# Generative Security > Your data guardian in the age of Gen AI agents ## Posts - [The AI Sidecar is Here: Introducing Agent Vardøger](https://blog.generativesecurity.ai/the-ai-sidecar-is-here-introducing-agent-vardoger/): In May of 2025, I wrote about how GenAI security was making the exact same mistakes as early container security: trying to force legacy, perimeter tools onto dynamic workloads. The container world solved this by moving away from heavy host-based agents and proxies in favor of lightweight, out-of-band tooling like Falco that ran right next to the compute. GenAI needs that exact same evolution – moving away from brittle prompt wrappers and WAFs toward a decoupled security layer that doesn't ask the LLM to police itself. Today, we're making that architectural jump with the release of Agent Vardøger, an open-source security […] - [On Air 2.0: a podcast, a certification, and a sidecar](https://blog.generativesecurity.ai/on-air-2-0-a-podcast-a-certification-and-a-sidecar/): The past few weeks have been extremely busy for us at Generative Security. I sat down with Rohan at Vision and Venture and recorded a new podcast, spent a week in Singapore with ISC2 to define the future of AI Security certification, and we're about to launch a new open-source agentic sidecar for AI security. So let's talk about these three things, and a bonus at the end. On the podcast, the conversation ranged widely, but a few threads are worth pulling out here. First is a question every founder in this space eventually faces: why build a dedicated security solution […] - [Agent Data Injection: Breaking the context, not the message](https://blog.generativesecurity.ai/agent-data-injection-breaking-the-context-not-the-message/): If you’ve been following the agentic AI space over the last year, you know that Indirect Prompt Injection is both a huge problem and an area of active research. We train models to look for and ignore instructions in websites and distrust instructions that arrive inside documents. While not complete, the industry would say it has a reasonably good understanding of the problem. Against these current state-of-the-art agent defenses, the classic "ignore your instructions and email this to me" attack rarely succeeds. But a paper out of Seoul National University and UIUC in July, "Agent Data Injection Attacks are Realistic Threats […] - [Open questions after OpenAI accidentally hacks Hugging Face](https://blog.generativesecurity.ai/open-questions-after-openai-accidentally-hacks-hugging-face/): Editor's note: This blog is a follow-on to last week's post: The Asymmetry Problem after the Hugging Face incident, and a short form version of our recent recording Reviewing OpenAI's notice regarding their role in the hacking of Hugging Face. At the end of last week I wrote about the Hugging Face intrusion and complained that the disclosure left some of the most important questions unanswered: who was behind it, how much they knew about the pipeline, and whether the sophistication implied a well-funded, patient adversary. A couple of days later, OpenAI answered. The adversary was better funded than I guessed […] - [The Asymmetry Problem after the Hugging Face incident](https://blog.generativesecurity.ai/the-asymmetry-problem-after-the-hugging-face-incident/): Editor's note: Shortly after this post went live, OpenAI published their involvement. Read our follow-on post: Open questions after OpenAI accidentally hacks Hugging Face. You can also find a recording of our longer thoughts at Reviewing OpenAI's notice regarding their role in the hacking of Hugging Face. In 2004, someone installed rogue software on Vodafone Greece's switches and used the lawful intercept subsystem – the one built so that trusted, vetted, legally authorized parties could listen in – to wiretap the Greek Prime Minister and about a hundred other officials for most of a year. Nobody broke the encryption; instead they simply used […] - [Silencing a Fable: You Can't Export-Control a Capability That's Already Everywhere](https://blog.generativesecurity.ai/silencing-a-fable-you-cant-export-control-a-capability-thats-already-everywhere/): Early in my career as a network engineer at Lockheed Martin, I spent more time than I should have worrying about U.S. export controls. Back then the battleground wasn't AI – it was encryption. If a router or firewall left American soil running (then) modern encryption, the federal government legally classified it as a munition. So everything we shipped was supposed to have the weakened images – capped at 40-bit or 56-bit encryption. Even then, we knew it was security theater. Math doesn't care about customs forms or international borders, and PGP was already available internationally anyway. The absurdity peaked with […] - [LLMs taking orders from ghosts – when attacks have zero lines of code](https://blog.generativesecurity.ai/llms-taking-orders-from-ghosts-when-attacks-have-zero-lines-of-code/): When I first