AI security
YZ güvenliği
D5
AI security is the protection of AI systems and dependent assets against threats to confidentiality, integrity, availability, and intended behavior.
Review status: 2027-02-24
Technical explanation
It considers threats such as adversarial examples, data poisoning, exfiltration, and unauthorized changes to use, performance, or security properties in a stated context.
Conceptual boundaries
AI security is not the same as safety, privacy, robustness, or ordinary application security, although those concerns can interact.
Provider-neutral example
A team can limit a document-analysis agent’s tool permissions, test hostile input paths, protect credentials, and review logs for unauthorized action attempts.
Limitations
Controls reduce stated risks but cannot establish that a complex AI system is invulnerable to all attacks or failures.
Related concepts
Atomic claims and evidence
1.1NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0) — D5 governance and security slice
- Source
- NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0) — D5 governance and security slice
- Source role
- Authoritative source
- Exact locator
- Section 3.3, Secure and Resilient, printed p. 15
- Supported claim
- NIST describes AI systems that maintain confidentiality, integrity, and availability through protections against unauthorized access and use as secure, and identifies adversarial examples, data poisoning, and exfiltration as common concerns.
- Last verification
- Review due
- Scope limitation
- This describes security characteristics and concerns; it does not make a system safe, private, robust, or attack-proof.
1.2OECD AI Principles
- Source
- OECD AI Principles
- Source role
- Authoritative source
- Exact locator
- Robustness, security and safety
- Supported claim
- NIST describes AI systems that maintain confidentiality, integrity, and availability through protections against unauthorized access and use as secure, and identifies adversarial examples, data poisoning, and exfiltration as common concerns.
- Last verification
- Review due
- Scope limitation
- This describes security characteristics and concerns; it does not make a system safe, private, robust, or attack-proof.
2.1Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 — D5 instrument slice
- Source
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 — D5 instrument slice
- Source role
- Authoritative source
- Exact locator
- Article 15(5), consolidated text of 27 July 2026
- Supported claim
- For high-risk AI systems within its scope, the EU AI Act requires an appropriate level of cybersecurity considering the circumstances and risks, including resistance to attempts by unauthorized third parties to alter use, performance, or security properties.
- Last verification
- Review due
- Scope limitation
- This is an EU instrument-specific requirement for high-risk systems, not a claim that all AI security is satisfied by one technical control.
2.2OECD AI Principles
- Source
- OECD AI Principles
- Source role
- Authoritative source
- Exact locator
- Robustness, security and safety
- Supported claim
- For high-risk AI systems within its scope, the EU AI Act requires an appropriate level of cybersecurity considering the circumstances and risks, including resistance to attempts by unauthorized third parties to alter use, performance, or security properties.
- Last verification
- Review due
- Scope limitation
- This is an EU instrument-specific requirement for high-risk systems, not a claim that all AI security is satisfied by one technical control.
2.3European Commission, AI Act regulatory framework
- Source
- European Commission, AI Act regulatory framework
- Source role
- Supplementary source
- Exact locator
- High risk, supplementary summary
- Supported claim
- For high-risk AI systems within its scope, the EU AI Act requires an appropriate level of cybersecurity considering the circumstances and risks, including resistance to attempts by unauthorized third parties to alter use, performance, or security properties.
- Last verification
- Review due
- Scope limitation
- This is an EU instrument-specific requirement for high-risk systems, not a claim that all AI security is satisfied by one technical control.