Skip to main content
Article 1

Digital Security Magazine 19th Edition

Trustworthy AI is lost without security:
Turning principles into enforceable controls

Control, Trust and accountability at scale

When it comes to controlling AI, security has only recently moved to the forefront of AI governance.

Organizations have been investing in largely policy-driven programs to mitigate harmful bias, correct inaccuracies, and work toward better explainability.  

It’s only in the past year or two that security has risen to the top of AI governance priority lists.

This gap is surprising for three reasons:

  1. The risk factor – Security violations are among the biggest risks to organizations’ AI applications and environments, especially as agentic AI systems support more critical business processes.
  2. The control factor – Most of the other categories of compliance, risk, and ethical concerns related to AI cannot be addressed without strong security controls.
  3. The compliance factor – Security is now an explicit legal requirement for AI. For example, the EU AI Act makes cybersecurity an explicit obligation for high-risk AI use cases, naming data poisoning, model evasion, and adversarial attacks as in-scope threats. Equivalent duties also apply to providers of general-purpose AI models with systemic risk.


Most of the other categories of compliance, risk, and ethical concerns related to AI cannot be addressed without strong security controls.

From principle to control: Security capabilities that support AI governance

While AI introduces new challenges to organizations and the technology programs that support them, many of the fundamental controls are familiar to security professionals. Executives looking to enforce effective AI governance measures should lean heavily on the expertise and technical capabilities of their security organization. These are some of the areas in which security professionals have built substantial capabilities and expertise, which can quickly be tuned to support AI governance.

  • Asset discovery and registration: Security typically begins with an understanding of technology assets, whether residing in the organization’s environment or connected from a third-party environment. But you can only secure assets you’re aware of. AI governance is lost without a clear understanding of what AI models, applications, and use cases are operating within the company’s purview.
  • Access control: Every AI application and use case comes with its own set of risks, compliance requirements, and ethical concerns – no two are alike. But despite these differences, well-controlled access is a necessity. That includes controlling who can access the systems and what they can do once they are accessed. And just as importantly, with agentic AI systems now such a big concern, it includes what kinds of access agentic systems are given to other corporate assets and data.
  • Monitoring: Strong monitoring capabilities are a must-have, notwithstanding whatever controls you need to put in place to address the risk, compliance, and ethical concerns of your AI applications. This includes operational monitoring to understand the system’s functions and outputs, as well as monitoring employees, customers, and other users interacting with the systems to gauge their behaviors and experiences.
  • Employee training: Just like with security, no AI governance program is good enough to design the perfect set of technical and process controls to mitigate every potential risk. Alongside these controls, you’ll need to deploy effective employee training modules, testing, and reinforcement to drive responsible engagement with AI.
  • Incident response: When something inevitably goes wrong with an AI system, organizations will need effective tools and processes to reduce the impact and mitigate future damage. The wide range of potential incidents related to AI makes it especially important to have the kind of sophisticated workflow logic, reporting, and accountability that security teams have built at scale for the past several decades.
  • Audit: While AI-related regulations are only now coming onto the scene, it’s a safe bet that regulatory bodies will impose increasingly strict requirements for documentation of AI processes, controls, and outcomes. Once again, security teams have been through the ringer on requirements like this for more than two decades, and the control documentation and reporting capabilities they’ve developed offer a strong model for AI governance programs.

Security: The enforcement layer for AI governance

Beyond its potential supporting role, security is often an essential component for achieving critical AI governance outcomes. In fact, organizations can’t adhere to principles like fairness, reliability, quality, safety, explainability or authority without first being strong in security. Consider these examples:

