Accelerate AI impact with our new AI Enablement & Productivity Assessments!
Register for the Free Beta Program
AI

AI Security: Operationalizing the Protection of Sensitive Data and Systems

AI security maturity model and secure AI adoption

AI security protects sensitive data, systems, identities, and operations as organizations expand AI adoption across everyday work, applications, models, and increasingly autonomous agents.

AI creates new ways to work and new ways for sensitive data and systems to be exposed.

An employee pastes confidential information into an unapproved AI tool. A development team connects an AI application to enterprise data using credentials handled manually.

An agent receives broader permissions than it needs. A new model is deployed without a defined security review. Prompt injection manipulates an AI application's behavior in ways its designers did not intend.

Individually, these look like isolated technical issues.

At enterprise scale, they represent a broader challenge:

AI adoption expands the security surface faster than organizations strengthen the controls surrounding it.

IBM's 2025 Cost of a Data Breach research found that 13% of organizations reported breaches involving AI models or applications, and 97% of those organizations reported lacking proper AI access controls. Sixty percent of AI-related security incidents resulted in compromised data.

The risks are also increasingly specific to AI.

OWASP's guidance for LLM and generative AI applications identifies threats including prompt injection, sensitive-information disclosure, improper output handling, and excessive agency, risks that require organizations to extend traditional security practices into AI-specific workflows.

Organizations don't simply need their security teams involved in AI.

They need an operational capability for AI Security.

 

What Is AI Security?

AI security is the organizational capability to apply clear expectations and controls that protect sensitive data, systems, identities, models, and operations when AI is used.

That includes familiar security disciplines such as:

  • Identity and access management
  • Data protection
  • Credential and secrets management
  • Secure architecture
  • Threat modeling
  • Monitoring
  • Incident response

But those disciplines must also address AI-specific technologies, risks, and workflows.

A stronger AI Security capability helps organizations answer practical questions such as:

  • Which AI tools are approved?
  • What sensitive information can AI access?
  • How should credentials and secrets be handled?
  • What access does an AI application or agent actually need?
  • How are prompts, outputs, and data flows protected?
  • What security requirements must an AI solution satisfy before deployment?
  • Where should AI security reviews occur?
  • How are AI-specific threats detected?
  • How do controls change as AI systems gain more autonomy?
  • How do security protections scale as AI adoption expands?

NIST identifies Secure and Resilient as a core characteristic of trustworthy AI and emphasizes incorporating security throughout the AI lifecycle. Microsoft's AI security guidance similarly addresses data protection, access controls, threat modeling, monitoring, and data-loss prevention throughout AI implementation.

The objective is not to prevent people from using AI.

It is to establish clear, repeatable protections that enable valuable AI use without unnecessarily exposing enterprise data, systems, or operations.

 

Figure Out Where You Are

Before strengthening AI Security, identify how consistently AI-specific protections are defined, shared, embedded into workflows, and improved today.

LAI's AI Security Maturity Model uses five stages to describe that progression.

Organizations looking for a broader baseline can use LAI’s AI Readiness Assessment to evaluate AI Security alongside governance, ethics, technology, data, fluency, and other capabilities required to scale AI responsibly.

Stage

Where You Are

Primary Focus

Starting

AI is already being used, but approved tools, data boundaries, access expectations, and AI-specific security requirements remain unclear.

Establish a basic security baseline for AI use.

Emerging

Security appears in AI discussions and reviews, but involvement remains inconsistent and reactive.

Turn recurring AI security questions into shared requirements.

Enabling

Common AI security controls, review practices, and technical requirements are defined and repeatable.

Create predictable protections across different AI use cases.

Operationalizing

Security controls are embedded into architecture, development, deployment, access, and production workflows.

Ensure AI security consistently reaches the work that requires it.

Optimizing

Security continuously improves based on threats, incidents, red-team findings, usage patterns, and changes in AI capability.

Make AI security stronger and more scalable as AI adoption expands.

 

The objective is not to apply every possible security control to every AI use case.

It is to understand where AI security stands today, which protections remain inconsistent, and what capability needs to improve next.

