Demystifying AI Security: Three Ways Enterprises Need To Think About It

This article was previously published in the October 2026 edition of Cyber Defense Magazine, a leading periodical for information technology and cybersecurity professionals. This article explains why security leaders need to determine what they are trying to accomplish and distinguish between AI security “from,” “of,” and “with”.

Ask ten security leaders what “AI security” means, and you’ll get ten different answers. In the 30+ years I’ve been in this industry, I’ve watched the same pattern play out with every wave of new technology, from application coding to the cloud and now AI.

A new concept emerges, everybody thinks about it narrowly within their own working world, and the industry spends a year or two talking past itself before it settles down.

I credit the way I’ve approached explaining AI security to Mark Gilmor of Cyberify Services, who looks at AI security with three lenses — “from,” “of,” and “with.” I’ve found it’s the cleanest way to get a room full of security leaders on the same page in under five minutes. Mark looks through these three lenses because, as he has explained, AI is changing the game faster than most organizations can rewrite the rules. It’s not just about plugging holes anymore; it’s about seeing the whole game board before someone tips it over.

Security from AI defends against adversaries using AI to come after you. Security of AI protects the AI systems, applications, and agents your organization builds and deploys. Security with AI uses AI-enabled tools to make your existing security operation sharper. These are three separate jobs that don’t necessarily depend on each other but support each other. Treating them as one undifferentiated problem and labelling them as “AI security” is one reason why organizations fall short on their initial security efforts. Security leaders need to know which of these three they’re solving, and that starts with understanding all three.

Security FROM AI: Start by knowing your adversary and their capabilities

AI is changing the threat landscape by increasing the volume, velocity, and novelty of what organizations must defend against. Frontier models can analyze enormous amounts of code and find vulnerabilities at a scale much larger and speed much faster than human attackers can replicate.

A customer who recently took part in Anthropic’s Project Glasswing told me they ran one analysis against a single application with 30 million lines of code and were told that doing the equivalent work through traditional means would have cost nearly $400,000. I understand that there’s a ton of concern about frontier models breaking into sophisticated organizations and stealing data, but the economics and cost model isn’t there yet for an average bad actor. These tools cost hundreds of thousands of dollars in compute to properly leverage.

My advice is to know who your adversary is and build your strategy around their likely threat tactics. Consider which threat actors are capable of targeting your organization, at what scale and financial means, and have your threat intelligence reflect these tactics. Push your detection further left, earlier in the attack lifecycle, so you’re acting on preparation instead of reacting to impact.

Security OF AI: Control what enterprises are deploying

Securing the AI used internally is where a lot of investment is being focused because it’s the mechanism that lets organizations adopt the technology with confidence.

Think of it like brakes on a car. Brakes aren’t in a car to make it slower. Brakes let cars go faster while enabling the driver to maintain speed, agility, and control on the road. Security controls around your internal AI systems work the same way, letting businesses adopt AI with confidence.

AI agents raise the stakes considerably, since control becomes more complex to engineer. Traditional automation follows a fixed set of rules and steps to reach a known outcome. With agents, you give them a goal, and they determine how to get there. Without explicit rules about what’s off-limits, agents can easily go rogue in the eye of a security team, ultimately widening an organization’s potential risk.

This behavior is already happening and well documented. Within roughly two weeks, OpenAI, Anthropic, and Meta independently disclosed incidents in which models reached real, external systems from environments that were supposed to be isolated. Details varied by incident, but the underlying issue was the same. When an AI agent was given a goal and the ability to take actions to achieve it, small gaps between what the environment was supposed to allow and what it allowed led to security issues and agents taking actions even safety researchers couldn’t explain. With how much AI exists already and is being built today, these incidents won’t be far and few between.

CISOs must strategically and thoroughly consider permission parameters (Guardrails) for agents and AI connectors before pursuing any objective.

Security WITH AI: Don’t let the tool replace the fundamentals

The final lens of AI security is focused on using AI to improve existing security operations. It’s the most straightforward and probably the one best suited to benefit from AI, and the easiest to deprioritize.

AI can help security teams process far more signal than a human analyst can, spot patterns faster, and make better-informed decisions under pressure, but it is not a replacement for the fundamentals. Teams still need strong detection, prevention, and trustworthy threat intelligence. Layer this with brutal honesty about whether the controls already paid for would stop the threats the organization is most vulnerable to. I’ve seen plenty of organizations invest millions in detection and prevention and still get breached, and the postmortem question is never “did we have a tool for that?” It’s “was the tool positioned or configured to catch it?” AI should sharpen that discipline, not permit anyone to skip it.

Practical advice for deploying AI and agents

For security teams deploying agents, here are a few pieces of advice to consider after reflecting on the from, of, and what AI security positioning above.

Define agent’s objective and boundaries before deployment. Be explicit about what the system is permitted to do and, just as importantly, what it’s explicitly prohibited from doing. Don’t assume it will infer organizational intent the way a human employee would.

Design for the worst-case version of goal-seeking behavior. Ask what the system could do if it used every resource technically available to it in pursuit of its assigned goal, and test that scenario before the system ever enters production.

Limit access to the minimum required. Whatever resources, systems, and data the agent doesn’t need to complete its task, it shouldn’t be able to reach. Treat every external connection as part of your attack surface. Begin with a “deny all” mentality and carefully enable access from there only as needed.

Test your controls for efficacy, continuously. Knowing a control exists isn’t the same as knowing if it would stop a major breach. This will only become more important as the systems and adversaries evolve faster than most organizations’ assumptions do.

Knowledge is power. AI is moving too quickly for any one organization to figure this all out alone. Security teams and communities that openly share what they’re seeing, including successes, failures, and challenges, will be better prepared than those treating every lesson learned as proprietary insights. Meet regularly with your peers and peer institutions and share what is working and what is not working.

The goal is to make moving faster possible

AI security will continue meaning different things to different teams, all dependent on whether you’re defending from AI, securing the AI you’ve introduced, or defending environments with AI. I urge CISOs to consider approaching AI security through the “from,” “of,” and “with” framework Mark Gilmor has so passionately advocated for. Treating those as three separate and complementary priorities gives security leaders a starting point to allocate resources and evaluate risk today.

I believe that the organizations that come out ahead will be the ones that make AI trustworthy enough to use while keeping their security strategies flexible enough to evolve with it. In the short term, this means building security into how AI is developed, deployed, and governed from the start, and adapting as we learn more.

Next Steps: This free WEI solution brief outlines the strategic capabilities, program gaps, and organizational capacities that define AI-era security maturity. Synthesizing leading frameworks with real-world insights from the WEI CISO community to answer the question every security leader is asking: What are other organizations in my space doing today?

DOWNLOAD SOLUTION BRIEF: Defending at Machine Speed

LinkedInFacebookEmail