CONNECT WITH US
AI & Deeptech

AI & Deeptech

AI Security Is an Engineering Problem — How to Solve It at Every Layer of the Agent Stack

NVIDIA logo

Published on

Add as a preferred source on Google
AI Security Is an Engineering Problem — How to Solve It at Every Layer of the Agent Stack

AI security is an engineering problem. That means defined security requirements, enforceable controls, named owners and evidence that protections work. 

As AI becomes more capable, the industry must accelerate security engineering, broaden access to defensive tools and share what works faster. 

The internet and cloud computing changed how software operates, while core security responsibilities endured: establish identity, control access, limit exposure and verify that protections work.

AI agents introduce new capabilities — reasoning, using tools and adapting actions based on the data they encounter. Those capabilities require applying established principles to new operating conditions.

This pace creates pressure. Organizations want the productivity benefits of AI while the practices to govern and secure these systems are still developing. 

Applications depend on code, data, identities, services and infrastructure. Security depends on how those components work together — and AI agents extend that system.

Models provide capabilities; harnesses organize context, tools and workflows; and runtime environments provide the infrastructure within which actions execute. Each part of that stack carries security responsibilities, and proper protection requires controls across each layer, as data, instructions and actions move through the system. 

Consider an agent updating a customer record. Say it encounters malicious instructions in an attached document and attempts to export customer data to an unauthorized destination. 

A network policy should block the transfer, and protected logs should capture the attempted tool call, authorization decision and outcome so the security team can identify the tool used and the destination it attempted to reach. 

Permission to update a customer record should not automatically extend to exporting that data.


Source link

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We TheMorningPulse.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It's possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.