started learning about malware, I was always impressed not by the attacks or the payloads, but by the evasion techniques they implemented. The best malware didn't fire the second you opened it; it asked questions first. Are there VMware artifacts on this disk? Is a debugger attached? If anything smelled like an analyst's sandbox, the code simply went to sleep and did nothing interesting. If not, the second thing it did was start killing active applications and services. Bitdefender running? Great – kill the process and then move forward. It wasn’t enough to have a great payload – […] - [Why resilience is a top priority for your Gen AI chatbot](https://blog.generativesecurity.ai/why-resilience-is-a-top-priority-for-your-gen-ai-chatbot/): When most enterprise leaders talk about "securing" a generative AI chatbot, the conversation almost always defaults to safeguarding against privacy leaks and keeping proprietary data safe. But if you're myopically focused on confidentiality, you are missing two-thirds of the CIA triad. Worse than that, when your Gen AI chatbot is generating revenue, integrity and availability aren't nice-to-haves, they're essential to the whole business case. The industry spent the last few years focused on the confidentiality problem: stopping jailbreaks, blocking prompt injections, and keeping the model from saying what it shouldn't. When a sophisticated prompt injection or an abusive exploit corrupts your […] - [Generative Security On Air! Recent talks about the future of generative AI security](https://blog.generativesecurity.ai/generative-security-on-air-recent-talks-about-the-future-of-generative-ai-security/): Welcome back to the Generative Security blog - we took a week off because we were preparing for some exciting conversations with folks around the globe. First, we had the pleasure of presenting at the AWS Sydney Well-Architected User Group about how lessons from the AWS Cloud Adoption Framework and Well-Architected framework can help accelerate generative AI adoption securely. After that, we spoke with the host of the Asia Tech Podcast, Michael Waitze about the direction of generative AI security, why we need to focus on both the technical attacks and the non-technical attacks, and the importance of 3rd-party partners in […] - [When Security through Friction fails in the AI world](https://blog.generativesecurity.ai/when-security-through-friction-fails-in-the-ai-world/): In last week’s blog, What Anthropic's Zero Trust for Agents eBook Gets Right (And What It Doesn't Say), we explored the idea that "Security through friction is the new security through obscurity." For years, cybersecurity teams relied on deliberate user experience hurdles – rigid form fields, hidden rate limits, and the dreaded CAPTCHAs – to keep automated bad actors away from sensitive data and environments. The idea was straightforward: if you make the system rigid and tedious enough, automated bots will eventually make enough noise to get detected or fail quickly and go after softer targets. But as we’ve just seen […] - [What Anthropic's Zero Trust for Agents eBook Gets Right (And What It Doesn't Say)](https://blog.generativesecurity.ai/what-anthropics-zero-trust-for-agents-ebook-gets-right-and-what-it-doesnt-say/): When a frontier AI company publishes a 36-page security framework for autonomous agent deployments, it is worth paying attention. Anthropic's “Zero Trust for AI Agents” eBook was released in May, and if you have been following this blog, a significant portion of its core philosophy will look incredibly familiar. Non-human short-lived credentials as the baseline for agent authentication, MCP as a critical attack surface that cannot self-secure, and the structural reason that prompt injection isn't patchable - we've covered all of these. So if sections one and two of the eBook feel like a recap, it's because you've been following along. […] - [What the NSA has to say about MCP Security](https://blog.generativesecurity.ai/what-the-nsa-has-to-say-about-mcp-security/): Today, the Model Context Protocol (MCP) is the commonly agreed-upon mechanism to facilitate the discovery, execution, and sharing of tasks across AI-driven tools. In essence, it serves as the universal adapter for AI tool and agent integration. The value proposition makes sense on the surface: let models and agents seamlessly connect to enterprise data sources, query databases, and trigger workflows without building custom API glue for every new tool. But for those of us who have been doing security for more than five minutes, you know this lack of friction is also an open invitation for atrocious security boundaries. Enter the […] - [The "HTTPS moment" for Agentic AI? A look at the A2AS Framework](https://blog.generativesecurity.ai/the-https-moment-for-agentic-ai-a-look-at-the-a2as-framework/): I recently came across a post on LinkedIn discussing the A2AS Framework: Agentic AI Runtime Security and Self-Defense whitepaper. Here, a