As artificial intelligence increasingly becomes part of the attack surface, Katerina Tasiopoulou, CEO and Founder of Threatscene, explores the options for protecting today’s businesses.
Summary:
- AI is changing the cyber threat landscape by expanding the attack surface beyond what teams are currently used to
- AI tools are easy and cheap to deploy for bad actors, while defending against them requires investment of expertise, time and money
- The speed of AI adoption often exacerbates security risks as tools and processes are adopted faster than they can be assessed
- AI tools enhance the speed, volume and believability of existing attack types, and new types which target AI systems directly are emerging
- Reducing risk and succeeding in the AI era means treating centrally governed, monitored AI security as business as usual
For many years, security teams have understood the attack surface in familiar terms: endpoints, networks, applications, identities and third-party suppliers. Artificial intelligence is now reshaping that model.
AI introduces new assets that must be secured, new techniques that attackers can exploit, and new forms of failure that existing controls were never designed to address. Beneath this technical shift lies an economic reality: many AI tools are inexpensive or free for attackers to use, while deploying them responsibly as a defender requires investment, governance and scarce expertise.
That imbalance is already influencing how organisations need to think about cyber resilience.
What does ‘attack surface’ mean in the AI era?
Traditionally, the attack surface has been the collection of points where an attacker could gain access to, disrupt or influence an organisation. In practice, this meant vulnerable software, exposed services, weak credentials, misconfigurations and supplier risk.
AI does not replace these concerns. It adds to them.
Today’s risk footprint may include:
- foundation models and fine-tuned models
- training and inference data
- prompts and user interactions
- APIs connected to AI services
- vector databases and retrieval systems
- GPUs and specialised infrastructure
- automated workflows driven by AI outputs
Many of these components sit outside conventional security processes, creating blind spots for governance and assurance teams.
How AI is expanding risk for organisations
In many cases, AI risk is being created by the speed of adoption rather than by the technology itself. Business units are deploying AI tools faster than security teams can assess them.
For you
Be part of something bigger, join BCS, The Chartered Institute for IT.
One clear example is shadow AI: employees using unauthorised tools to summarise documents, generate code or draft communications. In doing so, sensitive information may be entered into public services without legal, contractual or security review.
Third-party AI providers also introduce a new form of supply-chain dependency. Organisations are no longer outsourcing only storage or software capability; they may be outsourcing decision support, reasoning processes and data handling to vendors whose internal controls are not always transparent.
At the same time, internal complexity grows. New service accounts, API keys, plug-ins and integrations are often created quickly, sometimes outside established identity and access management controls.
How threat actors are leveraging AI
Cybercriminals are rapidly adopting AI, often at a lower cost than defenders. Open-source models, free-tier services and criminally adapted tools such as WormGPT and FraudGPT have lowered the barrier to entry for less-skilled actors.
In practical terms, AI is being used to:
- generate more convincing phishing emails in multiple languages
- create deepfake voice and video for fraud or impersonation
- automate reconnaissance of exposed systems
- improve malware variation to evade detection
- scale scams and social engineering campaigns
The result is not necessarily a new category of attack, but a significant increase in speed, volume and believability.
Emerging AI-native threats
Alongside traditional attacks enhanced by AI, there are now threats that target AI systems directly. These include:
- prompt injection: manipulating a model through crafted inputs
- indirect prompt injection: malicious instructions hidden in files, webpages or emails
- data poisoning: corrupting training or retrieval data
- model extraction: recreating proprietary models through repeated querying
- sensitive data leakage: exposure through prompts, logs or outputs
- hallucination risk: confident but inaccurate outputs used in business processes
Frameworks such as OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework provide useful starting points.
The steps needed to reduce risk
Reducing AI risk is not about a single tool or a blanket ban. It is about bringing AI into the security disciplines that already apply to the rest of the business and extending those disciplines where AI is required.
A practical starting set of steps:
- Establish AI governance: define approved tools, acceptable use and data-handling rules, and make them enforceable rather than aspirational
- Discover and inventory AI usage: you cannot secure what you cannot see. Shadow AI needs to be found, not assumed away
- Classify data before it enters AI systems: apply the same sensitivity rules to prompts and training data as you would to any other data flow
- Apply least privilege to models, datasets, APIs and admin tools: identity is now the primary control plane for AI, as it is for cloud
- Vet AI vendors as critical suppliers: ask about data retention, training practices, subprocessors, and incident handling
- Monitor prompts, outputs, and anomalous behaviour: logging is the foundation for both detection and accountability
- Red-team AI systems: test for prompt injection, data leakage and misuse as part of normal offensive security work
- Train staff on AI-specific risks: focus on AI-enabled phishing, deepfakes and safe usage, not just generic awareness content
- Align with established frameworks: NIST AI RMF, ISO/IEC 42001, and the NCSC's Guidelines for Secure AI System Development provide structure and defensibility
None of this is free. The asymmetry with attackers will not disappear, but it can be narrowed by investing in fundamentals rather than chasing point solutions.
Future outlook
AI is becoming embedded in everyday business operations, while regulation and scrutiny continue to increase. Measures such as the European Union AI Act, sector guidance and growing insurer expectations mean boards are being asked sharper questions: where is AI used, what data does it access, and who is accountable when it fails?
The organisations most likely to succeed will not be those that moved fastest, nor those that delayed longest. They will be those that treated AI security as part of normal business management: governed centrally, monitored continuously and improved over time.
AI should not be feared, but it must be secured. The attack surface has changed, attackers have gained an economic head start, and traditional controls need to stretch further than before. The response is not exotic technology. It is governance, visibility, identity, supplier discipline, testing, training and sustained investment.
With extensive experience in global incident response units, Katerina has overseen high-profile cyber incidents and advises top organisations and government officials on cybersecurity. Katerina has received various awards, including the 'BCS Young IT Professional of the Year Award' in 2018, 'Top 100 Women in the UK, sponsored by the Sunday Times' in 2019, 'WeAreTheCity Rising Star Winner 2019,' and the 'FDM EveryWoman Rising Star Award' in 2020.
Take it further
Interested in this and similar topics? Explore BCS' books and courses:
- BCS Essentials Certificate in Artificial Intelligence
- Artificial Intelligence and Software Testing: Building systems you can trust
- Making a Case for an Information Security Management System
- Designing Digital Solutions: Architecting user experiences, processes, data and security
- Information Risk Management: A practitioner's guide