TL;DR: AI systems are now part of the cloud attack surface, but traditional IAM, segmentation, and monitoring controls do not fully address model poisoning, inference abuse, prompt injection, or shadow AI, according to Orca Security. The practical gap is governance, not just tooling: security teams need inventory, ownership, lifecycle controls, and continuous monitoring for models and pipelines.
Editorial analysis by NHI Mgmt Group, based on content published by Orca Security: “What is AI Security?”.
Key questions
Q: What breaks when agentic AI governance is still built like traditional IAM?
A: Traditional IAM assumes access can be granted, reviewed, and revoked around a stable actor with predictable intent.
Q: Why do cloud AI deployments create governance risk even when access is restricted?
A: Restricted access does not solve ownership, lifecycle, or shadow-deployment problems.
Q: How can security teams tell whether AI posture management is actually working?
A: It is working when teams can answer four questions quickly and consistently: who owns the agent, what it can access, which guardrails apply, and when access changed.
Practitioner guidance
- Define model ownership and accountability Assign a named owner for every model, endpoint, and training pipeline, including responsibility for monitoring, change approval, and retirement decisions.
- Build a complete AI asset inventory Track production models, inference endpoints, training data stores, and third-party integrations so security teams can classify exposure and sensitivity.
- Add AI-specific risk reviews Evaluate poisoning, prompt injection, inference abuse, and model inversion alongside existing cloud risk assessments, especially where models process sensitive data.
Bottom line: AI security in cloud environments is becoming an identity and governance issue, not just a model protection issue.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI security is now an identity governance problem as much as a model risk problem. The article shows that cloud AI risk is not only about adversarial inputs or poor model quality. It is about who owns the model, who can change it, who monitors it, and which supporting identities and data paths remain in scope. For practitioners, that means AI security must sit inside IAM, IGA, and cloud governance rather than alongside them.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- Only 23% of IT leaders were very confident in their organisation's ability to manage security and governance for GenAI deployments, according to a 2025 Gartner survey of 360 IT leaders.
A question worth separating out:
Q: How should organisations compare AI security controls with workload and NHI controls?
A: They should not treat AI security as separate from workload and NHI governance. The better comparison is between controls that govern access and controls that govern behaviour after access. AI systems need both, because identity controls can restrict entry while AI-specific controls address poisoning, inference abuse, and unsafe outputs.
👉 Read our full editorial: AI security in cloud environments exposes gaps in IAM controls