AI is a transformative technology with immense potential, but it introduces both familiar and novel risks. To fully capitalize on its benefits, organizations must address these risks through proactive and effective risk management strategies. By combining human oversight, a solid security architecture, and advanced technical controls, organizations can enhance the benefits of AI while ensuring its safe deployment.
1. Establish Guardrails for Secure and Compliant AI
Organizations should leverage existing risk and governance frameworks to create AI-specific guardrails. This involves:
- Refining Security Policies: Update and adapt existing policies to address new risks associated with generative AI, while expanding the scope of risk oversight.
- Conducting Critical Reviews: Regularly evaluate current security capabilities to identify areas needing AI-focused policies.
- Integrating Human Oversight: A "human-in-the-loop" approach ensures responsible AI use by managing risks across three areas:
- Risk Assessment — Rank AI risks by evaluating data sensitivity, potential impact, and critical mission dependencies.
- Trigger Points — Implement technical or operational triggers that require human intervention for high-stakes decisions.
- Acceptable Use Policies — Define "do's and don'ts" to prevent unauthorized AI use, such as shadow AI tools.
2. Strengthen Security Architecture and Technical Controls
A secure AI environment relies on a robust infrastructure and application-level controls. Focus on the following areas:
- Secure Infrastructure: Use traditional network and endpoint controls while addressing vulnerabilities in the AI supply chain.
- Application Security: Incorporate secure development practices, leverage advanced scanning tools, and enforce strict authentication measures.
- Model Security: Protect AI models from adversarial attacks, bias, and theft by conducting regular red team exercises and securing model outputs.
- Data Protection: Implement encryption, data masking, and access controls, while maintaining clear data provenance records and ensuring the integrity of training datasets.
These measures ensure the security of both AI systems and sensitive data.
3. Evolve Cybersecurity Strategies to Address AI Threats
AI systems require a dynamic and adaptable security strategy to keep pace with emerging threats. Key actions include:
- Understanding AI Risks: Mitigate vulnerabilities such as data poisoning, model manipulation, training data theft, adversarial examples, and prompt attacks.
- Leveraging AI for Security: Employ AI to enhance threat detection and response initiatives.
- Building Cyber Resilience: Develop a comprehensive incident response plan tailored to AI-specific challenges, ensuring clear protocols for detecting and resolving security incidents.
By continuously refining their security strategies, organizations can bolster their defenses against the rapidly evolving threat landscape.
Balancing Innovation and Risk
Security leaders face the challenge of navigating the dual pressures of rapid AI innovation and increasing risks. A layered security approach — combining human oversight, robust safeguards, technical controls, and proactive threat defense — can help organizations unlock AI's potential while safeguarding their systems and data. This strategy positions organizations for a secure, innovative future in an AI-driven world.
Does DORA Apply to AI?

It is crucial that the AI system complies with the security and resilience standards defined by both DORA and the AI Act, and that the DORA ICT risk management processes are integrated with AI risk assessment.
What Is the Relationship Between AI, Quantum, and Cybersecurity?
The rapid advancements in quantum computing, which could potentially compromise internet encryption, alongside the ongoing cyber challenges driven by AI and machine learning (ML), raise an important question: can AI/ML also play a role in defense?
The concept involves countering technological threats with advanced technology. By integrating AI/ML with post-quantum cryptography (PQC), organizations can create an adaptive cybersecurity framework capable of defending against a diverse array of threats, including those posed by both quantum computing and AI itself.



