Join our Newsletter — 33% off our NHI Course
Home Glossary AI Security Foundation Model
AI Security

Foundation Model

← Back to Glossary
By NHI Mgmt Group Updated September 1, 2026 Domain: AI Security

A foundation model is a large AI model trained on broad data so it can be adapted to many downstream tasks. It serves as a reusable base for applications such as chat, image generation, summarisation, and classification. The same general capability also creates governance risk because one model can influence many systems at once.

Expanded Definition

A foundation model is not just a large model, but a general-purpose model that can be adapted through prompting, fine-tuning, retrieval, or tool use to support multiple downstream applications. That flexibility is what makes it powerful in enterprise environments and also harder to govern than a single-purpose model. In practice, the model may be used directly by end users, embedded into other systems, or exposed through APIs that other teams depend on. Definitions vary across vendors on where "foundation model" ends and "large language model" or "general-purpose model" begins, so NHIMG treats the term as a capability class rather than a product category.

For governance and assurance, the most useful lens is whether the model can influence many workflows, data paths, and decisions from one shared base. The NIST AI 600-1 Generative AI Profile is useful here because it frames generative AI risk in operational terms, including lifecycle controls, testing, and monitoring. The most common misapplication is treating a foundation model like an ordinary application component, which occurs when teams ignore shared downstream impact and reuse the model without change control.

Examples and Use Cases

Implementing foundation models rigorously often introduces governance overhead, requiring organisations to weigh speed of reuse against control over model behaviour, data exposure, and drift.

  • A customer support assistant built on a shared model is fine-tuned for brand tone, but still inherits the base model's weaknesses and must be monitored for unsafe or incorrect outputs.
  • An internal search assistant uses retrieval-augmented generation to answer policy questions, where the foundation model interprets content but does not replace source-of-truth documents.
  • A development team uses the same model behind code generation, ticket summarisation, and release-note drafting, creating a single point of governance for multiple workflows.
  • A security operations team connects the model to investigation tools, which improves triage speed but increases the need for strict tool permissions and logging.
  • A regulated organisation reviews whether a vendor-hosted model is a foundation model under its AI governance policy before allowing business units to deploy it at scale.

These scenarios are consistent with the broader risk-management approach in the NIST AI 600-1 Generative AI Profile, especially where the same model influences multiple services. The key question is not whether the model is impressive, but how many decisions it can affect from one shared dependency.

Why It Matters for Security Teams

Foundation models matter because they concentrate operational risk. A weakness in the base model can propagate into chatbots, copilots, classification services, and agentic workflows that rely on the same underlying weights or API. That creates governance requirements around model provenance, access control, prompt handling, evaluation, and change management. Security teams also need to distinguish between model capability and system trustworthiness: a model may be broadly useful while still being unsuitable for high-impact decisions without guardrails.

This term also intersects with identity and NHI governance when foundation models are used inside autonomous agents or exposed to tool-using workflows. In those cases, the model is not just generating text, but helping determine which actions an agent takes, which secrets it requests, and which resources it can reach. That makes model governance inseparable from privilege boundaries and auditability. Organisations typically encounter the consequences only after a model update, unsafe output, or unintended tool invocation affects production systems, at which point foundation model governance becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST AI 600-1 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST AI RMFAI RMF defines risk governance practices for models used across many downstream tasks.
NIST AI 600-1The GenAI Profile addresses lifecycle risks for generative foundation models.
OWASP Agentic AI Top 10Agentic AI guidance is relevant when foundation models drive tool-using autonomous systems.
CSA MAESTROMAESTRO covers security concerns for agentic AI systems built on reusable model foundations.
NIST CSF 2.0GV.RM-01CSF risk management supports oversight of shared AI dependencies and governance decisions.

Apply profile guidance to testing, monitoring, and change control for generative model deployments.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 1, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org