Skip to main content
AI Security Hub
02AI Security Pillar

Input Security Checks

Inspect information before it reaches the model or influences an AI workflow.

Business focus

Inspect before processing

Why it matters

Security starts with a defined business boundary

Input security checks look for malicious instructions, unsafe formats, sensitive information, and suspicious files before the AI processes them.

Business risk

An AI system may receive instructions from users, documents, websites, email, or connected applications. If every input is trusted equally, an attacker or compromised source can influence the workflow.

What this pillar covers
  • Prompt-injection screening
  • Jailbreak-attempt detection
  • Personal and confidential data detection
  • Malware and suspicious file patterns
Operating model

Turn inspect before processing into repeatable controls

A policy is only the starting point. For each AI use case, name the business owner, define the allowed boundary, configure the relevant technical controls, and decide what evidence proves those controls are working. Repeat the review when the model, data, connected tools, or business purpose changes.

Start with a single high-value workflow instead of trying to govern every experimental use at once. That makes it possible to test the controls with real users, find exceptions, and create a pattern the rest of the business can reuse.

StepDecisionEvidence to retain
1Scope the workflowOwner, purpose, approved data, users, and connected systems.
2Apply the controlsConfiguration, access rules, approval points, and test cases.
3Operate and reviewLogs, review results, exceptions, incidents, and change records.

Questions for leadership

  • Which input channels can influence the AI?
  • How does the workflow handle a rejected or suspicious request?
  • Who reviews repeated attack patterns or false positives?
  • Are file and data checks applied before retrieval and tool use?
Practical control checklist

Put the pillar into practice

  1. 1List every user, file, retrieval, and application input path.
  2. 2Treat external content as data rather than trusted instructions.
  3. 3Validate file type, size, structure, and malware status.
  4. 4Screen for restricted or sensitive information before processing.
  5. 5Log blocked requests and define an escalation owner.
Authoritative guidance

Use recognised guidance to validate the control design

These resources help teams translate AI-specific risks into documented, testable business and technical controls. Apply them to the actual data, permissions, and actions in the workflow rather than treating them as a one-time compliance exercise.

Review a real workflow

Turn this pillar into operating controls

Map the data, access, approvals, monitoring, and evidence around one important AI use case before expanding it.

Explore AI services