Skip to main content

NSS Labs Publishes Two White Papers on Enterprise AI Security

NSS Labs published two white papers on enterprise AI security, pairing a governance framework with procurement questions for evaluating runtime “AI Protection Systems.” The guidance targets CISOs and GRC leaders assessing controls for production AI systems.

Research Overview

The two white papers focus on securing artificial intelligence deployments in enterprise environments rather than relying only on protections for an AI model. NSS Labs said the materials were developed in collaboration with Amazon Web Services, F5, Microsoft, and other industry participants.

The papers are positioned as structured guidance for how enterprise security leaders evaluate AI risk and what to verify before failures become visible under regulatory, legal, customer, or board-level scrutiny. They also aim to support governance practices for what AI systems are permitted to do.

Key Findings

One paper argues that securing only an AI model is not sufficient and frames enterprise AI security as a system-level and governance challenge. It is intended to help Chief Information Security Officers, enterprise buyers, and Governance, Risk and Compliance stakeholders identify questions to ask prior to production deployment.

The second paper is described as moving procurement from theory into evaluation discipline, including how to form questions when shortlisting AI security vendors. It highlights runtime guardrails implemented as AI Protection Systems that enforce policy, protect data, and produce audit evidence.

Operational and Governance Priorities

NSS Labs listed several priorities for enterprises, including embedding AI security into Governance, Risk and Compliance frameworks. The papers also emphasize moving from model-centric controls to system-level runtime guardrails.

The guidance further addresses managing delegated authority in agentic AI systems and combining detection with verification where certainty is required. NSS Labs also cited the establishment of measurable, independent validation practices and described the combined materials as a roadmap for transitioning from AI experimentation to production-grade deployment.

Leadership Perspective

NSS Labs CEO Vikram Phatak said the papers provide a framework for thinking about securing AI and practical guidance for governance of permitted actions, adding that AI security involves governance as well as technical work. The statement frames AI security as part of how organizations manage what their AI systems do and why.

NSS Labs stated that both white papers are available for download through a research page on its host domain.

Overall, the announcement centers on two NSS Labs white papers that pair governance-oriented guidance with buyer-focused procurement questions for enterprise AI security, with emphasis on runtime guardrails and independent validation. This “Blog Signals brief” is a fact-based summary of the vendor blog.