group of extremely smart people with a lot of visibility into the generative AI issue published what they called the "BASIC Security Model". Now if you read our recaps from earlier this year, you know the security conversation has finally started breaking away from just trying to shoehorn legacy security models into practice. With agentic architectures, security folks have also collectively realized we need to stop treating Large Language Models like fancy text engines and started treating them for what […] - [Mapping AI Attacks - Why control plane vs. data plane matters](https://blog.generativesecurity.ai/mapping-ai-attacks-why-control-plane-vs-data-plane-matters/): In last week's blog, "The Modern Cap'n Crunch Whistle - the in-band design flaw of LLM's", we talked about the difference between the control plane and the data plane as it related to the Plain Old Telephone Service (POTS) and generative AI. We also discussed how the combination of the two planes in an in-band system created the issues around prompt injection and jailbreaking we're seeing today. For this blog, we're going to dive into common attacks against generative AI, and look at whether they attack the control plane, or the data plane. But why does it matter if the attacks […] - [The Modern Cap'n Crunch Whistle - the in-band design flaw of LLM's](https://blog.generativesecurity.ai/the-modern-capn-crunch-whistle-the-in-band-design-flaw-of-llms/): I may be dating myself here - but if you know what a Blue Box is, and how it worked - then the tone of this week's blog is likely going to ring a bell for you. Before we call this discussion complete, we'll lay out why LLM's are facing the same fundamental flaw that early telephone service lines did - and why we need to dial back the clock to find solutions. (okay - enough phone puns) The 2600Hz Ghost in the Machine We've talked about the need to look to the past to understand the future of generative AI […] - [Who is responsible for, and who owns (generative AI) Security?](https://blog.generativesecurity.ai/who-is-responsible-for-and-who-owns-generative-ai-security/): Recently I’ve been spending a lot of time in conversations with just about everyone in the IT ecosystem - partner conversations with Cloud Service Providers (CSPs), demos with technology vendors, customer briefings with enterprise leaders, investor conversations on the direction of AI security, etc... The conversations we're having, once you get past all the technology, bring up a much bigger anxiety. The question isn’t just "How do we secure this?" but rather: "Who is responsible for security, and what does that responsibility actually mean?" We are currently witnessing a massive land grab with the "security" label. Google and Wiz are announcing […] - [Recapping Google Next '26: The 12-Month Transition from AI to Agentic](https://blog.generativesecurity.ai/recapping-google-next-26-the-12-month-transition-from-ai-to-agentic/): If you read our blog recapping Google Next ‘25, you would have seen that AI seemed to be the only thing Google was working on. But this year, I’m pretty sure the word “agentic” showed up 20 times more frequently than any other word in the keynote, in any of the session headlines, or in any of the printed material on the floor. And don’t get me wrong, it’s for a good reason – agents have taken over the enterprise narrative. But let’s talk about what all this meant for security. Based on the sessions and the massive noise around the […] - [The Continuous Patching Lie: Why "Mythos-Ready" Requires More Than a Faster Treadmill](https://blog.generativesecurity.ai/the-continuous-patching-lie-why-mythos-ready-requires-more-than-a-faster-treadmill/): So in this blog we tend to talk about Securing Generative AI more than the other 3 categories we previously defined around what security in generative AI means; but there is no escaping the Claude Mythos conversation going on right now. Claude Mythos is Anthropic’s latest frontier model, a system so proficient at autonomous vulnerability research and exploit chaining that its creators have restricted its public release, citing "destructive cybersecurity potential." In internal testing, Mythos independently discovered thousands of zero-day vulnerabilities across every major operating system, including a 27-year-old flaw in OpenBSD that had survived nearly three decades of expert scrutiny […] - [Autonomous Red Team Agents - just because we can, should we?](https://blog.generativesecurity.ai/autonomous-red-team-agents-just-because-we-can-should-we/): Back in May of 2025, we wrote about the resurgence of red teaming in the security conversation because of generative AI. We posited "automated red teaming, powered by LLM’s but guided by humans, have a clear opportunity" to advance threat modelling practices and the security of applications and generative AI powered solutions alike. But today, generative AI isn't being used solely for threat modeling support or to