 

The AI Security Maturity Model

LAI's AI Security Maturity Model describes how organizations progress from unclear AI-specific security expectations toward protections that are integrated into the way AI solutions are designed, built, deployed, operated, and improved.

The five stages are:

Starting → Emerging → Enabling → Operationalizing → Optimizing

The progression moves from:

Unclear Protections → Early Security Practices → Shared Controls → Workflow-Embedded Security → Continuous Threat Improvement

At first, organizations establish basic boundaries around tools, data, credentials, and access.

Early AI initiatives reveal recurring security risks.

Shared controls make protections more consistent.

AI operationalization embeds those protections directly into the lifecycle of AI-enabled work.

Monitoring, incidents, testing, and threat intelligence then strengthen the security capability over time.

 

Five stages of AI security maturity

Starting: AI Security Expectations Are Unclear

At the Starting stage, AI is already being used, but AI security expectations and controls remain largely undefined.

Employees are unsure which AI tools are approved. Sensitive information enters AI systems without clear guidance. Credentials are manually copied into development environments.

Teams deploy models or applications without consistently considering AI-specific security requirements.

The organization relies heavily on existing cybersecurity practices and individual judgment to manage a changing class of risks.

 

What This Looks Like

Common signals include:

  • No AI-specific security policies
  • Unrestricted or poorly understood AI tool access
  • Manual credential handling
  • No defined AI model-security requirements
  • Unclear data boundaries
  • Limited visibility into Shadow AI

A particularly important symptom is Shadow AI—employees using AI applications the organization has not approved or does not know about.

The fundamental question remains unclear:

"What do I need to protect when I use AI, and what am I allowed to do?"

 

How to Progress to Emerging

Start by establishing a small number of clear security boundaries.

Do not attempt to create a comprehensive AI security program immediately.

Employees and teams first need clarity around:

  • Approved Tools: Which AI tools are approved for enterprise work?
  • Data Boundaries: What types of information are permitted or prohibited in AI systems?
  • Credential Expectations: How should API keys, tokens, passwords, and other secrets be managed?
  • Access: Which enterprise systems and data should an AI application or agent access?
  • Security Escalation: When does an AI use case require additional security review?

 

Practical Example: Create a One-Page AI Security Quick Guide

Create a simple guide employees and teams use before working with AI.

AI Security: Before You Use It

  • Approved AI: Use approved AI tools for enterprise information.
  • Sensitive Data: Do not enter restricted information into tools that are not explicitly approved for it.
  • Credentials: Never place passwords, API keys, tokens, or secrets directly into prompts, source code, or shared files.
  • Access: AI applications and agents should access only the information and systems required for their intended task.
  • Review: Customer-facing, production, sensitive-data, or autonomous AI uses require the appropriate security review.
  • Concern: If you are unsure, contact the appropriate AI Security or Security owner.

Then use the guide in employee AI training and developer onboarding. Individual awareness is only the starting point. These expectations become scalable when security moves from something individuals are expected to remember into shared team practices applied within real work.

The objective at Starting is straightforward:

Replace unclear AI security expectations with a shared security baseline.

 

AI security controls for data, access, and systems

Emerging: Security Enters AI Discussions and Reviews

At the Emerging stage, AI Security becomes part of AI discussions and reviews, but application still varies across initiatives.

Draft guidelines appear. Security teams participate in selected AI initiatives. Security tickets reference AI. Teams perform isolated AI security checks.

The organization increasingly recognizes that AI introduces security considerations beyond traditional technology delivery.

But involvement remains inconsistent.

One AI initiative receives a detailed security assessment while another similar use case moves forward without one.

Security participation still depends on whether someone remembers to involve the right people.

 

What This Looks Like

Observable signals include:

  • Draft AI security guidance
  • Isolated AI security checks
  • Security tickets referencing AI
  • Security teams consulted on selected AI initiatives
  • Early awareness of AI-specific threats
  • Inconsistent review timing

Security is now part of the conversation.

It is not yet a repeatable organizational practice.

 

How to Progress to Enabling

Study the security questions emerging from real AI initiatives and turn recurring issues into shared requirements.

