Your journey
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
0 of 34 units

You are in Degree 4 · Protectionunit 1 of 6Ahead of you: A miniature red-team test and a cognitive defence plan.

Degree 4 · Unit 4.1

From information security to AI security

For decades, information security rested on three pillars: confidentiality, meaning that nobody sees the data who has no right to; integrity, meaning that it is not altered without permission; and availability, meaning that it is there when it is called for. Those three pillars have not fallen. They are simply no longer enough on their own.

The three pillars: confidentiality, integrity, availability

One pillar giving way is enough to turn a creative asset into a loss — here are the three, with examples from your own work.

FIG. B20 — The CIA triad in creative work
ConfidentialityIntegrityAvailabilityThe CIA triadthe base of any security programme
Confidentiality
Keeping out access that was never granted.
a film's script leaking before release.
Integrity
Holding accuracy and preventing tampering.
a client's brand guidelines quietly altered.
Availability
Reliable access at the moment of need.
ransomware encrypting the archive before delivery.

In the creative sector confidentiality usually comes first, because the value of the work so often lies in its not having been seen yet.

An intelligent system adds something that was never in the original reckoning: an output that it creates itself, and behaviour that can be steered with words. Your data may be confidential, intact and available, and the system may still have produced wrong advice, or carried out an instruction that a stranger slipped into a document it was asked to read.

FIG. 18 — The five pillars
Confidentiality
That your data does not leak through what you put in or through what the system puts out
Integrity
That neither the training data nor the retrieval sources are contaminated
Availability
That the system does not stop — and a fallback procedure for when it does
Output integrity
That what it produces is truthful, grounded and attributed to its source
Control
That it does not exceed the actions and tools it was permitted

Five layers where a system is attacked

When you set out to secure an intelligent system, think about it layer by layer. Each layer carries its own characteristic danger, and the control that answers it is different in each case.

FIG. 19 — The five layers
The human
Excessive trust, or manufactured deception aimed at their conviction — the forgotten layer
Tools
Misuse of its privileges: an email sent, a file deleted, a sum transferred
Input
Prompt injection — directly from a user, or slipped into a document it reads
Model
Theft, cloning, or extracting sensitive data memorised inside it
Data
Poisoning or contaminating what it learns from or retrieves from

Do this

  1. 1 — In your field. Draw the layers of an intelligent system you actually use, and write against each layer: who owns it, and what control stands on it today.

  2. 2 — On paper. Which of the five pillars is weakest in your organisation? And why has nobody noticed until now?

Why the security team alone is not enough

In traditional systems, security was a speciality: you handed the system to a team who hardened it, and then you got on with your work. In intelligent systems, three of the five layers are in the hands of the person using it rather than the person hardening it — what they put into the window, what privileges they hand over, and which outputs they choose to believe.

This is why protection here cannot simply be bought as a service. It gets built by changing the habits of the people who work with these systems every day, and that is exactly what makes this degree addressed to you rather than to your technology department.

In intelligent systems, the weakest link is not in the server. It is the moment when a busy human being decides that the answer in front of them looks about right.

Where to after this unit? You know the map. The next unit enters the attacks themselves — five you must know by name.