Its scope includes training and evaluation data, models and weights, code, prompts, retrieval stores, development pipelines, identities, infrastructure, interfaces, connected tools and the decisions or actions an AI-enabled application can produce.
The work extends established cybersecurity practices across the AI lifecycle while addressing attack paths created or amplified by machine learning. A sound program starts with the system’s purpose, assets, actors and trust boundaries, then selects controls according to realistic consequences. It protects confidentiality, integrity and availability without assuming that a well-performing model or a reputable provider makes the complete application secure.
Key points
Lifecycle scopeAssess acquisition, data preparation, training or customization, evaluation, deployment, operation, change, incident response and retirement — not only the public model endpoint.
Core controlsMaintain an asset inventory; verify provenance; apply least privilege, secure development and supply-chain controls; isolate sensitive resources; validate outputs before use; and monitor both conventional and AI-specific abuse.
Assurance evidenceCombine threat modeling, security testing, adversarial evaluation, access and configuration review, incident exercises, monitoring and retesting after material changes.
Important limitationAI security is not a synonym for AI safety or overall trustworthiness. A system can resist attackers yet still be inaccurate, unfair, unsafe in its intended context or poorly governed, and no single gateway or scanner covers the full risk.