AI changes the attack surface.
The basics still matter.
AI can make fraud more convincing and software more autonomous. Our focus is what you can verify, restrict, test and recover—not hype, and not unreliable “AI detection” tricks.
00 /Three situations. Three first moves.
A familiar voice asks for money
Hang up and call the person on a number you already know. A voice is no longer proof of identity.
An AI tool asks for sensitive data
Stop before pasting it. Treat public AI tools like an external service unless your organization has approved the use.
An AI agent can take actions
Limit its tools and permissions. Require ordinary authorization and human approval for consequential actions.
01 /Start with your situation
How to Protect Yourself From AI Voice, Video and Impersonation Scams
A verification-first response to cloned voices, deepfake calls, synthetic profiles and AI-assisted phishing.
For workplace useHow to Use AI Tools Without Leaking Sensitive Data
A practical checklist for prompts, uploads, connected apps, workplace data and AI-generated output.
For buildersSecuring LLM and AI Agent Applications: A Practical Baseline
Architecture and test controls for prompt injection, sensitive output, tool abuse, poisoned context and excessive agency.
For leadersAI Risk Management Checklist for Organizations
A plain-English operating checklist for AI inventory, ownership, assessment, vendor review, testing and incident response.
02 /What this desk covers
Protect people
Deepfake impersonation, cloned voices, synthetic identity fraud, sextortion and AI-assisted phishing.
Use AI safely
Privacy, confidential data, unreliable outputs, workplace rules and safe use of connected AI tools.
Secure AI systems
Prompt injection, poisoned data, insecure output handling, excessive agency, model theft and supply-chain risk.
Govern the risk
AI inventories, impact assessment, vendor review, testing, incident response and changing legal duties.
Where the information comes from
We start with primary material: standards, regulators, security agencies, original research and documented incidents. Vendor blogs can explain their own products; they do not establish industry-wide facts. Fast-changing claims are dated and checked against the original source.
Source shelf reviewed July 27, 2026
This section separates observed attacks from lab demonstrations, and security guidance from legal advice. “AI-generated” labels and detector scores are signals—not proof. Important claims should be verified through provenance, context and an independent channel.