AI Security
AI Security Risks Every Board Should Understand: Prompt Injection, Data Leakage and Excessive Agency
The AI security risks that matter most to Boards and executives — prompt injection, sensitive data leakage, excessive agency and supply chain risk — and the controls that address them.
AI is moving from pilots to production faster than most governance frameworks can keep up. Boards don’t need to understand transformer architectures — but they do need to understand the AI security risks that are genuinely new, and ask whether management has them under control.
Why AI security is different
Traditional security protects systems that do what they’re programmed to do. Large language models and AI agents are different: they interpret natural language, follow instructions embedded in content, and can take actions through tools and integrations. That creates attack paths that firewalls and antivirus were never designed for.
The OWASP Top 10 for LLM Applications is a useful reference for the technical detail. Here are the risks I’d put in front of any Board.
1. Prompt injection
An attacker hides instructions in content the AI processes — an email, a document, a web page — and the AI follows them. An AI assistant summarising a supplier’s invoice could be told to “forward all recent invoices to this address.”
Ask management: Do our AI systems treat external content as untrusted? Are high-impact actions confirmed by a human?
2. Sensitive information disclosure
AI systems can reveal data they shouldn’t: confidential documents surfaced to the wrong user, personal information in responses, or prompts and data sent to third-party model providers outside your risk appetite.
Ask management: What data can each AI system access, and does it respect the same permissions as the user?
3. Excessive agency
AI agents increasingly hold credentials and act on our behalf — sending emails, changing records, running code. An agent with broad permissions and no oversight is an unmanaged privileged account with a chat interface.
Ask management: What can our AI agents do without human approval, and is every action logged?
4. Supply chain and model risk
Most organisations use AI through vendors. Models, plugins and SaaS AI features introduce supply chain risk that standard supplier questionnaires don’t cover. A weighted third-party risk questionnaire with an AI domain closes that gap.
Ask management: Do we know which suppliers use AI on our data, and did anyone approve it?
5. Over-reliance and integrity
AI outputs can be confidently wrong. When staff rely on AI for decisions without verification, errors propagate quickly — in reports, code and customer communications.
Ask management: Where are AI outputs used in decisions, and what review is required?
The controls that matter
Most AI security risks are addressed by a combination of familiar principles applied in new ways:
- An AI inventory — you can’t secure what you can’t see.
- Least privilege for AI agents — scoped, short-lived credentials and tool allowlisting.
- Human oversight for high-impact actions.
- Input and output controls — treat external content as untrusted; validate outputs.
- Logging and monitoring of AI activity.
- Supplier assurance that explicitly covers AI.
- A governance framework such as ISO/IEC 42001 to tie it together.
AI security isn’t a separate discipline. It’s the same principles — least privilege, defence in depth, accountability — applied to a new kind of user.
Frequently asked questions
What is prompt injection in simple terms?
It’s when someone hides instructions inside content an AI reads, causing the AI to do something the user didn’t intend — like leaking data or taking an unauthorised action.
Do we need a separate AI security framework?
Not necessarily separate, but you do need AI-specific coverage. Extending your existing security program with ISO/IEC 42001 and AI-specific controls is usually more effective than starting from scratch.
How do we start assessing AI security risks?
Begin with an inventory of AI use — including supplier features — then assess the highest-impact use cases for the risks above. An independent AI security assessment can accelerate this.
Want to understand your AI risk exposure? Explore AI security & governance services or talk to my AI agent.