AI systems can act with a degree of self-agency, adapt to their environment, and influence real-world outcomes in ways conventional software usually does not. That means static controls are not enough. Security and governance teams need lifecycle risk management, continuous oversight, and a clear view of how model behaviour changes over time, especially where decisions affect fairness, safety, or compliance.
Why This Matters for Security Teams
Traditional application security assumes software behaves in predictable ways once code is tested, deployed, and patched. AI systems do not always stay within those bounds. They can change output quality as data shifts, they can be influenced by prompt injection or poisoned inputs, and they can create business decisions that are difficult to explain after the fact. That makes the security question broader than hardening infrastructure or scanning code. It becomes a governance problem, a model risk problem, and an operational assurance problem.
For that reason, teams need to treat AI as a dynamic system with dependencies, not as a static application. NIST Cybersecurity Framework 2.0 is useful here because it reinforces the need to identify assets, manage risk, and monitor continuously rather than assuming one-time validation is enough. That approach matters when models are updated, retrained, wrapped in tools, or connected to sensitive data sources. In practice, many security teams encounter AI control failures only after an exposed workflow has already been exploited or an AI decision has already affected users, rather than through intentional pre-deployment testing.
How It Works in Practice
AI security requires controls across the full lifecycle, from data collection and model training through deployment, monitoring, and retirement. A secure AI program usually starts with knowing what the model is allowed to do, what data it can access, and which humans or systems can override it. It then adds specific tests for AI failure modes that traditional software controls do not cover, including prompt injection, training data contamination, unsafe tool use, and model drift.
Operationally, the control set should include:
- Data provenance checks so training and retrieval sources are traceable and trusted.
- Pre-release red teaming to test prompt injection, jailbreaks, and adversarial inputs.
- Output validation for hallucinations, policy violations, and unsafe recommendations.
- Change management for model updates, fine-tuning, retrieval content, and system prompts.
- Monitoring for abnormal behaviour, especially when the model can take actions through tools or agents.
Frameworks such as the NIST AI Risk Management Framework help structure these activities around govern, map, measure, and manage. For adversarial behaviour, MITRE ATLAS provides a practical catalogue of attack patterns against AI systems, while OWASP guidance for LLM applications is useful for application teams that need concrete guardrails for prompt handling, tool access, and output safety. This guidance breaks down in highly autonomous environments where an agent can chain multiple tools, make branching decisions, and act on stale or incomplete context faster than a human review process can intervene.
Common Variations and Edge Cases
Tighter AI governance often increases review overhead and slows experimentation, requiring organisations to balance innovation against safety, legal exposure, and operational complexity. That tradeoff is real, especially when teams want rapid model iteration or broad internal access to generative tools.
There is no universal standard for every AI use case yet, so best practice is evolving. High-risk systems that affect hiring, lending, identity decisions, healthcare, or regulated customer communications usually need stronger documentation, auditability, and human oversight than an internal productivity assistant. Current guidance also suggests different controls for different deployment patterns: a closed model with no external tools is not managed the same way as an autonomous agent with API access, retrieval permissions, and write capabilities.
One overlooked edge case is the interaction between AI and identity governance. If an AI agent can act on behalf of a person or service account, then its permissions, approvals, and activity logs need the same scrutiny applied to other privileged identities. That is where identity controls, secrets management, and task scoping become part of AI security rather than separate concerns. For regulated environments, the NIST Cybersecurity Framework 2.0 remains a useful baseline, but it does not replace AI-specific testing or model assurance. In practice, the hardest failures appear when AI is embedded into existing workflows and inherits broad access without anyone formally reviewing the new decision path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATLAS and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST AI RMF, NIST AI 600-1 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI RMF | AI RMF fits lifecycle risk, testing, and monitoring for AI behaviour changes. | |
| MITRE ATLAS | ATLAS maps adversarial tactics like prompt injection and model manipulation. | |
| OWASP Agentic AI Top 10 | Agentic AI controls address tool use, autonomy, and unsafe action execution. | |
| NIST AI 600-1 | GenAI profile helps operationalise security and governance for LLM systems. | |
| NIST CSF 2.0 | GV.RM-01 | Risk management governance supports oversight for AI as a dynamic system. |
Assign AI risk ownership, monitor changes, and keep controls tied to business risk.
Related resources from NHI Mgmt Group
- Why do AI systems require different security testing than traditional software?
- Why do AI-generated systems need stronger behavioural controls than traditional software?
- Why do traditional IAM and DLP controls fail for autonomous AI systems?
- Why do AI systems complicate traditional data security controls?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org