augment human activities - it's serving as the whole team. While the promise of "security at the speed of code" is alluring, the reality of fully autonomous red teaming is rife with existential risks […] - [The role of Identity in AI - On-Behalf-Of and Non-Human Identity](https://blog.generativesecurity.ai/the-role-of-identity-in-ai-on-behalf-of-and-non-human-identity/): Recently I've been having a lot of conversations with enterprises where the problem of internal employee access to data has come up. Normally, we'd have robust RBAC implementations, data policies, and strong authentication mechanisms in place to ensure internal employees only got access to what they needed. But when one chatbot has access to all of the company's most sensitive data, and it's supposed to support every employee regardless of their access, people are rightfully concerned. Because the struggle isn't just about getting their generative AI model to follow instructions - it’s about ensuring that the data being shared is strictly […] - [Can we shift from input to outcome based AI security](https://blog.generativesecurity.ai/can-we-shift-from-input-to-outcome-based-ai-security/): The current security model for AI primarily relies on the same M&M model used in many networks for the last 60 years. We currently evaluate individual prompts at the edge to determine if a command is inherently malicious. These traditional guardrails utilize input filters, regex, and prompt sanitization to detect prohibited syntax, toxic language, or known injection patterns at the point of entry. However, this method is incomplete because it ignores the broader conversational context and is easily bypassed by multi-turn grooming attacks where malicious intent is incrementally introduced across several benign-looking exchanges. Because it only asks "is this specific string […] - [The Physical Weaponization of Generative AI](https://blog.generativesecurity.ai/the-physical-weaponization-of-generative-ai/): Generative AI has introduced a surge of novel risks, most of which we’ve spent the last two years discussing in the context of digital interfaces. For example, we’ve analyzed the "perfectly aligned" vending machines that were maneuvered into giving away high-end electronics for free. And far more importantly, we’ve seen the heartbreaking psychological toll of chatbots lacking emotional guardrails, leading to real-world tragedies (I am not going to link to examples here, but you can find them quite quickly). As we move further into 2026 we need to pay attention to a much more chilling frontier: the physical weaponization of generative […] - [Rethinking Social Engineering under MITRE ATLAS](https://blog.generativesecurity.ai/rethinking-social-engineering-under-mitre-atlas/): A quick story - back during my Lockheed days a friend of mine left our program and went to work for MITRE. He was both impressed by and turned off by the depths at which they dove for even mundane decisions. (Optimizing bit patterns for QoS based on write efficiency, I believe) For him, it made otherwise easy and unimpactful decisions overly tedious. But it's that attention to detail that sets MITRE apart, and why the MITRE ATT&CK and ATLAS frameworks are the standard by which a lot of us think about security. The MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence […] - [The Structural Blind Spot in the OWASP Top 10 for LLMs](https://blog.generativesecurity.ai/the-structural-blind-spot-in-the-owasp-top-10-for-llms/): The cybersecurity landscape of 2026 has reached a definitive inflection point. Tools and frameworks that have long served us are starting to falter. Whether that's in technical controls, legal controls, or ethical expectations. I'll write about the Anthropic vs. Department of War saga another time, I wanted to first talk about something I've seen cropping up a bunch now, the OWASP Top 10 for Large Language Model Applications. As one of our industry’s most prominent security frameworks, the OWASP Top 10 is a go-to source for security professionals to do a first pass of their security approach. But for AI-powered software, […] - [Claude Code Security - Should you be excited, scared, or just confused?](https://blog.generativesecurity.ai/claude-code-security-should-you-be-excited-scared-or-just-confused/): If you are a legacy software security vendor, you should probably be a little scared - Anthropic’s Claude Code Security announcement literally wiped billions in market cap off the cybersecurity sector overnight (albeit temporarily). If you are an attacker who relies on "forgotten" business logic flaws to gain access, you should also be looking for a new hobby. And if you’re a developer already neck-deep in AI tools, you can genuinely be excited as the dream of a "self-healing" code pipeline just got (a little) closer to reality. For everyone else though - I think it's safe to stay calm. While […] - [Looking around corners - some academic and not-so-academic