Skip to main content
AI Security Learning Centre

A practical AI security framework for business

Secure AI from the information people submit through the actions systems take, the answers they produce, and the evidence your team keeps. These eight pillars turn AI risk into clear business controls.

End-to-end AI security flow
  1. 1Input
  2. 2Checks
  3. 3Context
  4. 4Guardrails
  5. 5Actions
  6. 6Output
  7. 7Monitoring
  8. 8Improvement
The control system

Eight pillars, one connected workflow

Start with the pillar closest to your immediate concern, then follow the flow. Strong AI governance depends on each layer supporting the next.

01

User Input Security

Control what enters AI

Control the prompts, files, requests, and conversation history entering an AI system.

  • Prompts and sensitive questions
  • Uploaded files and client documents
  • API requests and connected applications
  • Session context and conversation history
02

Input Security Checks

Inspect before processing

Inspect information before it reaches the model or influences an AI workflow.

  • Prompt-injection screening
  • Jailbreak-attempt detection
  • Personal and confidential data detection
  • Malware and suspicious file patterns
03

Context and Retrieval Control

Limit what AI can retrieve

Control which documents, records, and knowledge sources an AI system can access and use.

  • Document filtering and approved sources
  • Role-based retrieval authorization
  • RAG source validation and provenance
  • Context isolation between users or clients
04

Model Behaviour Guardrails

Define acceptable behaviour

Set the policies and boundaries governing what an AI system may say, recommend, or refuse.

  • System policy rules
  • Refusal and safe-fallback logic
  • Output boundaries
  • Reasoning and evidence constraints
05

Tool and Agent Security

Control AI actions

Limit the systems, credentials, permissions, and actions available to AI agents.

  • Approved-tool allowlists
  • Permission and authorization checks
  • Human approval for higher-risk actions
  • Action logging and accountability
06

Output Security Checks

Review before release

Review AI-generated content before the business relies on it or sends it externally.

  • Sensitive-data redaction
  • Hallucination and factual review
  • Policy and client-commitment checks
  • Citation and source validation
07

Monitoring and Threat Detection

Maintain visibility

Monitor AI usage, suspicious patterns, system changes, and security events after launch.

  • Prompt, retrieval, tool, and activity logs
  • Attack-pattern tracking
  • Anomaly and integrity monitoring
  • Security alerts and escalation
08

Feedback and Continuous Improvement

Test and improve controls

Keep AI controls current as models, data, tools, business processes, and risks change.

  • Human-review feedback
  • Policy and workflow updates
  • Evaluation and adversarial testing
  • Guardrail and threshold tuning

How to use this hub

Use the framework to review one real AI workflow. Avoid trying to solve every use case with one policy or one technical control.

  1. Step 1

    Map the workflow

    Record users, data, retrieval sources, model, tools, outputs, and owners.

  2. Step 2

    Apply the pillars

    Identify the controls required at each stage and the evidence they should produce.

  3. Step 3

    Test the result

    Run normal, unsafe, and error cases before expanding access or automation.

Put the framework to work

Start with one AI workflow that matters

The AI and Cyber Governance Diagnostic maps your use case, data, access, oversight, and evidence so the first control priorities are clear.

Explore the diagnostic