Skip to main content
Article 8

Digital Security Magazine 19th Edition

Control, Trust and accountability at scale

Securing AI workloads across the hybrid and multi cloud AI supply chain

Artificial Intelligence (AI) has come a long way in making our lives easier and more efficient. The swift rise of AI is also effectively shaping the future of hybrid and multi-cloud environments by utilizing their scalability, cost-efficiency and flexibility, but often leaving critical security oversight far behind.

Many organizations are adopting commercial AI systems without proper consideration for security and how it could be used with a malicious intent, which could in fact undermine the overall benefits of AI itself. When data is spread across these various settings, such as public clouds, private clouds, and on-premise infrastructures, it creates an extremely complicated attack surface.

Let’s close the AI oversight gap in hybrid and multi-cloud


According to IBM’s 2025 Cost of Data Breach report, breaches involving multiple environments are now the most expensive ones, costing organizations USD 5.05 million on average. Due to their complexity, they also take the longest to resolve, taking an average of 276 days (approximately 9 months!) to identify and contain.

Within these distributed environments, the AI supply chain has emerged as the primary attack target. Compromises in the supply chain, such as applications, APIs, and plug-ins, are the most common cause of incidents related to AI security. The IBM report also highlights that over 15% of breaches stem from supply chain compromises. We can name shadow AI as another industry challenge that often leads to the exposure of highly sensitive customer data. Surprisingly, 63% of data compromised due to shadow AI usage is in fact personally identifiable information (PII).

Despite the security breaches and incidents that have occurred in the sector, the same study found that 97% of organizations report lack of proper AI access controls to ensure their safety. Organizations that experienced a shadow AI security incident reported that the breached data was most often spread across multiple environments, including public cloud platforms (62%).

Effective security requires proactive cloud governance as fragmented AI tools and weak access controls can limit visibility and slow down threat response. Strong management and governance frameworks are therefore essential to ensure proper oversight and controlled use of AI and machine learning systems within the organization.

Let’s look at how we can close the gap.

Phase 1: Establish strict AI governance and compliance for safe and responsible AI use

Effective AI security is not an exception to the general approach, where security processes, measures and tools all begin with establishing the right governance. Without a proper strategy and assessment, it’s difficult to provide the right direction for the organization. Are we allowed to use AI in the organization?

If so, which use cases are allowed and which are not?
Are there any official company tools?
Only once you know what needs to be protected can you define how to protect it.

To regain control over distributed AI workloads, organizations must immediately address their policy deficit. IBM’s 2025 report indicates that 63% of breached organizations lacked AI governance policies capable of managing risk or identifying shadow AI deployments. Without defined accountability and approval mechanisms, AI workloads are often deployed inconsistently across cloud environments, creating blind spots that attackers can exploit.

To close this governance gap, organizations must implement mandatory risk-based approval processes for all AI deployments, including in-house developed models, third-party AI services, and embedded AI components within software products. For organizations with mature AI security postures, formal approval workflows are the most commonly adopted and effective governance measures. They serve as foundational control for visibility and risk assessment.

Governance frameworks must also align with emerging regulatory requirements, particularly the European Union Artificial Intelligence Act (EU AI Act). The EU AI Act introduces a risk-based approach for AI applications, such as those affecting critical infrastructure, employment, healthcare, and biometric identification. This imposes stringent compliance obligations, including documentation, risk management, and human oversight. For organizations operating across multiple jurisdictions, early alignment with these requirements reduces regulatory exposure and improves organizational readiness.

Beyond policy formulation, governance must be operationalized. This includes conducting regular audits to identify unsanctioned AI tools, integrating security and compliance teams to jointly uncover shadow AI, and investing in enterprise-wide AI literacy training. Employee awareness is particularly critical, as many shadow AI incidents originate from well-intentioned experimentation rather than malicious intent. By embedding governance into daily operations, organizations can regain visibility, control, and compliance without slowing responsible innovation.

Phase 2: NIST AI Risk Management Framework into practice

After governance has been established properly, next is risk assessment and risk management.
Securing complex AI workloads across multi-cloud environments requires a structured, repeatable approach. The National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework (AI RMF 1.0) provides such a foundation, offering a flexible yet systematic methodology for identifying, assessing, and mitigating AI-specific risks throughout the system lifecycle.

Management strategies should be built around the AI RMF’s four core continuous functions mentioned below.

  1. Govern: This foundational function builds a culture of risk management from the top down, integrating technical considerations with organizational policies to empower and train teams.
  1. Map: The focus is on context, understanding what the AI system was meant to be, its environment, data requirements, and other stakeholders. Mapping is especially helpful for identifying risks related to multi-cloud systems, which may pose threats related to data residency, international data flow, and the use of external AI systems. By fully understanding these aspects, an organization will be better able to anticipate future impacts.
  1. Measure: In this function, new measures are introduced to evaluate the AI’s trustworthiness in terms of security, robustness, privacy and bias. Measurement is ongoing and important since the AI system itself as well as its environment will change over time.
  1. Manage: The final step involves managing risks by prioritizing and addressing them.