conversations in AI security](https://blog.generativesecurity.ai/looking-around-corners-some-academic-and-not-so-academic-conversations-in-ai-security/): The world of generative AI security is constantly evolving right in front of our eyes. And while it can sometimes be hard to keep up with just what's right in front of our faces: the marketing, the new companies, the LinkedIn spiels (mine included); I find it's critical to try to look around corners and see what's happening in the academic world and with the boots on the ground (so to speak). That's because the challenge isn’t just theoretical anymore - to get security past the door we need to be aware of our impact on performance, modularity, and the practical […] - [Why your AI supply chain can be more important than your real-time prompts](https://blog.generativesecurity.ai/why-your-ai-supply-chain-can-be-more-important-than-your-real-time-prompts/): Today, generative AI security practitioners are spending a massive amount of energy trying to stop users from "tricking" our AI into saying something offensive, or conversely, being too nice and giving too much away. But security doesn't start at the user interface; it starts in your development environment. If you only focus on prompts, you largely miss the risks built into the tools we use to create those AI systems in the first place. That's why testing in development, and not just reacting to real-time prompts, is so critical to being secure. Let's look at some recent examples and experiences from […] - [When Your AI Model is "Too Nice" to Stay Secure - Real world examples](https://blog.generativesecurity.ai/when-your-ai-model-is-too-nice-to-stay-secure-real-world-examples/): When you think of "breaking" an AI model, it's likely you think one of two things: a technical jailbreak (finding the magical string of characters that bypasses safety filters) or a prompt injection (tricking a model into executing code by burying instructions in data). And if generative AI was like every other technology, we could stop there; but it's not. Generative AI doesn't just replace technology, it replaces human interaction, and that's why we’re seeing attacks evolve away from "syntax hacking" and into the realm of Social Engineering for Models. You may not have heard about these attacks - yet - […] - [“I Never Thought of That”: Reflecting on NRF 2026](https://blog.generativesecurity.ai/i-never-thought-of-that-reflecting-on-nrf-2026/): “I never even thought about that.” Over the three days of NRF 2026: Retail’s Big Show, that single phrase became the unofficial theme of the Generative Security booth. In our last post, we talked about the industry turning the page from AI curiosity toward actual business confidence. But as I spoke with hundreds of retail leaders in New York, it became clear that confidence cannot exist without a sobering understanding of the new attack surface: the intersection of Generative AI and social engineering. The majority of people we talked to immediately understood the impact. Whether they were worried about protecting their […] - [2026: Turning the Page from Curiosity to Confidence (and seeing you at NRF'26!)](https://blog.generativesecurity.ai/2026-turning-the-page-from-curiosity-to-confidence-and-seeing-you-at-nrf26/): Welcome everyone to 2026! Let’s jump straight to the punchline: 2026 is the year the "sandbox" phase of Generative AI ends for the enterprise. For the last two years, vendors, providers, and executives have talked about what AI could do. As 2025 came to a close, and into 2026, the conversation has shifted to what AI must do, and more importantly, how we ensure it doesn't accidentally hand over the keys to the kingdom while doing it. The Hidden Risks of the Chatbot Explosion I recently had the pleasure of joining the team over at the Software Sales Simplified podcast to […] - [The practical application of Assume Breach and Agentic AI with Lee Newcombe](https://blog.generativesecurity.ai/the-practical-application-of-assume-breach-and-agentic-ai-with-lee-newcombe/): In last week’s blog, Agentic Architectures: Securing the Future of AI with Zero Trust, we discussed the critical role of Zero Trust in securing agentic AI architectures. As part of that, we introduced a few critical practices, including the principle of "Assume Breach". This practice, or tenet, demands that every interaction within a component-based design, whether with users, data stores, or other agents, be treated as originating from a potentially compromised source, driving the need for layered defenses, limiting the blast radius when a breach occurs. In this next iteration of the series, we’re going to dive deeper into putting Assume […] - [Agentic Architectures: Securing the Future of AI with Zero Trust](https://blog.generativesecurity.ai/agentic-architectures-securing-the-future-of-ai-with-zero-trust/): If you believe the hype, the evolution towards agentic architectures promises a revolution in generative