Degree 4 · Unit 4.1
From information security to AI security
For decades, information security rested on three pillars: confidentiality, meaning that nobody sees the data who has no right to; integrity, meaning that it is not altered without permission; and availability, meaning that it is there when it is called for. Those three pillars have not fallen. They are simply no longer enough on their own.
One pillar giving way is enough to turn a creative asset into a loss — here are the three, with examples from your own work.
Keeping out access that was never granted.
a film's script leaking before release.
Holding accuracy and preventing tampering.
a client's brand guidelines quietly altered.
Reliable access at the moment of need.
ransomware encrypting the archive before delivery.
In the creative sector confidentiality usually comes first, because the value of the work so often lies in its not having been seen yet.
An intelligent system adds something that was never in the original reckoning: an output that it creates itself, and behaviour that can be steered with words. Your data may be confidential, intact and available, and the system may still have produced wrong advice, or carried out an instruction that a stranger slipped into a document it was asked to read.
Five layers where a system is attacked
When you set out to secure an intelligent system, think about it layer by layer. Each layer carries its own characteristic danger, and the control that answers it is different in each case.
Do this
1 — In your field. Draw the layers of an intelligent system you actually use, and write against each layer: who owns it, and what control stands on it today.
2 — On paper. Which of the five pillars is weakest in your organisation? And why has nobody noticed until now?
Why the security team alone is not enough
In traditional systems, security was a speciality: you handed the system to a team who hardened it, and then you got on with your work. In intelligent systems, three of the five layers are in the hands of the person using it rather than the person hardening it — what they put into the window, what privileges they hand over, and which outputs they choose to believe.
This is why protection here cannot simply be bought as a service. It gets built by changing the habits of the people who work with these systems every day, and that is exactly what makes this degree addressed to you rather than to your technology department.
In intelligent systems, the weakest link is not in the server. It is the moment when a busy human being decides that the answer in front of them looks about right.
Where to after this unit? You know the map. The next unit enters the attacks themselves — five you must know by name.