Look for patterns:

  • Which AI tools repeatedly create security concerns?
  • Where are teams handling sensitive information?
  • Which AI applications connect to internal systems?
  • Where are credentials being handled manually?
  • Which AI outputs are exposed externally?
  • Where does prompt injection create meaningful risk?
  • Which agents have permission to take actions?
  • Which uses repeatedly require security review?

Google's Secure AI Framework recommends integrating AI security into the development lifecycle rather than relying on an after-the-fact review. SAIF addresses the security of AI systems across data, models, infrastructure, applications, and controls.

 

Practical Example: Introduce an AI Security Discovery Checklist

Before an AI use case progresses beyond experimentation, ask:

AI Security Discovery

  • Data
    • What information will the AI receive?
    • Does it include confidential, personal, regulated, or proprietary information?
  • Model
    • What model is being used?
    • Where is it hosted?
    • Are prompts or data retained or used for training?
  • Access
    • Which systems can the AI access?
    • What permissions does it require?
  • Credentials
    • How are secrets managed?
  • Outputs
    • Can AI outputs trigger actions or influence downstream systems?
  • External Exposure
    • Is the AI exposed to customers, partners, or the public?
  • Security Review
    • Does the use case require additional assessment?

Use the checklist during AI use-case discovery instead of waiting until deployment.

This moves security upstream, where teams still have choices about architecture, data, permissions, and controls.

 

Protecting AI systems from emerging security risks

Enabling: Shared AI Security Controls Are Defined

At the Enabling stage, AI Security becomes a shared and repeatable organizational capability supported by common controls and requirements.

The organization publishes security expectations. AI solutions move through defined security reviews. Teams use common controls.

Requirements around areas such as data masking, secrets management, access, monitoring, and AI-specific threats are established.

The organization moves from: "Security should probably look at this."

to: "These are the security requirements for this type of AI use."

 

What This Looks Like

Evidence includes:

  • Published AI security policy or guidance
  • Defined AI security reviews
  • Shared AI-specific security tools
  • Standard data-protection requirements
  • Defined access and identity controls
  • Standard AI threat considerations
  • Consistent monitoring requirements

Similar AI use cases increasingly receive similar protections.

 

How to Progress to Operationalizing

Create a shared AI Security Control Framework that translates security expectations into reusable technical and process controls.

Organize the controls around the AI lifecycle.

  • Data Security
    • Data classification
    • Data masking
    • Data-loss prevention
    • Encryption
    • Retention controls
  • Identity and Access
    • Least privilege
    • Managed identities
    • Role-based access
    • Secret management
    • Agent permission boundaries
  • AI Application Security
    • Prompt-injection defenses
    • Input validation
    • Output validation
    • Rate limiting
    • Tool restrictions
    • Action controls
  • Model Security
    • Approved model sources
    • Model access controls
    • Model integrity requirements
  • Monitoring
    • AI activity logging
    • Access logging
    • Security-event monitoring
    • Agent action logging

OWASP's GenAI security guidance highlights risks such as prompt injection and sensitive-information disclosure, reinforcing the need for protections specifically designed around AI systems.

Google's AI security guidance similarly emphasizes data protection, monitoring, access controls, and security protections across AI workloads.

 

Practical Example: Create an AI Security Requirements Matrix

Define required security controls according to the characteristics of an AI use case.

AI Use

Required Security Controls

Internal productivity assistant

Approved tool + data classification + DLP

Internal RAG application

Identity + permission-aware retrieval + logging + data controls

Customer-facing AI

Threat modeling + input/output protection + monitoring + security review

AI agent with system access

Least privilege + tool restrictions + action logging + approval controls

AI processing restricted data

Masking + encryption + strict access + formal approval

 

Create a reusable AI Security Review that references the matrix.

Teams should understand before implementation:

What controls apply → Why they apply → How they demonstrate compliance

The objective is to make secure AI practices predictable rather than dependent on individual interpretation.

 

AI security embedded into delivery workflows

Operationalizing: AI Security Becomes Part of Standard Workflows

At the Operationalizing stage, AI Security is embedded into the standard workflows through which AI solutions are designed, built, deployed, accessed, operated, and changed.

This represents the shift from having defined AI security controls to AI operationalization of those controls.

