Join our Newsletter — 33% off our NHI Course

How should security teams scale Gen AI training without creating new human risk gaps?

Security teams should pair Gen AI rollout with cross-functional governance, clear acceptable use rules, and continuous visibility into behaviour, identity, and threat signals. That lets them spot risky use of public tools, sensitive data exposure, and policy drift early. A data-driven Human Risk Management approach helps teams target interventions where they matter most instead of relying on one-time awareness training.

Why This Matters for Security Teams

Scaling Gen AI training is not just a learning problem. It changes how people handle data, how quickly risky workarounds spread, and how often employees rely on tools that may store prompts or outputs outside approved controls. The security impact is broader than phishing awareness because Gen AI can accelerate misuse of sensitive information, weaken review discipline, and blur accountability when users treat model output as authoritative. The NIST Cybersecurity Framework 2.0 is useful here because it anchors the problem in governance, protection, detection, response, and recovery rather than in training alone.

Teams often assume that a single policy update or awareness module will reduce risk. In practice, the real issue is whether employees can recognise unsafe use cases, understand what data must never be entered into Gen AI tools, and know how to escalate when the output affects customer, legal, or operational decisions. Human risk grows when training is generic, controls are inconsistent across business units, or approved tools are harder to use than public alternatives. In practice, many security teams encounter Gen AI risk only after sensitive prompts, shadow AI use, or bad output has already influenced a business decision, rather than through intentional governance.

How It Works in Practice

Effective scaling starts with role-based governance. Security teams should define which Gen AI uses are allowed, which data classes are prohibited, and which workflows require human review. Training should then be built around those actual decisions, not around broad warnings that lack operational context. This makes the guidance actionable for developers, analysts, customer-facing teams, and managers who each face different exposure.

Current guidance suggests treating Gen AI training as part of a wider control system. That means pairing awareness with technical guardrails, such as approved model access, data loss prevention, logging of prompt and response activity, and review of high-risk use cases. It also means validating where model output enters business processes, especially when staff may copy content into reports, code, tickets, or customer communications without verification. For teams handling sensitive workloads, the model itself is only one part of the risk surface; the user journey matters just as much.

  • Publish acceptable use rules that distinguish public tools, approved enterprise tools, and prohibited inputs.
  • Train by persona and by workflow so users learn the risks tied to their specific decisions.
  • Instrument logging and review so security teams can see prompt volume, data sensitivity, and policy exceptions.
  • Require escalation paths for outputs that affect legal, financial, customer, or security actions.
  • Refresh training when new model features, connectors, or agentic workflows are introduced.

For AI-specific control mapping, the OWASP Top 10 for Large Language Model Applications helps teams connect training to concrete abuse cases like prompt injection, data leakage, and insecure output handling, while the NIST AI Risk Management Framework provides a broader governance structure for trustworthiness and accountability. These controls tend to break down when Gen AI use is embedded in fast-moving, decentralised workflows because employees can bypass review through browser tools, chat plugins, or copied outputs that never pass through security logging.

Common Variations and Edge Cases

Tighter Gen AI controls often increase friction, requiring organisations to balance speed and experimentation against misuse prevention. That tradeoff is real, especially in teams that need rapid drafting, coding, or analysis support. Best practice is evolving here, and there is no universal standard for exactly how prescriptive training should be across all roles.

In highly regulated environments, the focus may shift toward approval workflows, retention rules, and auditability rather than broad enablement. In engineering teams, the bigger risk may be code generation that introduces insecure patterns or exposes secrets in prompts and outputs. In customer-facing functions, the key issue is inaccurate or overconfident responses that create compliance or reputational harm. Where agentic AI is used, the risk expands further because the system may act on behalf of a user, so training must cover both human approvals and machine execution boundaries.

The OWASP Agentic AI Top 10 is especially relevant when AI systems can take actions, not just generate text. For teams operating under formal governance expectations, the NIST AI resources help structure accountability even when business adoption is uneven. The main exception is early-stage experimentation in contained sandboxes, where lighter controls may be acceptable if data is synthetic, outputs are isolated, and access is tightly limited.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATLAS address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST AI 600-1 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV-01 Gen AI training needs ongoing oversight, not one-time awareness.
NIST AI RMF GOVERN AI risk management requires accountability, policy, and monitoring.
OWASP Agentic AI Top 10 Agentic workflows create action and approval risks beyond simple prompting.
NIST AI 600-1 GenAI-specific guidance addresses prompt, output, and data handling risks.
MITRE ATLAS AML.T0057 Adversarial AI threats include prompt injection and model abuse.

Set governance metrics for Gen AI use and review them as part of routine risk oversight.