access control. Keep models and agents inside explicit capability boundaries. Identify untrusted content, and keep its provenance through every transformation. Detect and contain misuse, compromise, unsafe behavior and supplier failure. Keep enough evidence to investigate incidents, without retaining sensitive data longer than needed. Security pages Page Covers Threat model Assets, trust boundaries, and threats mapped to OWASP and MITRE ATLAS identifiers Zero-trust AI Enforcing controls outside the model, agent identity, tool controls, MCP authorization Data protection Where AI copies data, retrieval authorization, securing training and operational data AI supply chain Inventory, AI bills of materials, model signing, supplier risk AI incident response Incident types, response steps, regulatory reporting, information sharing
Control domains Reference sources For the frameworks these controls support, see the compliance mappings .
September 28, 2026 July 27, 2026