AI and cybersecurity interact in two directions simultaneously. AI is an attack surface – AI models can be manipulated, poisoned, and exploited in ways that legacy security frameworks do not address. And AI is a defensive tool – AI-powered threat detection, behavioral analytics, and automated response are materially changing the speed and effectiveness of security operations.

Organizations that govern only one direction of this relationship are exposed on the other.

MITRE ATLAS: The Framework for AI Adversarial Threats

MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) is the AI-specific equivalent of the MITRE ATT&CK framework for traditional cybersecurity. It catalogs the tactics, techniques, and case studies by which adversaries attack AI systems – providing the structured threat taxonomy that security teams need to assess and defend AI deployments. The framework is continuously updated by MITRE in collaboration with government, academia, and industry, and is referenced in NIST AI 600-1 as a key resource for AI security risk analysis.

ATLAS organizes adversarial AI attacks across the AI system lifecycle, from reconnaissance and training data manipulation to model deployment exploitation and impact. Its case study library documents real-world attacks on production AI systems – not theoretical scenarios – making it directly actionable for security teams conducting AI-specific threat modeling.

Specific Attack Classes

Data poisoning. Training data contamination that causes a model to learn incorrect associations or acquire exploitable behaviors. A model trained on poisoned data may perform normally in standard evaluation but behave adversarially on inputs with specific trigger patterns. Defenses include training data provenance verification, anomaly detection during training, and independent model validation.

Model inversion and membership inference. Model inversion attacks attempt to reconstruct private training data from model outputs; membership inference attacks determine whether a specific data record was included in training data. Both attack classes are particularly significant for organizations training AI on customer data, health records, or other sensitive information. The EDPB’s Opinion 28/2024 specifically identifies model inversion as a reason why AI models trained on personal data cannot automatically be considered anonymous.

See also  AI, Privacy, and Data Governance - The Intersection Is Unavoidable

Adversarial examples. Inputs crafted to cause AI models to produce incorrect outputs. In image classification, adversarial examples exploit the model’s learned representations to cause consistent misclassification. In fraud detection, adversarial transaction patterns may evade detection. In NLP systems, adversarial text manipulations can cause sentiment classifiers or content filters to produce incorrect labels.

Prompt injection. Malicious content embedded in inputs that hijacks the behavior of large language model-based systems – causing the model to ignore system-level instructions and follow attacker-controlled directives instead. OWASP identifies prompt injection as the top LLM security risk in 2025. For organizations using AI-powered customer service, document processing, or automated workflows, prompt injection via external input is an active threat requiring input sanitization and output validation controls.

Joint Government Guidance

In November 2023, the NSA, CISA, NCSC UK, and partner agencies released “Guidelines for Secure AI System Development” – a joint cybersecurity information sheet establishing secure-by-design principles for AI system development. The guidance addresses four key areas: secure design (threat modeling, supply chain risk), secure development (protecting model artifacts, training pipelines, and code), secure deployment (environment hardening, access controls, API security), and secure operation (ongoing monitoring, incident response, and compromise assessment).

The Canadian Centre for Cyber Security (CCCS) – Canada’s national authority on cybersecurity guidance – is a contributing partner to the international AI security guidance network established through this collaboration. Canadian organizations should monitor CCCS publications for AI-specific guidance adapted to the Canadian regulatory context.

A December 2025 NIST Cybersecurity Framework Profile for AI (Cyber AI Profile) integrates AI-specific security considerations into the CSF 2.0 framework, across three focus areas: securing AI system components (models, data, algorithms, supply chains); leveraging AI for cyber defense; and building resilience against AI-enabled threats.

The CSA AI Controls Matrix

The Cloud Security Alliance AI Controls Matrix (AICM), released September 2025, provides 243 control objectives across 18 security domains specifically designed for AI systems in cloud environments. The AICM maps to NIST AI 600-1, ISO 42001, and the EU AI Act, and provides both implementation and auditing guidelines. It is currently the most comprehensive vendor-neutral AI security control framework available to practitioners.

See also  AI Procurement and Third-Party Risk - Where AI Risk Now Enters Most Organizations

AI in Defense: Where It Is Working

AI-powered defense capabilities are producing measurable results at scale:

The IBM Cost of a Data Breach Report 2025 found that organizations using AI and automation extensively in security shortened breach lifecycle timelines by 80 days and reduced average breach costs by USD 1.9 million compared to organizations without these capabilities – the largest single cost-reduction factor identified in the report.

In financial services, behavioral analytics AI has become foundational to fraud detection. Mastercard’s AI-powered fraud detection has doubled the detection rate of compromised payment cards before fraudulent use. These results represent AI governance in practice: explainable, monitored, continuously validated models operating within defined risk parameters.

Integration with Existing Security Frameworks

AI security does not require building a parallel framework. The established frameworks already provide the architecture:

NIST CSF 2.0 (published February 2024) explicitly addresses AI-related risks within its six functions – Govern, Identify, Protect, Detect, Respond, and Recover – and notes that the AI RMF uses the same functional structure, enabling integrated risk management. The NIST CSF 2.0 document states that “cybersecurity and privacy risk management considerations and approaches are applicable to the design, development, deployment, evaluation, and use of AI systems.”

ISO/IEC 27001 – the international information security management system standard – provides the organizational and control structure within which AI security controls should be implemented. AI systems that process personal data or operate critical infrastructure should be governed within the organization’s existing ISO 27001 or equivalent ISMS scope, not as a separate framework.

Subscribe to Ethosure's Newsletter to get monthly updates on AI Governance

We don’t spam! Read our privacy policy for more info.