To ensure these functions are effective throughout the entire AI lifecycle, organizations should mandate test, evaluation, verification and validation (TEVV) tasks. NIST explicitly recommends embedding TEVV from data collection and model training through deployment and post-production monitoring to detect emergent vulnerabilities, performance degradation, and unintended biases. In dynamic cloud environments, continuous TEVV is essential to maintaining trust in AI systems over time.

Phase 3: Fortify the cloud-native AI supply chain

The security of AI workloads is inseparable from the security of the software supply chain that supports them. After all, a chain is only as strong as its weakest link.

Protecting the underlying infrastructure of the AI supply chain, which is often complex and multi-cloud-based, requires cloud-native security controls.


Taking a DevSecOps approach to software development is one of the most effective factors in reducing the overall cost of a data breach, and can save organizations an average of USD 227,192 per incident as per IBM’s 2025 research.

By integrating security controls directly into development and deployment pipelines, organizations can now identify and remediate vulnerabilities earlier, when remediation is less costly and disruptive.

For cloud-native environments, guidance from the Cloud Native Computing Foundation (CNCF) Security Technical Advisory Group (TAG Security) provides a valuable reference point. Resources such as the NIST Cloud-Native Control Implementation guidance and Software Supply Chain Best Practices offer standardized controls and secure-by-default configurations tailored to distributed, containerized workloads.

These cloud-native strategies must be specifically tailored to mitigate the unique risks outlined in the OWASP Top 10 for LLMs. For example, proactive defenses must address Training Data Poisoning (LLM03), where attackers tamper with data to impair model behavior and security. Similarly, teams must heavily scrutinize their reliance on third-party integrations to prevent Supply Chain Vulnerabilities (LLM05) and Insecure Plugin Design (LLM07), which can process untrusted inputs and lead to severe exploits like remote code execution and data breaches.

Phase 4: Reinforce identity controls and AI-driven defenses

Identity and access management failures remain the dominant root cause of AI-related breaches. Organizations must strictly manage both human and non-human identities (NHIs), such as AI agents and APIs, operating within their cloud environments. This requires enforcing proper lifecycle management, utilizing vaulted credentials, and establishing continuous behavioral monitoring to ensure AI agents operate exclusively within their expected parameters. Additionally, implementing zero trust principles is of prime importance to ensure proper environment access security, and AI identities are no exception here. Interestingly, most organizations that have implemented zero trust have focused on human identities, leaving NHIs without proper monitoring and access control.

Apart from ensuring proper identity management, security teams[ES20.1][GG20.2] must enhance their efficiency by utilizing AI to handle the magnitude and complexity of the multi-cloud AI attacks.
The rule is simple: to defend AI, organizations need to adopt AI speed.
According to IBM’s 2025 Cost of Data Breach report, using AI and automation in security operations can dramatically accelerate response times and shorten the breach lifecycle by an average of 80 days. From a[ES21.1] financial viewpoint, this operational speed translates to immense savings, lowering average breach costs by USD 1.9 million compared to organizations that do not utilize AI for security.

Security in AI – A continuous process Securing AI workloads across the hybrid and multi-cloud AI supply chain is not a one-time technical exercise but a continuous management process.


As AI adoption accelerates, organizations must balance innovation with rigor by embedding governance, standardized risk frameworks, cloud-native supply chain controls, and automated defenses into every stage of the AI lifecycle.

This holistic and proactive approach is the best way to help enterprises reduce exposure, maintain regulatory compliance, and sustain trust in AI-driven systems amid an increasingly complex threat landscape.

Identifying security gaps is an essential step to help your business grow its AI footprint. Start by assessing your AI governance, reviewing your supply chain resilience, and evaluating your identity controls today. Connect with us for an unbiased assessment and guidance to help you secure your AI workloads today.

Share this article

X IconLinked-in Icon

Gabriela Gorzycka

Cybersecurity Director – Strategic Deals and Engagements Future Makers Research Community

View detailsof Gabriela Gorzycka >
  • Follow Gabriela Gorzycka on LinkedIn
 

Agata Mikos

Cybersecurity Business Development Manager

View detailsof Agata Mikos >
  • Follow Agata Mikos on LinkedIn
 

Subscribe for regular insights

Thank you for your interest. You can download the report here.
A member of our team will be in touch with you shortly

Control, Trust and Accountability at Scale

Agentic AI threat modeling: When AI starts acting

Cyber at machine speed: can your security program keep up?

Digital sovereignty in the age of AI: Control over decisions, not just data

Identity for AI Agents: The new nonhuman perimeter

Move from prediction to resilience: Navigating the new cyber equilibrium

Rethinking the AI supply chain security: Models, data, agents, tools, and the new skills layer

Trustworthy AI is lost without security: Turning principles into enforceable controls