
Generative AI has moved from novelty to everyday tool. Staff draft emails with it, summarize documents, write code and ask questions about company data. Increasingly, AI assistants are connected directly to mailboxes, file shares, CRMs and other business systems.
That connectivity is where the value is, and it's also where the risk is. To help our clients adopt AI safely, our team completed SANS SEC411: AI Security Principles and Practices: GenAI and LLM Defense, a hands-on course focused on how large language model (LLM) applications are attacked and how to defend them.
For our healthcare, construction, finance and insurance clients, that means AI tools can now touch patient information, bids and project files, financial records and policyholder data.
Why AI needs its own security thinking
Traditional security assumes a clear line between code and data. LLMs blur that line: the instructions a model follows and the content it reads arrive through the same channel, as text. That creates new kinds of weakness that firewalls and antivirus weren't designed to catch.
The risks businesses should understand
Prompt injection. An attacker writes instructions the model will follow. This can be direct, typed into a chatbot, or indirect, hidden in an email, web page or document that the AI is asked to read. An assistant that can send email or access files can be tricked into doing so for the attacker.
Sensitive data leakage. Employees paste contracts, patient information or financial data into public AI tools without realizing where it goes or how it may be retained.
Over-permissioned AI integrations. AI agents and connectors, including those built on the Model Context Protocol (MCP), are often given broad access "to make them useful." If the AI is manipulated, it acts with every permission it was given.
Poisoned knowledge sources. Retrieval-augmented generation (RAG) systems answer questions from your documents. If someone can plant misleading content in those sources, they can influence the answers.
Jailbreaks and unreliable output. Safety guardrails can be bypassed, and models can confidently produce wrong answers. Decisions that matter still need human review.
The OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework are useful references for these risks, and both were part of our coursework.
What an AI security program looks like
AI security isn't a single product you install. For most organizations it comes down to a few repeatable habits:
- Inventory. Know which AI tools, models and integrations are in use, who owns them, and what data they can reach.
- Threat modeling. Consider how each AI feature could be misused. Frameworks such as MITRE ATLAS catalog real techniques attackers use against AI systems.
- Guardrails. Input and output filtering, restricted tool permissions, and human approval for sensitive actions.
- Supply chain awareness. Third-party models, plugins and data sources are dependencies like any other software, and they need the same scrutiny.
- Review and update. AI capabilities change month to month, so policies and controls have to keep pace.
How Dominant-IT applies this for clients
- An AI acceptable-use policy. Clear rules on which AI tools are approved, what data may never be entered, and when human review is required.
- Choosing the right tools. Business-grade AI services with appropriate data protection terms, instead of whatever staff find on their own.
- Least privilege for AI. AI assistants and connectors get only the access they need, with high-impact actions like sending email, deleting files or making payments requiring confirmation.
- Data protection first. We identify where your sensitive data lives so it can be kept out of places AI tools shouldn't reach. This matters for HIPAA and PCI DSS environments.
- Monitoring and response. AI usage and integrations are logged and included in our monitoring and incident response planning.
- Testing and risk assessment. AI features and integrations are now part of our security assessments and penetration testing scope.
- Training your people. Staff learn what prompt injection looks like and why "the AI said so" isn't a reason to skip verification.
Questions to ask about your own AI use
- Do you know which AI tools your staff are using today?
- Is there a written policy on what data can and can't be shared with AI?
- Which AI tools are connected to your email, files or business systems, and with what permissions?
- Would you know if an AI integration did something it shouldn't?
If any of these are hard to answer, talk with us. We'll help you get the benefits of AI without handing attackers a new way in.