Security is integrated into:

  • Architecture reviews
  • Delivery workflows
  • Access processes
  • Deployment pipelines
  • Production monitoring

Controls increasingly occur as part of the workflow rather than through separate manual intervention.

Sensitive-data scans run automatically. Access is provisioned through defined mechanisms. AI security requirements appear in architecture reviews.

Teams measure whether protections are consistently reaching applicable AI use cases.

 

What This Looks Like

Observable evidence includes:

  • AI Security included in architecture reviews
  • Automated sensitive-data scanning
  • Automated access controls
  • Security checks incorporated into pipelines
  • AI-specific threat testing
  • Production AI monitoring
  • AI security performance measured

At Enabling: Security controls are defined.

At Operationalizing: Those controls consistently reach the AI work that requires them.

 

How to Progress to Optimizing

Embed AI Security directly into the lifecycle through which AI solutions move from idea to production.

For example:

  • AI Use-Case Discovery → Identify sensitive data, systems, users, and autonomy
  • Architecture → Threat model and determine required controls
  • Build → Apply secrets management, access controls, and data protection
  • Test → Conduct security testing, prompt-injection testing, and data-leakage testing
  • Deploy → Validate required security policies and controls
  • Operate → Monitor access, threats, outputs, actions, and incidents
  • Change → Reassess security requirements when capabilities, integrations, data, or autonomy materially change

Microsoft's AI security guidance recommends data-loss prevention, secure access, monitoring, and AI-specific protections throughout AI implementation. Google similarly recommends applying AI security across the full lifecycle rather than securing only the deployed model or application.

 

Practical Example: Build AI Security Into the Delivery Pipeline

Take one production AI application and introduce security checkpoints throughout its lifecycle.

  • Before Development
    • Require:
      • Data classification
      • Initial threat assessment
      • Security owner
  • During Build
    • Automatically check:
      • Secrets in source code
      • Dependency vulnerabilities
      • Sensitive information
      • Infrastructure configuration
      • Access policies
  • Before Deployment
    • Validate:
      • Security review completed
      • Required DLP rules active
      • Access follows least privilege
      • Logging enabled
      • AI-specific threat tests completed
  • In Production
    • Monitor:
      • Unauthorized data access
      • Prompt-injection indicators
      • Sensitive-data leakage
      • Unexpected model or agent behavior
      • Permission changes
      • Security incidents
    • Then measure:
      • Security Review Coverage: What percentage of applicable AI use cases complete required security review?
      • Sensitive Data Violations: How often are inappropriate data exposures detected or blocked?
      • Access Violations: Where are unauthorized attempts or excessive permissions appearing?
      • AI Security Incidents: What confirmed AI-related security events occur?
      • Time to Remediate: How quickly are identified issues addressed?

The objective is to move from: "Security reviews our AI applications."

to: "Security controls are part of how AI applications are built and operated."

 

Continuous improvement of AI security controls

Optimizing: AI Security Continuously Adapts to New Threats

At the Optimizing stage, AI Security becomes a continuously improving capability that adapts based on threat intelligence, incidents, testing results, usage patterns, and changes in AI systems.

AI security cannot remain static. Models evolve. Agents gain autonomy. New attack techniques appear. Employees adopt new tools.

AI applications gain access to additional systems and data.

The organization's security capability must evolve with them.

At this stage, teams intentionally improve AI Security based on:

  • Threat intelligence
  • Security incidents
  • Red-team results
  • Security testing
  • Usage patterns
  • Permission changes
  • New integrations
  • Changes in AI capability

 

What This Looks Like

Observable signals include:

  • Periodic AI Security KPI reviews
  • Security policies updated based on learning
  • AI red-team exercises
  • Control improvements based on testing
  • Permission and access reviews
  • Improving incident and remediation trends

The question shifts from: "Are our AI systems secure?"

to: "What have we learned about our AI security posture, and what should change?"

 

How to Sustain and Continuously Improve

Create a continuous AI Security improvement loop:

Monitor → Test → Learn → Improve → Retest

Examine both real incidents and simulated attacks.

