NSS Labs publishes two white papers on enterprise AI security
4 companies named across 3 categories, one of 36 articles referencing NSS Labs. Previous coverage: Netskope, CISA, EU AI Act, and NSS Labs updates - Q3 2026 (Aug 2026).
Companies mentioned
Best suited for
- Seniority
- C Level / Executive Team
- Job function
- Chief Information Security Officer
- Persona
- Security Operations Leader
- Buyer role
- Decision Maker / Budget Holder
- Buyer journey
- Want to Buy
- Adoption curve
- Early Majority
- Technology maturity
- Emerging Exploration
- Industry
- Information Technology / Cybersecurity / Application, Cloud & AI Security / AI Security & LLM/Model Security
Our classification, not the publisher's statement. Best suited for, not only for.
NSS Labs published two white papers on enterprise AI security, one focused on risk beyond the model and the other on questions buyers should answer when evaluating vendors. The papers were developed with Amazon Web Services, F5, and Microsoft, along with other industry participants.
The material framed AI security as a governance issue as well as a technical one. It pointed to production systems, regulatory scrutiny, legal exposure, customer review, and board-level oversight as reasons to define controls before failures occur. The papers also referred to a shift from experimentation toward production deployment.
One paper said securing the model alone was not enough and described AI security as a system-level concern. The other moved into procurement guidance and focused on runtime guardrails in the form of AI Protection Systems. Those controls sat outside the model and were described as enforcing policy, protecting data, and producing audit evidence.
Vikram Phatak, CEO of NSS Labs, said, “We’re at the beginning of the AI revolution and everyone has questions,” and added, “These papers provide a framework for how to think about securing AI as well as practical guidance for governance of what their AI systems are permitted to do and why. Yes, AI security is a technical issue, but it is also a governance issue.”
The papers highlighted several priorities: embedding AI security in Governance, Risk, and Compliance frameworks; extending controls beyond the model; managing delegated authority in agentic AI systems; combining detection with verification where certainty is required; and using independent validation practices. NSS Labs said both papers were available for download on its site.
Blog post, originally published at nsslabs.com.