  • Fairness: Eliminating unintentional and harmful biases in AI systems is often the first priority of AI governance programs, especially when these systems are being deployed in ways that determine outcomes for employees, customers, or patients. This is impossible without strong controls over AI-related data, including data security, access control, and chain-of-custody controls. Security is also key to preventing potentially predatory manipulation of AI data and applications.
  • Reliability: With Agentic AI implementations supporting more critical business processes, there’s an even greater need to ensure the continuity of AI systems. Some of the most important controls here will be more traditional backup and recovery tools and techniques, but reliability also requires effective security capabilities including threat modeling, anomaly detection, and incident response in case of attack.
  • Quality: Most AI governance programs work hard to prevent AI systems from generating inaccurate, irrelevant, and inappropriate results. In most cases, this includes preventing potential manipulation of AI systems through attacks embedded in training data or delivered via user prompts. Security teams need to be involved on both fronts to prevent malicious access and manipulation of the data and to prevent prompt injection attacks at the interface. They can help by monitoring generated content for potentially inappropriate, private, or confidential information.
  • Safety: Concerns related to safety in AI are often defined in broad terms, usually including aspects of protecting people’s physical, mental, and financial well-being. Security capabilities are necessary here to prevent access to AI systems by individuals working to defraud or manipulate other users. Monitoring capabilities can be helpful in identifying any user behavior that violates the employee code of conduct or user terms and conditions.
  • Observability: It’s impossible to implement any AI governance controls without first understanding AI’s role in the environment. Just as IT organizations have dealt with shadow AI at various points over the past 20 years, today AI governance teams are also struggling to curtail this threat. Security capabilities are essential in this effort. They can help prevent employees’ access to restricted websites, monitor application use at the endpoint, track network traffic that indicates AI operations, and analyze behavior that might suggest AI use outside of policy. And beyond mitigating risks of shadow AI, all these capabilities can also help strengthen AI governance with respect to licensing, adoption, and usage.
  • Authority: As agentic AI shifts from advising to transacting by placing orders, executing payments, modifying records, and making commitments to customers, the question, “What can an AI bind the company to?” becomes a core AI governance concern. Courts are already answering it under traditional agency law. In Moffatt v. Air Canada (2024), the British Columbia Civil Resolution Tribunal held the airline liable for promises made by its customer-facing chatbot, applying the apparent authority doctrine just as it would for any other corporate agent.


The implication for AI governance is that the technical controls constraining an agentic AI system including role-based permissions, tool and API scopes, transaction caps, human-in-the-loop approval thresholds, and output guardrails are the company’s delegation of authority policy, written in code.

These are precisely the controls security teams have built and refined for decades. In the agentic era, they are pulling double duty: preventing unauthorized actions in the security sense, while simultaneously defining the legal boundaries of what an AI can commit the organization to do, say, or pay. Without them, the company has no defensible answer when a counterparty or a regulator argues that the AI system in question was, in fact, authorized to act on its behalf.

More security, more trustworthy AI

This is a perfect moment for security to demonstrate a direct top-line and bottom-line case for involvement. Without strong security controls in place, it’s harder for an organization to convince customers that the AI systems it provides are trustworthy enough to adopt, engage with, and invest in.

Behind the scenes, trust among employees is just as important, as any AI objectives relating to product innovation, quality improvement, efficiency, or cost reduction also require individuals to have confidence that they can entrust their critical data and processes to highly capable, yet potentially risky, AI systems.

If you are looking to implement a robust security plan as a core AI governance function in your business, connect with us today and let’s chart a roadmap together.

Explore how the Atos Group has industrialized agentic AI as a governed, production‑ready capability for ourselves and our clients: AI – Atos Sovereign Agentic Studios – Atos

Share this article

X IconLinked-in Icon

Chris McClean

Global Head of AI Governance and Responsible AI

View detailsof Chris McClean >
  • Follow Chris  McClean on LinkedIn
 

Yann Dietrich

Group Head of Legal - AI, Data & IP

View detailsof Yann Dietrich >
  • Follow Yann Dietrich on LinkedIn
 

Subscribe for regular insights

Thank you for your interest. You can download the report here.
A member of our team will be in touch with you shortly

Control, Trust and Accountability at Scale

Agentic AI threat modeling: When AI starts acting

Cyber at machine speed: can your security program keep up?

Digital sovereignty in the age of AI: Control over decisions, not just data

Identity for AI Agents: The new nonhuman perimeter

Move from prediction to resilience: Navigating the new cyber equilibrium

Rethinking the AI supply chain security: Models, data, agents, tools, and the new skills layer

Securing AI workloads across the hybrid and multi‑cloud AI supply chain