Ask:

  • What AI threats are appearing?
  • Which controls detect them?
  • Which attacks bypass existing protections?
  • Are access permissions broader than necessary?
  • Where is sensitive information being exposed?
  • Which agents have gained new capabilities?
  • Which security requirements create unnecessary friction?
  • Which policies need updating?
  • What should be automated next?

Red teaming becomes particularly useful at this stage.

Google's Secure AI Framework includes AI red teaming as a way to test defenses and understand whether organizations detect and respond effectively to attacks on AI systems. Microsoft also provides AI red-team guidance focused on vulnerabilities, attack techniques, and defenses.

 

Practical Example: Run a Quarterly AI Security Review and Red-Team Exercise

Review important AI systems across five areas.

  1. Security Incidents
    1. What occurred?
    2. What data or systems were affected?
    3. Which control failed?
    4. What changed afterward?
  2. Access
    1. Do AI applications still require every permission they have?
    2. Are agents operating with least privilege?
    3. Have new integrations increased exposure?
  3. Data Protection
    1. Where is sensitive information being used?
    2. Are masking and DLP controls working?
    3. Where are violations occurring?
  4. Threat Testing
    1. Red-team selected AI systems against scenarios such as:
      1. Prompt injection
      2. Attempts to reveal sensitive information
      3. Unauthorized tool execution
      4. Privilege escalation
      5. Manipulated context or retrieved content
      6. Abuse of agent autonomy
  5. Improvements
    1. For every meaningful finding, decide:
    2. Strengthen → Automate → Restrict → Monitor → Remove
    3. Turn the decisions into an AI Security Improvement Backlog.
 

Improvement

Reason

Measure

Automate sensitive prompt detection

Data leakage attempts increasing

Leakage incidents

Reduce agent permissions

Access broader than required

Excess permissions

Add prompt-injection testing

Red team bypassed controls

Test success rate

Strengthen secret management

Manual credentials still detected

Secret violations

Update security training

New agent risks emerging

Security adherence

 

Then examine the trends.

  • Are incidents changing?
  • Are controls catching problems earlier?
  • Is remediation becoming faster?
  • Are teams able to implement secure AI with less manual intervention?

Optimization means AI Security becomes stronger and more scalable as AI adoption expands.

 

Key Takeaway

AI Security maturity isn't achieved when an organization publishes an AI security policy. It is demonstrated when clear protections consistently safeguard sensitive data, identities, systems, and operations throughout AI-enabled work—and those protections continuously improve as threats and AI capabilities evolve.

 

From AI Adoption to AI Security Operationalization

AI operationalization requires security protections to evolve from isolated reviews into shared controls embedded throughout the lifecycle of AI-enabled work.

Security easily becomes disconnected from AI adoption. Employees experiment first. Security reviews later. Controls are added after problems appear.

That approach becomes increasingly difficult as AI use expands across applications, data sources, agents, and business workflows.

The AI Security Maturity Model progresses from:

Unclear Controls → Early Security Practices → Shared Controls → Workflow-Embedded Security → Continuous Improvement

At first, organizations establish basic security boundaries. Early reviews reveal recurring risks. Shared controls make protections repeatable. Workflow integration makes AI security operational.

Monitoring, incidents, red teaming, and organizational learning continuously strengthen the system.

That is the difference between:

Securing individual AI projects

and:

AI operationalization with security built into the operating model

The objective is not to remove every possible risk before allowing AI use.

It is to establish security controls proportionate to the data, systems, autonomy, and potential consequences involved—while making secure AI use easier to execute consistently as AI adoption scales.

 

AI Beta Program

Evaluate Whether AI Security Is Embedded in the Work

Having cybersecurity policies and security teams involved in AI establishes a starting point.

The more important question is whether AI-specific protections consistently reach the data, applications, models, agents, and workflows that require them.

Lean Agile Intelligence helps organizations establish a baseline across AI capabilities and determine whether practices remain dependent on individual interpretation, have become shared across teams, or are embedded into standard AI workflows.

For AI Security, that means evaluating whether data protections, identity and access controls, secrets management, AI-specific threat protections, security reviews, monitoring, and continuous improvement are defined, repeatable, measurable, and integrated into everyday AI-enabled work.

Establish where your AI security capability is today and identify the next practices needed to support secure AI adoption at scale.