Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Securing AI from, in and with AI: what controls do teams need?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: AI security is really three problems, not one: defending against AI-powered threats, securing models and agents, and using AI to improve defensive operations, according to Anomali. That framing matters because agent permissions, auditability, and governance now sit alongside traditional detection and response, not outside them.

NHIMG editorial — based on content published by Anomali: Securing the Three Pillars of AI: A Practical Framework for Security Leaders

Questions worth separating out

Q: How should security teams govern AI systems that can act without human approval?

A: Security teams should govern autonomous AI the same way they govern other high-risk identities, but with runtime enforcement instead of periodic review.

Q: Why do AI agents increase IAM and PAM risk?

A: AI agents increase IAM and PAM risk because they can execute actions quickly once privilege is available, which shortens the time available to detect misuse.

Q: How can security teams tell whether AI lifecycle controls are working?

A: They should look for evidence that access requests, policy enforcement, and usage visibility are centrally recorded and current.

Practitioner guidance

  • Define separate control owners for the three AI security domains Assign ownership for threats from AI, security of AI systems, and security with AI to different teams or clearly separated programme lanes.
  • Inventory AI models, agents and integrations Create a living register of deployed models, connected tools, data sources, and third-party dependencies.
  • Constrain agent permissions to the minimum delegated scope Treat agent access like any other privileged workload.

What's in the full article

Anomali's full article covers the operational detail this post intentionally leaves for the source:

  • How the webinar mapped practical controls to each of the three AI security domains for security operations teams
  • The leadership discussion on governance, auditability, and deployment qualification for agentic AI
  • Operational examples of where AI can improve triage, correlation, and response workflows
  • The on-demand session context behind the framework and the speakers' original wording

👉 Read Anomali's framework for securing AI from, in and with AI →

Securing AI from, in and with AI: what controls do teams need?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

AI security is now a governance segmentation problem, not a single control domain. Treating threats from AI, security of AI, and security with AI as one programme obscures ownership, metrics, and control design. Each domain needs different success criteria, different control owners, and different audit evidence. Security leaders who fail to separate them will overinvest in one area while leaving another structurally under-controlled. The practical conclusion is to govern AI by risk domain, not by label.

A question worth separating out:

Q: What is the difference between securing AI and using AI for security?

A: Securing AI protects models, data, and pipelines from attack. Using AI for security applies machine learning to improve detection, prioritisation, and response. Both matter, but they solve different problems. A mature programme needs controls for the AI system itself, not only AI-assisted security operations.

👉 Read our full editorial: Securing AI requires separate controls for threats, models and operations



   
ReplyQuote
Share: