AI security field guide

AI changes the attack surface.
The basics still matter.

AI can make fraud more convincing and software more autonomous. Our focus is what you can verify, restrict, test and recover—not hype, and not unreliable “AI detection” tricks.

00 /Three situations. Three first moves.

A familiar voice asks for money

Hang up and call the person on a number you already know. A voice is no longer proof of identity.

An AI tool asks for sensitive data

Stop before pasting it. Treat public AI tools like an external service unless your organization has approved the use.

An AI agent can take actions

Limit its tools and permissions. Require ordinary authorization and human approval for consequential actions.

01 /Start with your situation

02 /What this desk covers

01

Protect people

Deepfake impersonation, cloned voices, synthetic identity fraud, sextortion and AI-assisted phishing.

02

Use AI safely

Privacy, confidential data, unreliable outputs, workplace rules and safe use of connected AI tools.

03

Secure AI systems

Prompt injection, poisoned data, insecure output handling, excessive agency, model theft and supply-chain risk.

04

Govern the risk

AI inventories, impact assessment, vendor review, testing, incident response and changing legal duties.

Research method

Where the information comes from

We start with primary material: standards, regulators, security agencies, original research and documented incidents. Vendor blogs can explain their own products; they do not establish industry-wide facts. Fast-changing claims are dated and checked against the original source.

Source shelf reviewed July 27, 2026

Editorial boundary

This section separates observed attacks from lab demonstrations, and security guidance from legal advice. “AI-generated” labels and detector scores are signals—not proof. Important claims should be verified through provenance, context and an independent channel.