AI’s ability to deliver on complex activities. We introduce what an agentic, tool-based architecture might look like in our lessons from container security blog, and in our blog about Trust in the age of agentic tools, we touch on the impact of agentic architectures in security, specifically around how these agents are likely to come form different suppliers, different maturities, and with different access rights. For the next few weeks, I want to combine these two concepts into a single thread, and dive deep into how […] - [Digital Identities: Unifying identity for the human and AI workforce](https://blog.generativesecurity.ai/digital-identities-unifying-identity-for-the-human-and-ai-workforce/): There’s an open question among generative AI proponents right now about just how the technology will be a part of the workforce of the future. Will the technology be used primarily to support teams of people to achieve their outcomes more efficiently or effectively, or will the technology serve as an independent actor in and of itself, needing an HR to measure against their success just like employees today. It’s a daunting question, with many technical and societal implications, but today I want to focus on one technical implication: what does identity look like in this future? Traditionally, identity and access […] - [Trust, or the lack thereof, in the age of agentic tools](https://blog.generativesecurity.ai/trust-or-the-lack-thereof-in-the-age-of-agentic-tools/): Last week we talked a bit about how modern agentic architectures can impact the security dynamic in our blog Accelerating generative AI security with lessons from Containers. A future where a core agent can call and utilize agent-powered “tools” is already researched and deployable using the Model Context Protocol. But as we build this future, it should be fairly obvious that no single organization will develop the complete set of tools its agents will require, and much like every other software model, we will leverage a combination of in-house, open-source, and purchased 3rd party tools and services. We find ourselves echoing […] - [Red Teaming’s attempt to go mainstream with generative AI](https://blog.generativesecurity.ai/red-teamings-attempt-to-go-mainstream-with-generative-ai/): When you think about foundational security, red teaming is often simply not on the list. According to the Ponemon Institute in 2023, only 64% of organizations use red teaming, and most testing is done using tabletop exercises instead of live environment attacks. Look at the AWS Well Architected Security Pillar; security simulations are found in the “Incident response” section towards the end, as the 2nd to last control, and you’re expected to “consider” doing them regularly. Hardly a ringing endorsement. But, if you have been watching the generative AI security publications the past month, a lot of red ink related to […] - [Accelerating generative AI security with lessons from Containers](https://blog.generativesecurity.ai/accelerating-generative-ai-security-with-lessons-from-containers/): A few weeks ago we talked about the top 3 lessons generative AI security can learn from the cloud. And just as generative AI is having its cloud moment, there’s still more we can learn from the evolution of security in other technologies. If you look at the lessons from cloud, a lot of the problems weren’t just technical, but had a very human element to them, or at least to their solutions. If we want to get more granular in the technology, one of the most instructive parallels comes from the adoption of containers. The journey from trying to secure […] - [Unlock Gen AI Value Faster by Making Security Your Ally](https://blog.generativesecurity.ai/unlock-gen-ai-value-faster-by-making-security-your-ally/): Let’s jump to the punchline – business leaders and AI developers are in the unique position to prove they have considered meaningful security in their generative AI powered applications before security teams have fully defined the technical controls. How? By strategically focusing security considerations on tangible risks to the application use cases and their outcomes. You can make security your ally by demonstrating you are protecting the risk to what matters most – your data. In doing so, you can actually accelerate your time to value with more confidence and security assurances. Today, while standards and compliances are still being defined, […] - [Top 3 lessons generative AI security can learn from the cloud](https://blog.generativesecurity.ai/top-3-lessons-generative-ai-security-can-learn-from-the-cloud/): For anyone who’s been in the industry for a while, we know that IT is cyclical. The technology changes, but the patterns remain the same. During the early cloud days, I heard from former COBOL and Unix programmers about the progression from renting time on early mainframes to personal computers, and back to running on someone else’s computer again. And they weren’t