Analysis · curated 16 Jul 2026

Securing AI with a Defense-in-depth Strategy

Dossier

Coverage timeline

14 Jul 2026hornetsecurity.com 16 Jul 2026darktrace.comdope.securityhuntress.comlinkedin.com

Why it matters

Darktrace's guidance frames AI as both a new attack surface and a defensive force multiplier, offering security leaders a structured approach to managing agentic and generative AI risk across the enterprise stack.

Darktrace's blog by Nicole Carignan argues that securing AI requires a defense-in-depth strategy spanning governance, identity, data security, secure development, runtime monitoring, and incident response, rather than relying solely on model guardrails or prompt filtering. It draws on the upcoming NIST Cybersecurity Framework Profile for AI and Five Eyes guidance on careful adoption of agentic AI services.

guidance

Summary

The primary source is a vendor playbook (dope.security) framing generative AI security as two distinct problems: securing how employees use external AI tools (data leakage, shadow AI, account control) and securing the AI applications an organization itself builds and ships (prompt injection and model abuse). It argues most organizations over-invest in the novel application-security risk while leaving the immediate employee-data-leakage risk uncovered.[0]

A companion government advisory, co-authored by ASD's ACSC, CISA, NSA, the Canadian Centre for Cyber Security, NCSC-NZ and NCSC-UK, addresses the careful adoption of agentic AI services, warning that agentic AI operating across critical infrastructure and defence sectors introduces new risks of misuse, service disruption, privacy breaches and cyber security incidents that require deliberate security controls.[10]

Both sources are advisory and guidance-oriented rather than reports of a specific exploited vulnerability or a named-actor campaign; they map risk categories and recommend layered controls, frameworks (OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework), and phased governance rollouts.[0][6][7][10]

How it works

The playbook describes prompt injection and model abuse as attackers manipulating AI features an organization ships to customers, distinct from the employee-usage risks of pasting sensitive data into chatbots and using unapproved shadow AI tools and personal accounts.[0]

The government advisory characterizes agentic AI risk in operational terms: automated agents acting across IT environments can be misused or misappropriated, producing productivity losses, service disruption, privacy breaches or cyber security incidents.[10]

Key takeaways

  • Generative AI security is not a single-tool problem: employee-usage risks (data leakage, shadow AI) and application-build risks (prompt injection, model abuse) require different controls and should be prioritized by which risk is actually live in the environment.[0]
  • Five national cyber agencies jointly urge organizations to adopt agentic AI carefully, applying security controls and ongoing assurance before letting autonomous agents operate in critical or mission-critical environments.[10]
  • Established frameworks — OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework — provide reference points for splitting AI application-security work from governance work.[0][6][7]

Defensive actions

  • Start by covering the live employee-facing risks — data leakage into chatbots and shadow AI — before investing in application-layer prompt-injection defenses.: The article argues data leakage and shadow AI are the most common and immediate risks that classic controls often miss, while teams tend to buy for the novel app-security risks first.[0]
  • Deploy discovery, publish an AI-use policy, and turn on monitoring in the first 30 days; enforce account control, block personal AI logins, and run DLP in monitor mode in days 31-60; then move high-risk data types to block and stand up prompt-injection testing in days 61-90.: The playbook presents this 90-day phased sequence to build a generative AI security stack in order of live risk.[0]
  • Map controls to established frameworks — OWASP Top 10 for LLM Applications for application-security risks and the NIST AI Risk Management Framework for governance.: The article cites these frameworks as reflecting the split between app-security and governance concerns.[0][6][7]
  • For agentic AI, anticipate what could go wrong, assess how agentic risk scenarios affect operations, establish ongoing visibility and assurance, and consider reducing or eliminating low-value repetitive processes rather than automating them with agents.: The co-authored government advisory recommends these measures to protect critical infrastructure and mission-critical capabilities from agentic-AI-specific risks.[10]