AI Security

AI security and new attack surfaces

8 August 2026

Artificial intelligence doesn't just change how companies work. It also changes how they are attacked. A practical overview of new risks and secure AI use.

Few technologies have spread as fast as generative AI. From customer-service chatbots and automated document analysis to coding assistants, AI is now embedded in ever more business processes.

But as the benefits grow, so does the attack surface. AI systems can become targets themselves, and at the same time attackers use AI to create phishing, fraud, deepfakes and malicious code more convincingly and faster.

Two sides of the same coin

AI security has two dimensions. On one hand, AI itself becomes a target: language models, RAG systems and autonomous agents can be manipulated, misinstructed or influenced with malicious data.

On the other hand, AI becomes a tool for attackers. Phishing, deepfakes, social engineering and malicious code can be produced faster, cheaper and more convincingly with generative methods. Anyone securing AI has to consider both sides.

When AI becomes the target

Prompt injection

Hidden instructions get models to bypass rules or perform unwanted actions

Data leakage

Sensitive information can escape via prompts, responses or connected systems

Supply-chain risks

Models, libraries, plug-ins and data sources can be manipulated or compromised

Data poisoning

Manipulated training or reference data changes the behavior of an AI system

Autonomous agents

Agents with too many permissions can perform actions no one has adequately controlled

System-prompt leaks

Internal instructions and configurations can be read out and used for attacks

When AI becomes a tool for attackers

Generative models drastically lower the barrier to convincing attacks. Phishing emails become linguistically cleaner, more personal and available in many languages. With a few seconds of audio, voices can be cloned, and deepfakes make it harder to detect fake calls or video conferences.

Technical safeguards alone are not enough here. Processes such as the four-eyes principle for payments, callbacks over known channels and clear approvals become more important than ever.

Shadow AI: the underestimated everyday risk

The biggest risk often comes not from attackers, but from within. Employees paste contracts, source code or customer data into freely available AI services to work faster. What is well-intentioned can lead to an uncontrolled outflow of confidential information.

Make shadow AI visible

Before companies issue bans, they should understand which AI services are already in use. An approved, secure standard service with clear rules is often more effective than a blanket ban that gets circumvented in daily work.

Regulatory framework: the EU AI Act

The EU AI Act creates a binding legal framework for the use of artificial intelligence. For companies, this makes it more important to classify AI applications, document responsibilities and manage risks in a traceable way across the entire lifecycle.

Seven measures for secure AI use

1

Establish governance

Define who may use AI for what and who is responsible

2

Classify data

Define which data may go into which AI systems and which may not

3

Limit access

Give AI systems and agents only the permissions they truly need

4

Check inputs and outputs

Treat prompts and model responses as untrusted data

5

Keep human approval

Do not fully automate critical actions such as payments, deletions or publications

6

Log usage

Make it traceable who uses which AI functions and where anomalies arise

7

Vet providers

Clarify where data is processed, whether it is used for training and which certifications exist

Shape AI use in a structured and secure way
To AI Security