Skip to content

AI Security Requires New Protection Concepts Across Four Levels

Key takeaway: AI requires security boundaries through four-level governance—from training through access control to network monitoring—because AI agents act with user rights and create new attack surfaces.

Artificial intelligence intensifies cybersecurity challenges from both outside and inside simultaneously: it accelerates attacks while also operating as an autonomous agent within corporate systems. Security managers must therefore develop guardrails for AI use instead of ignoring it.

Andreas Fuchs, Director Product Management at DriveLock, distinguishes two fundamentally different AI risks for enterprises. The external risk lies in attacks becoming faster, more precise, and more automated through AI: AI systems find vulnerabilities faster than human penetration testers, generate customized phishing emails in any language, and advance malware development in shorter cycles. This is particularly critical for Critical Infrastructure (KRITIS) and manufacturing industry, which often run on legacy systems and cannot be updated weekly.

The internal risk is more subtle and invisible to many: AI agents are no longer passive chatbots, but programs that independently plan and execute tasks—directly on employee devices and in workflow processes. These agents receive voluntary access to enterprise systems and act with the rights of the logged-in user. This creates a new security question that goes beyond classical Zero Trust: not only “who may do something,” but “what may an AI do on behalf of the user?”

Fuchs recommends structuring protective measures across four levels: (1) people and organization through training and clear policies, (2) identity and access through governance that grants and revokes AI rights, (3) network and cloud through control over which data agents may transfer externally, and (4) data and applications through monitoring of sensitive access. These levels follow different logics and must not be mixed.

The central insight: blocking AI itself is not a solution—the benefits are too great. Instead, enterprises must treat AI like bamboo in a garden and guide its growth through rhizome barriers—in other words, governance structures. Security managers must reframe the internal AI risk and combat external and internal threats using different strategies.


Source: www.it-daily.net · Published 14 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: