Top AI Security Questions Every Leader Must Ask
In a discussion with security professionals, Frederic Bull, Security Officer at Gremlin, highlights critical considerations for organizations navigating AI integration. The conversation emphasizes that while concerns about data training sources remain prevalent, deeper security strategies must address data authority and integrity. Traditional principles such as least privilege, authentication, and access controls continue to play a central role in securing AI systems. Modern implementations like session-based role-based access control (RBAC) via OIDC/OBO and context-specific permission scoping ensure AI agents operate within defined boundaries. These measures, foundational to enterprise security for decades, remain essential as AI adoption expands.
The evolving threat landscape reveals significant shifts in attacker capabilities
While increased speed of vulnerability discovery and exploitation is a key factor, the broader challenge lies in the erosion of the historical asymmetry between attackers and defenders. AI has enabled adversaries to identify exploitable conditions and develop attack methods with reduced technical expertise, narrowing the gap between offensive and defensive capabilities. This trend is expected to intensify as AI models gain access to more contextual data and improve pattern recognition.
The National Vulnerability Database (NVD) has faced challenges classifying the surge in reported vulnerabilities
Highlighting systemic pressures on security infrastructure. Organizations are reevaluating staffing strategies in response to AI-driven risks. At Gremlin, the team processed over nine times the number of vulnerabilities in the past year while maintaining consistent staffing levels. This was achieved through the strategic use of large language models (LLMs) and supporting tools, which reduced mean time to resolution (TTR) by 5%. However, this success relied on experienced engineers to design and maintain these systems, underscoring the continued importance of human expertise.
AI has not eliminated staffing gaps but has transformed their nature
Requiring teams to balance automation with oversight. Hiring priorities are also evolving. While AI systems can generate outputs comparable to entry-level analysts, the ability to identify and correct confident but incorrect results remains a critical skill. This demands professionals with broad technical knowledge, familiarity with compliance frameworks, and experience managing AI workflows. The reliance on AI-generated data introduces additional risks, including potential model collapse due to lack of input diversity. Human curation of training data is increasingly vital to maintain the effectiveness of AI systems.
Recent advancements in application security demonstrate AI’s potential to shift security practices upstream
By integrating AI into the software development lifecycle (SDLC), teams can identify risks early through real-time evaluations against curated policies. This approach enables developers to address issues proactively, reducing the need for costly retroactive fixes. The integration of AI tools has also streamlined internal processes, allowing teams to handle tasks previously outsourced to external developers. As AI continues to reshape cybersecurity, leaders must prioritize layered security strategies, human oversight, and adaptive hiring practices to mitigate emerging risks.
According to Frederic Bull, Security Officer at Gremlin, “The evolving threat landscape reveals significant shifts in attacker capabilities. AI has enabled adversaries to identify exploitable conditions and develop attack methods with reduced technical expertise, narrowing the gap between offensive and defensive capabilities.”