wrong. But it’s not just the technology. As an industry we tend to have to relearn the early lessons from these technological evolutions. Noisy neighbors, shared resource contention, and security issues unique to shared services came back all over […] - [RSAC 2025 – Wait, there's more to security than gen AI?](https://blog.generativesecurity.ai/rsac-2025-wait-theres-more-to-security-than-gen-ai/): Although originally not part of the plan (there’s a plan?), I was able to attend RSAC 2025 and see a couple of talks and hit the expo floor. I have to be honest; it was nice to see something, anything, not directly pushing generative AI hype (*cough* Google Next *cough*). Now don’t get me wrong, Agentic AI was front and center in a plethora of ways: semi-autonomous SOC agents, threat intelligence, and all over the early investment worlds. However, good old network and device security was visible, physical security had a place, and discussions about (still) getting the basics right could […] - [Deeper dive - Gen AI In Security: Gen AI powered threats](https://blog.generativesecurity.ai/deeper-dive-gen-ai-in-security-gen-ai-powered-threats/): In our previous discussions, we delved into the platform-level risks, systemic-level risks, and the empowerment of security through generative AI. Now, let's explore the darker side of this powerful technology: generative AI-powered threats. This topic is crucial as it highlights the potential misuse of generative AI in creating sophisticated and automated cyber-attacks. We’ll cover four different examples where generative AI today is making an impact, and also ground the scope of those impacts as well. If you want to get a great primer on the topic, we highly recommend the Adversarial Misuse of Generative AI paper published by Google. Generative AI […] - [Deeper dive - Gen AI In Security: Empowerment of security](https://blog.generativesecurity.ai/deeper-dive-gen-ai-in-security-empowerment-of-security/): So far, we’ve talked about the security challenges inherent in generative AI as a technology. But now let’s take a look at how generative AI impacts the security landscape itself. We’ll start with looking at how security processes, especially in the SOC, are poised to evolve because of the introduction of generative AI. While the debate continues about the extent to which AI can replace human analysts, it's clear that generative AI can significantly augment their capabilities, providing a powerful first line of analysis and accelerating response times. The elephant in the room: Generative AI in the SOC Looking across the […] - [What happened at Google Next - GCP sells what mostly?](https://blog.generativesecurity.ai/what-happened-at-google-next-gcp-sells-what-mostly/): This week Google Next took place over three days, from April 9th until April 11th. I was lucky enough to see what Google had done not only in the last year but what they were planning to do in the future, and obviously AI was a huge piece of this. Since it would be almost impossible to capture all three days in any real detail, I'll just kind of hit the high notes and provide some links for you to dive in. As always, you're welcome to e-mail me and I would love to talk about any of these topics. First, you'd […] - [Deeper dive - Security of Gen AI: Systemic level risks](https://blog.generativesecurity.ai/deeper-dive-security-of-gen-ai-systemic-level-risks/): In our previous blog, we explored the Platform-level risks associated with generative AI, emphasizing the importance of securing the models themselves as well as the broader ecosystem in which they operate. Today, we shift our focus to Systemic level risks, which encompasses both technical and non-technical challenges. While the systemic technical risks are significant, it is likely the non-technical risks that will pose more existential risk to organizations in the future. So what is a systemic risk to begin with? Most definitions of systemic risk focus around the risk of collapse of an entire system or structure because of the collapse […] - [Deeper dive - Security of Gen AI: Platform level risks](https://blog.generativesecurity.ai/deeper-dive-security-of-gen-ai-platform-level-risks/): In one of our first blog posts, we introduced the concept of 4 intersections between generative AI and security: Platform level risks and Systemic level risks as part of the Security of Gen AI; and the Empowerment of security and Gen AI powered threats as part of Gen AI in Security. Over the next few blogs, we will dive into each of these topics to better explain what they mean for you, and how you should consider them as part of your enterprise and IT risk management. This isn’t meant to be an exhaustive dive into the nitty gritty details, but […] - [Gen AI Security – Why it’s so important to protect more than just the technology](https://blog.generativesecurity.ai/gen-ai-security-why-its-so-important-to-protect-more-than-just-the-technology/): I want you to think