Evidence over alarm
+ THE AI SECURITY FRAMEWORK

From awareness
to action.

AI is changing the work.
Security needs to cover the whole organization.

A practical map for leaders: five areas to protect, the capabilities that help, and the evidence to ask for.

Find your starting point
FOR ENTERPRISES & GOVERNMENTS · NO TECHNICAL BACKGROUND NEEDEDStart a leadership conversation ↓
THE ORGANIZATION AT A GLANCE
FIVE AREAS. ONE SHARED FOUNDATION.

Where does your
organization need a boundary?

Start with the people, systems,
and decisions you depend on.
Select an area to explore it.

Governance

Know what you have. Name an owner. Set the rules. Keep evidence that they work.

Protect your own AI. Strengthen defenses against AI-enabled attackers.A map of responsibilities, not a maturity score.
AREA 01 / The AI people use

Make safe use easier.

Open the full guide

Sensitive information can leave through an unapproved tool. A convincing message can trick someone into handing over access.

01

Know what is in use

Identify AI services, connected apps, the people using them, and the data they can access. Offer an approved route for common tasks.

02

Protect the moment of sharing

Warn or block sensitive transfers where policy requires it. Check app permissions and detect suspicious messages and account activity.

03

Verify consequential requests

Confirm payment, account-change, or sensitive-data requests through a separate trusted channel. Do not share passwords or sign-in codes. Give people a simple way to report concerns.

ASK TO SEE THE EVIDENCE

Show one sensitive-data test from warning to resolution, and list the apps and devices that are outside coverage.

WHO SHOULD OWN THIS?

Workplace IT + security + privacy

WHAT TO KEEP IN MIND

Discovery can miss personal accounts or unmanaged devices. Polished text alone does not prove AI involvement; blocking prompts cannot eliminate deception.

What are these technologies called?

Names you may encounter in a buying conversation. Products often span several areas.

AI usage discovery
Find which AI services and connected apps people use.
Data loss prevention
Detect or restrict sharing of specified sensitive information.
Email and messaging security
Identify suspicious messages and attempts to impersonate trusted people.
Identity protection
Detect suspicious account access and reduce account takeover risk.
Choose another area ↑
CONNECT THE INCIDENT TO THE DEFENSE

Where can you
interrupt the chain?

The useful question is what you can control. Your organization can limit its own agents—and protect its systems even when an attacker controls the AI.

Protect what the attacker can reach.

In the 2025 AI-orchestrated espionage case, attackers used AI to perform much of the tactical work. The organizations being targeted did not control that AI. Read the sourced case ↗

01 / POSSIBLE ATTACK PATH

Look for a way in

A PLACE TO INTERVENE
Software

Find exposed systems and fix reachable flaws.

Explore the controls ↗
02 / POSSIBLE ATTACK PATH

Use access to move further

A PLACE TO INTERVENE
Cloud

Limit permissions and protect credentials.

Explore the controls ↗
03 / POSSIBLE ATTACK PATH

Reach and copy sensitive data

A PLACE TO INTERVENE
Security operations

Spot unusual access and interrupt the intrusion.

Explore the controls ↗

This is an illustrative control map, not a reconstruction of every step or evidence that these controls were absent. Control mapping is editorial analysis, not proof of prevention.

ACROSS ALL FIVE AREAS

Governance is the foundation.

Someone needs to own the risk—and be able to show what is being done about it.

01

Discover & assign

Maintain an inventory, purpose, supplier, data access, and accountable owner.

02

Set policy

Define allowed uses, sensitive data, approval thresholds, and requirements for vendors.

03

Check the evidence

Test controls and record exceptions, incidents, coverage gaps, and remediation.

04

Review & improve

Reassess as tools, permissions, risks, and organizational obligations change.

For public institutions and sensitive environments

Include the mission owner, procurement, privacy, records, and security teams. Specify where data may be processed, who can access it, what must be retained, and how essential services continue during an incident. Requirements depend on the organization and jurisdiction; this map does not establish compliance.

YOUR NEXT LEADERSHIP MEETING

Ask for a demonstration.
Then ask what it missed.

Start with one important workflow. Turn broad assurances into an owner, a test, and a decision.

Open the discussion brief
  1. 01

    What can our AI access and change?

    Bring the inventory, owners, permissions, and a short list of the most consequential actions.

  2. 02

    Where would we notice or stop misuse?

    Walk through one scenario across people, agents, cloud, software, and the response team.

  3. 03

    What proof do we have—and what is uncovered?

    Review test results, detection gaps, false alarms, patch status, and the person responsible for closing each gap.

WHY YOU CAN TRACE THIS GUIDE

Capabilities first.
Evidence always.

The five-area structure is our editorial synthesis, adapted from a user-supplied Abnormal AI security concept and extended to include software. Recommendations draw on the guidance below. NIST and OWASP do not endorse this site or this particular structure.

How should you evaluate a provider—including Abnormal?

Use these capability areas to evaluate coverage across your existing tools and any new provider. A product can cover several areas; no mapping here establishes that it would have prevented a particular incident.

WHAT PUBLIC MATERIAL SAYS

Abnormal describes email, messaging, account and identity protection, AI governance, and AI-assisted mailbox triage. Its AI Governance page describes discovery, risk assessment, and governance workflows. These are vendor descriptions, not an independent effectiveness assessment.

WHAT TO VERIFY BEFORE BUYING

The AI Governance page includes a roadmap disclaimer. Verify what is available today, licensing, deployment requirements, supported environments, and enforcement coverage. The supplied concept slide does not establish availability of every agent, cloud, workbench, or software capability.

Ask any provider: What is generally available? What is monitored versus blocked? Which paths are outside coverage? Can you demonstrate an end-to-end outcome in our environment? What evidence supports the claim?

Control recommendations and incident mappings are educational analysis. Effects depend on implementation, coverage, and the attack. The guide supplements established security practice, including access control, patching, backups, and incident response.

A GUIDE THAT CAN KEEP LEARNING

Bring the context.
Keep the evidence.

Have interviews or long-form conversations to draw from? Use our research prompt to extract useful explanations, decisions, and source references—while separating opinions, product claims, and verified facts.

Get the transcript research prompt

Produces a sourced brief and structured records for editorial review.

Download the framework data ↗