Navigating AI Security and Assurance: AI Security Requires More than Governance
Artificial intelligence is rapidly moving from experimentation into business-critical operations. The next stage of adoption will increasingly depend on agentic AI systems that can access enterprise data, interact with other systems, and take actions with varying degrees of human oversight.
This transition can create significant business value, but it also expands the potential consequences of insecure AI across organizations and their extended vendor ecosystems.
Traditional information security and AI governance remain essential. Organizations also need reliable evidence that deployed AI systems are protected against AI-specific threats such as prompt injection, data poisoning, and the misuse of privileges granted to AI agents and applications.
Agentic AI Changes the Risk Equation
Organizations continue to expand their use of AI. According to McKinsey’s The State of AI: Global Survey 2025, 88% of organizations report using AI in at least one business function, while 62% of organizations using AI remain in the Experimenting or Piloting phase. Deloitte’s 2026 State of AI in the Enterprise report found that 74% of companies plan to deploy agentic AI within the next two years.
However, relatively few companies have the AI security programs necessary to align with their AI adoption. F5’s 2025 State of AI Application Strategy Report found that 96% of organizations are implementing AI models, but only 2% indicate they are “highly ready” for the challenges of their AI deployments.
The transition from generative AI tools to agentic AI systems represents a meaningful change in organizational risk. Generative AI systems primarily produce content or recommendations. Agentic AI systems may also access data, call APIs, use software tools, communicate with other agents, and take actions on behalf of users or organizations.
As organizations grant AI systems more authority, they can also increase the consequences of a security failure. Many organizations will adopt agentic capabilities through third-party applications and vendor-managed AI services. As a result, an organization’s AI security will increasingly depend on controls that companies throughout its technology and data supply chain implement.
Comprehensive AI Assurance Requires Four Domains
Comprehensive AI assurance requires visibility across four complementary domains:
-
Traditional information security governance
-
Traditional information security
-
AI governance
-
AI security
Together, these domains help organizations determine whether they appropriately govern an AI-enabled system, whether they secure its underlying IT environment, and whether they implement protections for threats that arise specifically from the use of AI.
Many organizations use NIST AI RMF to define AI governance controls and ISO 42001 to demonstrate AI compliance to stakeholders. ISO 42001 provides valuable guidance for establishing AI management systems, accountability structures, and risk management processes. However, this level of AI compliance does not demonstrate that organizations have addressed system-level AI threats within their environments.
ISO 42001 and HITRUST AI Security address different layers of assurance. ISO 42001 focuses primarily on governance, accountability, risk management, and continuous improvement. HITRUST AI Security focuses on security controls for deployed AI systems and their operational protection.
In simple terms, ISO 42001 answers the question, “Are you governing AI responsibly?” HITRUST AI Security Certification answers the question, “Is your AI system secure?”
AI Access Controls Become Critical as Agents Gain Authority
Agentic AI increases the importance of identity, access management, and least privilege because an agent may access enterprise data, interact with applications, invoke APIs, or take actions on behalf of a user. If an agent processes malicious instructions or operates with excessive permissions, an attacker may exploit that authority to access information or perform actions the attacker could not execute directly.
According to IBM’s Cost of a Data Breach Report 2026, 92% of organizations that experienced an AI-related breach lacked proper AI access controls.
Organizations therefore need to evaluate not only whether access controls exist, but also whether they appropriately restrict and monitor the permissions, tools, data, and actions available to an AI system.
Building Assurance for Deployed AI
As AI becomes more embedded in critical business processes, organizations will need more than evidence that they govern AI. They will need reliable evidence that they protect systems using AI against threats associated with their data, models, and actions.
For third-party risk management programs, that means identifying vendors with AI-enabled systems that can access sensitive information, support important operations, make consequential decisions, or take actions within the organization’s environment. TPRM programs should establish risk-based assurance expectations that address both foundational cybersecurity controls and AI-specific threats.
For organizations deploying AI, that means identifying the AI-enabled systems that customers and partners rely upon and demonstrating the security of those systems through a consistent, independently validated approach.
Read Navigating AI Security & Assurance to explore the complete AI assurance landscape and considerations for organizations deploying AI and managing third-party risk.