Generative AI has firmly established itself as a critical component of enterprise IT. CISOs are now tasked with developing AI security policies and technologies to mitigate the significant risks that come with its use. In the midst of the ongoing excitement, practical guidance for establishing AI security practices is essential for CISOs to safeguard their organizations as they adapt to new deployments and plans. By integrating effective cybersecurity policies and advanced tools, enterprises can achieve their current goals while preparing for the evolving challenges of AI.
When experts highlight the importance of mitigating the risks of a new technology on a global scale, it’s prudent to take heed. This was exemplified on May 30, 2023, when the Center for AI Safety published an open letter signed by over 350 scientists and business leaders, warning about the severe potential dangers of AI.
As the media coverage following this letter noted, focusing solely on the most extreme hypothetical threats might divert attention from the pressing AI risks we currently face, such as inherent biases and fabricated information. A recent example of this was when an AI-generated legal brief contained entirely fictitious cases, causing a legal debacle.
Our other AI blogs have addressed some immediate AI security concerns for corporate CISOs: AI’s capability to impersonate humans and execute sophisticated phishing schemes, ambiguities regarding the ownership of data processed by public AI platforms, and the overall unreliability of AI, including misinformation generated or absorbed by AI from the internet.
In my interactions with ChatGPT about network security, I have encountered incorrect information that required pressing the AI to reveal the accurate details it seemingly knew all along. While the Enterprise version of ChatGPT claims not to use user data for training, not all employees and contractors may have access to this version. Additionally, the implications of a breach in either public or private AI systems are significant and warrant consideration.
With these risks in mind, the pertinent question becomes: “What can CISOs do to enhance their organizations’ AI security?”
Establishing Robust AI Security Policies
Corporate IT security leaders have learned from experience that banning certain software and devices often backfires, increasing enterprise risk. If a tool is convenient or if sanctioned solutions don’t meet user needs, shadow IT emerges. Given that ChatGPT gained over 100 million users within two months of its launch, generative AI platforms are already integral to many workflows. Prohibiting their use could lead to a more dangerous ‘shadow AI’ problem. Moreover, many corporations are leveraging AI to boost productivity, making it difficult to block its usage entirely. If banning unapproved AI is the chosen route, detection and blocking mechanisms must be in place.
Instead, CISOs should provide access to AI tools within a framework of sensible usage policies. There are emerging examples online for large language models like ChatGPT, along with advice on evaluating AI security risks. However, standard approaches are still lacking. Even organizations like the IEEE haven’t fully addressed the issue, and while online information quality is improving, it remains inconsistent. Organizations should be selective in adopting AI security policy models.
Four Key AI Security Policy Considerations
To address the outlined risks, protecting corporate data privacy and integrity should be primary goals. Thus, any corporate policy should at least:
- Restrict Sharing Sensitive Information: Employees should be instructed not to share sensitive or private data with public AI platforms or third-party solutions outside the enterprise’s control. Gartner advises treating shared information as if it were posted publicly.
- Maintain Data Separation: Clearly separate different types of data, ensuring that personally identifiable information and legally or regulatory protected data are not mixed with public data. This may necessitate a data classification scheme.
- Validate AI-Generated Information: Confirm the accuracy of AI-generated information before using it. Requiring platforms to provide citations and verifying these references can mitigate the risk of disseminating false information.
- Adopt Zero Trust Principles: Implement zero trust to manage risks related to user, device, and application access to IT resources and data. AI’s ability to mimic trusted entities challenges zero-trust architectures, making it critical to control untrusted connections.
Choosing the Right Tools
AI security policies should be supported by appropriate technologies. New AI tools are being developed to detect AI-generated scams, plagiarism, and other misuses. These will be deployed to monitor network activities, acting like surveillance tools to identify malicious AI activity.
Current solutions like extended detection and response (XDR) can monitor for abnormal behaviors in the IT environment. XDR uses AI and machine learning to process large volumes of telemetry data to maintain network security. While not generative AI like ChatGPT, XDR is a precise and reliable security tool.
Other monitoring tools, such as security information and event management (SIEM) systems, application firewalls, and data loss prevention solutions, can manage web browsing, software use, and monitor information leaving the IT environment, minimizing risks and potential data loss.
Understanding Risk Tolerance
Beyond defining AI security policies and leveraging current and emerging tools, organizations should specify their risk tolerance to guide decisions on AI usage. The Society for Human Resource Management suggests formally determining risk tolerance to decide the extent and purposes of AI use.
The AI landscape is still in its early stages, and its future remains uncertain. However, AI is here to stay and offers significant benefits if used wisely. As AI evolves, it will increasingly be used to combat malicious AI uses. For now, a thoughtful and informed approach is the best defense.



