Why most organizations are getting AI security wrong (and why it’s about to catch up with them)
AI security fails when control isn't embedded where AI makes decisions
There’s a pattern starting to emerge with AI.
At first glance, everything looks like progress. AI is being adopted quickly, embedded into products, talked about in boardrooms, and pushed into real-world use faster than anything we’ve seen before. But as businesses become more accustomed to AI and increasingly find new ways to use it, there is a greater problem brewing that has the potential to be detrimental to a company’s cybersecurity posture.
Organizations are moving quickly to use AI, but far fewer are making the right decisions about how it’s actually being delivered and secured. And the gap between those two things is widening, with security teams left scrambling to fix vulnerabilities like whack-a-mole.
Director of Solutions Engineering at F5.
The speed is understandable. AI hasn’t followed the usual enterprise lifecycle. It hasn’t patiently moved from concept to pilot to controlled rollout. In many cases, it’s gone straight from experimentation into something business-critical, stitched together from APIs, models, agents, and data sources that weren’t originally designed to work together in this way.
That creates something fundamentally different. Not just another application, but something more fluid, a tool that behaves dynamically to make decisions and interact across multiple layers of the stack in real time.
And this is where the problem begins.
Where AI security currently breaks down
While the architecture that needs to be secure has changed, the thinking around security largely hasn’t, meaning traditional security measures are still being applied to situations they aren’t built for. Most organizations believe they have this covered. They’ve extended their existing controls, added new tools and invested in visibility. On paper, it looks like a sensible evolution of what they already had that keeps up with AI.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
But in reality, much of that security still sits around AI rather than within it.
These traditional methods are protecting edges, monitoring outcomes and analyzing behavior after the fact. What they’re not consistently doing is sitting in the path of execution, where decisions are actually being made, and where things can go wrong in real time. It’s this distinction that matters more than most people realize.
AI doesn’t behave like anything we’ve secured before. A single interaction isn’t just a request and a response. It’s a chain of events where a prompt is interpreted, a model responds, an agent may take action, data is retrieved, decisions are made, and outputs are generated. This all happens in one continuous flow.
The risk doesn’t exist at a single point. It exists throughout that chain. This is where prompt injection happens. It’s where models can be manipulated, where sensitive data can leak through inference and where unintended behaviors and outcomes emerge.
The cause of this isn’t always an incorrect configuration; it can also be the result of the system responding exactly as designed, just not in the way anyone expected.
The industry is starting to acknowledge this. There’s a growing recognition that runtime is where the real battle is being fought, and that securing AI means understanding how it behaves under pressure, not just how it’s built.
Moving beyond bolt-on security
But if that’s becoming clearer, why are so many organizations still getting it wrong? Well, in most cases, it comes down to how decisions are being made. AI is often being driven by innovation teams or developers, those who are closest to the opportunity and implementation of AI tools.
But that also means infrastructure and security decisions are following behind rather than shaping the architecture from the start. At the same time, there’s a tendency to default to adding more tools to plug the security gaps. Faced with a new risk, the natural instinct is to look for something new and shiny to buy that addresses it.
AI doesn’t fit neatly into that model. It doesn’t live in one place. It cuts across applications, APIs, data, and user interaction all at once. Treating AI as something you can secure with a standalone tool misses the point entirely.
What is actually needed is a different way of thinking, one that starts with looking at where control actually needs to exist. There are only so many places security can be meaningfully enforced, and for AI, one of the places that consistently matters is the flow of traffic itself.
This is the point at which requests are made, decisions are processed, and responses are returned - where behavior can be influenced the most and where policy can be enforced. Everything else, to some degree, is reactive.
This is also where the conversation around security platforms becomes more interesting. Not because AI capabilities have simply been added to existing portfolios, but because the role these platforms play is changing.
Sitting in front of applications and APIs, they have long been responsible for managing traffic, applying policy and enforcing decisions. What’s changed is that these same control layers are now being extended into AI interactions themselves.
That shift is subtle, but important, as it moves AI security away from being something that happens in isolation and closer to something that is embedded directly into how systems operate. Not bolted on, not observed from the outside, but enforced as part of the execution path.
This isn’t really about one vendor. It’s about recognizing that AI has changed the shape of the problem.
Control will define the next era of AI security
The market is still catching up. The tooling is still evolving. And most organizations are understandably feeling their way through it.
But the decisions being made now - where to place control, how to integrate security, what assumptions to carry forward from the past - will define how manageable this becomes over the next few years.
We’ve seen this before, just in a slightly different form. APIs went through a similar phase not long ago - rapid growth, fragmented control, and then a long period of retrofitting security once the risks became clear.
AI is moving faster than that ever did. The attack surface is broader, the behavior less predictable, and the consequences potentially more significant.
Which means there’s less room for getting it wrong.
The organizations that navigate cybersecurity well in the age of AI won’t necessarily be the ones that adopt AI the fastest. They’ll be the ones that understand where control needs to sit and make deliberate decisions about how it’s enforced. With AI, more than anything else, it’s not just about what you can see. It’s about where you can act.
We've featured the best endpoint protection software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
Director of Solutions Engineering at F5.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.