AI Security and Identity
Access control, data protection, and identity management for AI systems and agents. As AI models gain access to sensitive data and enterprise systems, security controls designed for human users are no longer sufficient. This topic covers the security frameworks, data governance obligations, and identity controls that apply specifically to AI.
Key board-level questions
- 1.What data can AI systems access, and how is data lineage and consent tracked?
- 2.Do we enforce fine-grained access control for AI models and agents?
- 3.How do we mitigate risks of data leakage or unintended exposure?
- 4.Are AI systems integrated into our identity and access management strategy?
Regulatory frameworks
OWASP Top 10 for Large Language Model Applications
OWASP’s LLM Top 10 identifies application security risks. These include prompt injection, insecure output handling, training-data poisoning, denial of service, and supply-chain vulnerabilities. Development and security teams use it to prioritize controls.
EU Cyber Resilience Act
The EU Cyber Resilience Act sets mandatory cybersecurity requirements for products with digital elements sold in the EU. It includes hardware and software containing AI components. Duties cover the lifecycle from design through end-of-life.
EU Data Act
The EU Data Act governs access to personal and non-personal data from connected products and related services. Data holders must share covered data with users and third parties. It also sets conditions for public bodies accessing privately held data in exceptional circumstances.
EU Digital Operational Resilience Act
DORA, Regulation (EU) 2022/2554, governs digital operational resilience for EU financial entities. Requirements cover ICT risk management, incident reporting, resilience testing, and third-party oversight. These affect financial AI systems and their technology providers.
