Five layers of risk AI security strategies should cover

0

Tony Burnside, SVP and Head of APAC, Netskope

In most organisations, AI is now operating at multiple levels. The speed of AI innovation and adoption is forcing security teams to build AI security capabilities that address these multiple layers, which is proving challenging.

According to our 2026 AI Risk and Readiness Report, 73% of companies report already having AI tools in production, but only 7% have real-time governance that technically enforces policies. And while 90% have increased their AI security budgets, almost one in three (29%) feel less secure than they did twelve months ago.

This is because most security strategies currently treat AI risk as a single problem. There are in reality five distinct challenges organisations should look to address.

Challenge 1: Employees using generative AI

Employees use large language models (LLMs) every day, and organisations are acting to secure this usage. In January Netskope Threat Labs researchers found that half of the organisations in their research group had deployed capabilities to prevent sensitive data loss when employees use genAI tools.

But the real challenge lies one level deeper. Almost half of employees (47%) use personal genAI accounts that the company does not control. And the vast majority of security teams (88%) don’t have the capability to reliably tell the difference between an authorised corporate tenant, and a personal account on the same platform, in which case data loss policies, access controls and audit trails fall short.

Enforcement should happen at the instance level, with the ability to identify not only which application is being used, but through which account, with controls adjusted in real time in response. The context of each interaction with genAI tools matters, from what was entered and which data was involved, to what the model returned. By understanding this transactional layer, organisations can provide adaptive security and enablement, rather than blunt blocking.

Challenge 2: Developers as AI integrators

Developers who integrate LLM application programming interfaces (APIs) into in-house applications introduce another risk vector. There is no human input in the traditional sense, as applications automatically send queries to external language models, process their responses, and feed the results into business processes.

These operations introduce new instances, and machine-to-machine traffic and communications protocols (such as the widely used model context protocol or MCP) that security tools designed to secure human usage do not account for. The introduction of guardrails between the application and the external model is necessary to monitor and secure them.

This security layer should provide security teams the capability to inspect and secure APIs calls and MCP traffic, read the content to enforce policies on outbound data requests, and detect inbound manipulated model responses that could cause damage. This is ultimately a data protection, and API and MCP governance problem that requires dedicated policies.

Challenge 3: In-house AI models 

To reduce their dependence and exposure via external AI models, many companies are choosing to run their own, hosted internally and trained on proprietary data. This approach shifts the burden of securing these models entirely onto the organisation.

Before deployment, they need to be tested for bias, unintended behaviour, and vulnerability to adversarial attacks. But red-teaming for AI models is fundamentally different from traditional penetration testing, which looks for known vulnerabilities in code and infrastructure. AI red-teaming targets model behaviour under adversarial conditions, which requires different skills.

After deployment, security teams also need to understand how the model responds to prompt injection attacks, and to deploy guardrails to detect malicious or manipulated inputs before the model processes them. These are risks that network gateways will never see.

Challenge 4: Autonomous agents

Autonomous AI agents are the fastest-growing security challenge, and arguably are the least covered by existing security architectures.

AI agents are already deeply embedded in enterprise environments, and a significant share are shadow deployments that IT never formally approved. They are often deployed with significant access rights across collaboration and productivity tools, inheriting extensive access privileges from the human user who set them up.

This creates a significant risk because their actions look like legitimate transactions to traditional identity and security tools that can’t distinguish a valid agent action from a compromised or malicious one. To prevent these risky actions, security teams need the ability to intercept agentic traffic and apply guardrails at the agentic communications layer (APIs, MCP…).

They should also extend zero trust principles from human users to agents. Providing minimal, but adaptive and contextual access to agents ensures they will only interact with the resources necessary for their tasks, and for the appropriate duration and reasons, which will drastically limit the potential damage if they are compromised or start behaving abnormally.

Challenge 5: Visibility

All four use cases discussed above require something most organisations currently lack: a complete, real-time picture of all AI operations within their systems. This is the foundation that everything else depends on.

Only 6% of organisations report having full visibility into all AI activity within their environment. In other words, 94% are making AI security decisions based on an incomplete picture. Achieving the necessary level of visibility, and understanding what is running in their environment at all times is the first challenge security teams should strive to overcome when defining their AI security strategy.

Most security teams would welcome a break in the successive waves of AI innovation and the new risks they continue to bring. But this is rather unlikely, and before new AI risk vectors appear, addressing those five layers should help organisations avoid the potential incidents and damage from incomplete AI security strategies.

At Netskope, we designed a platform able to cover the variety of AI risks, threats and scenarios that can emerge with the acceleration of AI usage and deployments of models and agents within organisations. With our Netskope One AI Security suite, and Netskope One AI Command Center, security teams gain full visibility and control over all AI applications, deployments, and models operating within their organisation, and the ability to apply granular and context-aware access and data loss protection policies over internal, outbound, and inbound AI traffic and transactions, whether generated by humans or machines. Our AI security suite is complemented by Netskope One AgentSkope, a growing library of AI agents designed to handle security and networking operations, and reduce SoC and NoC workloads.

For more information, visit Netskope.com/AI.

Share.