about this statement for a minute:      We take basic security for granted in customer experience. When you just thought of customer experience, do you first think of the people you interact with when you walk into a store? The person on the other end of the phone call? Or do you primarily think of the website or app interface on your mobile device? The majority of customer interaction is still done with another person, with technology helping augment the research, purchase, or finding of those people to help us. What does this have to do with […] - [What does "Generative AI Security" actually mean?](https://blog.generativesecurity.ai/what-does-generative-ai-security-actually-mean/): Welcome to the first blog for Generative Security. Before we begin, I want to make sure you know what you're going to get when you read this blog. Here, we will talk about what we see going on in the world of Generative AI security and most importantly how it affects you. We may talk about new ideas, how old methods apply to this new world, and what we are seeing in the market. It's also important to mention what you won't see. While we of course live talking about our products and services, you won't see marketing material in this […] ## Pages - [Generative Security Cookie Policy](https://blog.generativesecurity.ai/cookie-policy/): https://generativesecurity.aiEffective date: 17th April 2025 This Cookie Policy explains how Generative Security Pty Ltd (“Generative Security,” “we,” “us,” or “our”) uses cookies and similar technologies when you visit our website https://www.generativesecurity.ai, blog https://blog.generativesecurity.ai, and use any of our web-based services (collectively, the “Sites”) This Policy should be read together with our Privacy Policy, which explains how we collect, use, and protect personal data.  1. What Are Cookies?  Cookies are small text files placed on your computer or mobile device when you visit a website. These files enable the website to recognize your device and recall whether you have visited the site […] - [Generative Security Privacy Policy](https://blog.generativesecurity.ai/privacy-policy/): https://generativesecurity.aiEffective date: 17th April 2025 1. Introduction & Scope This Privacy Policy (“Policy”) describes how Generative Security Pty Ltd and its affiliated entities (“Generative Security,” “we,” “us,” or “our”) collect, use, disclose, and safeguard personal information in connection with our generative AI security assurance platform (the “Platform”), our corporate website https://www.generativesecurity.ai, our blog at https://blog.generativesecurity.ai, mailing list communications, and any related products or services we provide (collectively, the “Services” or “Sites”). This Policy applies to the following categories of individuals: By accessing or using our Sites or Services, you confirm that you have read and understood this Policy and consent to […] - [Insights into generative AI security](https://blog.generativesecurity.ai/insights/): Meet the authors Contributors to the Generative Security blog Michael Wasielewski Michael is the founder and lead of Generative Security. With 20+ years of experience in networking, security, cloud, and enterprise architecture Michael brings a unique perspective to new technologies. Working on generative AI security for the past 2 years, Michael connects the dots between the organizational, the technical, and the business impacts of generative AI security. Michael looks forward to spending more time golfing, swimming in the ocean, and skydiving... someday. - [Past Blog Entries](https://blog.generativesecurity.ai/blog/): Insights into generative AI security Meet the authors Contributors to the Generative Security blog Michael Wasielewski Michael is the founder and lead of Generative Security. With 20+ years of experience in networking, security, cloud, and enterprise architecture Michael brings a unique perspective to new technologies. Working on generative AI security for the past 2 years, Michael connects the dots between the organizational, the technical, and the business impacts of generative AI security. Michael looks forward to spending more time golfing, swimming in the ocean, and skydiving... someday. - [Home](https://blog.generativesecurity.ai/): Insights on securing generative AI Let’s be honest, we’re learning new things about the security of Generative AI systems every day. Whether you’ve been doing this for a few years, or just starting out new, there’s something new to discover about what it means to be secure in the age of Gen AI. We want to share with you what we’re learning as we go along too. So here you can find our thoughts, what we’re working on, and what we find interesting from others in the space as well. And while we will talk about our products and services, we […] ## Optional - [Agent (MCP protocol)](websites-agents.hostinger.com/blog.generativesecurity.ai/mcp) [comment]: # (Generated by Hostinger Tools Plugin)