Know what is in use
Identify AI services, connected apps, the people using them, and the data they can access. Offer an approved route for common tasks.
AI is changing the work.
Security needs to cover the whole organization.
A practical map for leaders: five areas to protect, the capabilities that help, and the evidence to ask for.
Find your starting pointStart with the people, systems,
and decisions you depend on.
Select an area to explore it.
Know what you have. Name an owner. Set the rules. Keep evidence that they work.
Sensitive information can leave through an unapproved tool. A convincing message can trick someone into handing over access.
Identify AI services, connected apps, the people using them, and the data they can access. Offer an approved route for common tasks.
Warn or block sensitive transfers where policy requires it. Check app permissions and detect suspicious messages and account activity.
Confirm payment, account-change, or sensitive-data requests through a separate trusted channel. Do not share passwords or sign-in codes. Give people a simple way to report concerns.
Workplace IT + security + privacy
WHAT TO KEEP IN MINDDiscovery can miss personal accounts or unmanaged devices. Polished text alone does not prove AI involvement; blocking prompts cannot eliminate deception.
Names you may encounter in a buying conversation. Products often span several areas.
An agent can mistake a hostile document for an instruction and use its permitted tools in a harmful way. Excessive access can make the damage worse.
Record each agent, its purpose, identity, tools, data access, and accountable owner. Include agents supplied by vendors.
Restrict tools, destinations, credentials, and permissions to the task. Treat instructions found in documents or websites as untrusted input.
Require approval for high-impact actions. Record tool calls and outcomes. Test whether revoking access actually stops a running agent.
AI platform + application owners + security
WHAT TO KEEP IN MINDA prompt filter or a written rule is not an access boundary. These controls apply to agents you operate or procure; they do not govern an attacker’s agents.
Names you may encounter in a buying conversation. Products often span several areas.
A stolen key or an exposed service can give an intruder access to connected systems and sensitive records.
Map exposed services and permissions. Remove unnecessary access, protect secrets, and separate sensitive systems.
Connect identity, cloud, and data-access events. Investigate unusual sign-ins, privilege changes, and unexpected data movement.
Be able to revoke credentials, isolate workloads, and preserve evidence. Test restoration and recovery for essential services.
Cloud platform + identity + security operations
WHAT TO KEEP IN MINDGood configuration does not catch every misuse of legitimate access. Behavior monitoring depends on available logs, reliable detection, and timely response.
Names you may encounter in a buying conversation. Products often span several areas.
A flaw in an application or a third-party component can become an entry point. A rushed fix can introduce a new problem.
Inventory software and dependencies. Combine security testing with AI-assisted review; prioritize flaws by exposure, exploitability, and business impact.
Use AI where useful to explain findings and draft changes. An accountable reviewer checks the security reasoning and the effect on the application.
Test that the flaw is addressed and essential behavior still works. Use an approved deployment process, a rollback plan, and checks on the running system.
AI can assist across the process. A person or an approved policy authorizes the release; a rollback path protects the running service.
Engineering + application security + service owners
WHAT TO KEEP IN MINDAI can miss flaws, invent findings, or propose insecure repairs. No tool finds and patches every vulnerability; a suggested change is not a deployed fix.
Names you may encounter in a buying conversation. Products often span several areas.
Clues can sit across separate tools while an intrusion continues. An automated response can also disrupt legitimate work.
Collect relevant identity, cloud, application, and agent events with timestamps. Protect log integrity and limit access to sensitive content.
Use AI to organize evidence, suggest hypotheses, and draft detections. Keep links to original events so analysts can check the conclusions.
Define which actions can be automated and which require approval. Test playbooks, keep action records, and rehearse containment and recovery.
Security operations + incident response
WHAT TO KEEP IN MINDMore data or a faster summary does not guarantee a correct conclusion. Security AI needs its own access limits, evaluation, and oversight.
Names you may encounter in a buying conversation. Products often span several areas.
The useful question is what you can control. Your organization can limit its own agents—and protect its systems even when an attacker controls the AI.
In the 2025 AI-orchestrated espionage case, attackers used AI to perform much of the tactical work. The organizations being targeted did not control that AI. Read the sourced case ↗
Find exposed systems and fix reachable flaws.
Explore the controls ↗Limit permissions and protect credentials.
Explore the controls ↗Spot unusual access and interrupt the intrusion.
Explore the controls ↗This is an illustrative control map, not a reconstruction of every step or evidence that these controls were absent. Control mapping is editorial analysis, not proof of prevention.
In the evaluation-pipeline attack reported as GTG-50020, malicious instructions caused a defender’s AI workflow to release access keys. Read the sourced case ↗
Treat outside text as data, not trusted authority.
Explore the controls ↗Check tool permissions; keep secrets outside untrusted tasks.
Explore the controls ↗Limit its reach, detect misuse, and revoke access.
Explore the controls ↗Prompt screening alone cannot guarantee safety. The third step describes a risk to contain, not an additional reported outcome. Control mapping is editorial analysis, not proof of prevention.
In GTG-50021, a counterfeit Claude service delivered a different model and installed software designed to steal credentials. Read the sourced case ↗
Provide approved tools and a clear way to request access.
Explore the controls ↗Check the supplier, downloads, and requested permissions.
Explore the controls ↗Detect unusual account use and remove compromised access.
Explore the controls ↗The case concerns an AI-themed lure. The source does not establish that AI carried out the attack or that all users lost credentials. Control mapping is editorial analysis, not proof of prevention.
Someone needs to own the risk—and be able to show what is being done about it.
Maintain an inventory, purpose, supplier, data access, and accountable owner.
Define allowed uses, sensitive data, approval thresholds, and requirements for vendors.
Test controls and record exceptions, incidents, coverage gaps, and remediation.
Reassess as tools, permissions, risks, and organizational obligations change.
Include the mission owner, procurement, privacy, records, and security teams. Specify where data may be processed, who can access it, what must be retained, and how essential services continue during an incident. Requirements depend on the organization and jurisdiction; this map does not establish compliance.
Start with one important workflow. Turn broad assurances into an owner, a test, and a decision.
Open the discussion briefBring the inventory, owners, permissions, and a short list of the most consequential actions.
Walk through one scenario across people, agents, cloud, software, and the response team.
Review test results, detection gaps, false alarms, patch status, and the person responsible for closing each gap.
The five-area structure is our editorial synthesis, adapted from a user-supplied Abnormal AI security concept and extended to include software. Recommendations draw on the guidance below. NIST and OWASP do not endorse this site or this particular structure.
Use these capability areas to evaluate coverage across your existing tools and any new provider. A product can cover several areas; no mapping here establishes that it would have prevented a particular incident.
Abnormal describes email, messaging, account and identity protection, AI governance, and AI-assisted mailbox triage. Its AI Governance page describes discovery, risk assessment, and governance workflows. These are vendor descriptions, not an independent effectiveness assessment.
The AI Governance page includes a roadmap disclaimer. Verify what is available today, licensing, deployment requirements, supported environments, and enforcement coverage. The supplied concept slide does not establish availability of every agent, cloud, workbench, or software capability.
Ask any provider: What is generally available? What is monitored versus blocked? Which paths are outside coverage? Can you demonstrate an end-to-end outcome in our environment? What evidence supports the claim?
Control recommendations and incident mappings are educational analysis. Effects depend on implementation, coverage, and the attack. The guide supplements established security practice, including access control, patching, backups, and incident response.
Have interviews or long-form conversations to draw from? Use our research prompt to extract useful explanations, decisions, and source references—while separating opinions, product claims, and verified facts.
Produces a sourced brief and structured records for editorial review.
Download the framework data ↗