All terms

Enterprise AI

AI security

Also known as: securing AI systems

AI security is the practice of protecting AI systems, their data and the applications built on them from misuse, manipulation and leakage. It covers threats such as prompt injection, data exfiltration through model outputs, unsafe tool use by agents and compromised supply chains. It also covers the controls that keep AI features safe once they are live.

What it is

AI security treats models, prompts, retrieval sources, plugins and agent tools as parts of an attack surface that behaves differently from traditional software. Risks include prompt injection hidden in web pages or documents, sensitive data appearing in model outputs, poisoned training or retrieval data, and over permissioned agents taking actions they should not. It sits alongside conventional application and cloud security rather than replacing it.

Why it matters

Many marketing and customer facing teams now ship AI features such as site assistants, content generation tools and support bots, which expose internal data and systems to untrusted input. A single injection in a crawled page or uploaded file can turn a helpful assistant into a data leak or a source of false statements about your brand. Because these failures are visible to customers, the reputational cost often exceeds the technical one.

How it works

Practitioners scope what each AI system can read and do, apply least privilege to tools and data sources, and separate trusted instructions from untrusted content. They add input and output filtering, log prompts and responses for review, require human approval for sensitive actions, and test systems with red teaming and adversarial prompts before launch. Vendor assessments, secrets management and monitoring for unusual usage patterns complete the picture.

When it applies

It applies from the moment an AI feature can read untrusted content, touch customer data or trigger an action in another system. Review controls before launch, after any change to data sources or tool permissions, and on a regular schedule for systems that stay in production.

Examples

  • A team red teams its website assistant and finds that instructions hidden in a crawled PDF can make it reveal internal pricing notes.
  • A support bot is restricted to a read only knowledge base and cannot issue refunds without a human approving the action.
  • A security review blocks an AI writing tool from connecting to the CRM until data processing terms and access scopes are agreed.

How it is measured

  • Number of AI systems with a documented threat model, data scope and permission review
  • Results of red team and prompt injection testing, including issues found and time to fix
  • Rate of blocked or flagged unsafe prompts and outputs in production logs
  • Share of AI vendors with completed security reviews and agreed data handling terms

Related terms in Enterprise AI

Primary research · August 2026

How ChatGPT Shortlists Software Brands

An audit across 10 categories and 60 buying questions. I recorded what ChatGPT reads, throws away and links to when a buyer asks it which software to buy, and what that decides.

60
Questions asked
10
Software markets
2,680
Results read
367
Links shown
Free35 pages · PDF · 536 KBDiscovery Digest every Friday

Free download

Get the full report

35 pages · PDF · 536 KB. Enter your details and it downloads straight away.

How ChatGPT Shortlists Software Brands downloads straight away. No spam, unsubscribe anytime.