Skip to main content

NSS Labs Unveils AIPS Framework to Test Enterprise AI Security Controls

NSS Labs released its AI Protection Systems (AIPS) test methodology for evaluating enterprise AI security controls, using adversarial testing across eight evaluation domains. The framework is aimed at helping enterprise security teams validate how controls perform under realistic, evolving attack techniques.

Research Overview

NSS Labs states that the AIPS methodology addresses the need for continuous, independent validation of AI security controls in enterprise deployments. The approach is described as multi-dimensional and adversarial to reflect complexity, scale, and variability in AI threat environments.

The methodology is intended to evaluate AI protection systems in line with how products are used and tested in practice, including constraints tied to testing cycles and operational dependencies. NSS Labs says testing aligns to vendors’ publicly documented features instead of applying a single uniform standard to all products.

Key Findings

NSS Labs describes eight major evaluation dimensions: prompt injection resistance, data exfiltration prevention, system resilience, policy enforcement accuracy, and agentic AI and tool invocation security. It also lists observability and auditability, performance and scalability, and cross-model integration.

The test program runs hundreds of thousands of attack variations intended to model how adversaries attempt to bypass AI security controls. NSS Labs cites variations involving obfuscation, role-based manipulation, context and instruction hijacking, RAG poisoning, exploit generation attempts, and API or tool misuse scenarios.

Technical Breakdown

NSS Labs says its adversarial model withholds full visibility into test cases from vendors in advance. NSS Labs frames this as a way to reflect real-world conditions rather than results optimized for known test inputs.

For product evaluation, the methodology maps results to what a given vendor supports, highlighting supported capabilities and differentiation areas. NSS Labs says it does not aim to identify a single winner, and it is designed to support layered AI security by helping organizations identify complementary technologies.

Operational Impact

NSS Labs says the methodology is designed to reflect product capabilities as documented, noting that no single vendor is expected to cover every capability defined in the framework. It describes the output as clarity on how solutions perform and where they fit within a defense-in-depth approach.

As part of the development process, NSS Labs is accepting feedback on this version of the methodology through May 15. The company also states that enterprises and security vendors can provide input or participate in the AIPS test program via an email address.

Leadership Perspective

In a quote, Vikram Phatak, CEO of NSS Labs, said, “AI security is fundamentally different from anything we’ve tested before.”

Phatak added that the attack surface is dynamic, context-driven, and evolving, and that the methodology combines adversarial testing, policy validation, and system-level resilience into a single framework.

NSS Labs’ AIPS methodology lays out an adversarial, eight-domain testing approach for enterprise AI protection systems, with large-scale attack variation coverage aligned to vendors’ documented features. Blog Signals brief is a fact-based summary of the vendor blog.