CISOOnline

Secure AI adoption starts with API best practices

Closing this security gap isn’t just important to mitigate the financial and reputational damage of the worst-case scenario of a data breach. It’s also increasingly important to keep regulators happy. Both NIS2 and DORA, while not AI-focused regulations, certainly make a strong case for looking at AI capabilities through the lens of resilience and security.

Not seeing is not knowing

One of the most acute challenges with API security is the proliferation of shadow and zombie APIs. Modern cloud and microservices environments are highly distributed, with APIs scattered everywhere – many of which are forgotten or have never even been recorded. That doesn’t matter to an AI agent. They’re highly resourceful at discovering APIs that are accessible, even if they’ve not been specifically asked or authorized to use that approach. If APIs offer a route to complete the task that’s been assigned to them, AI agents will invariably find and use them.

The issue is that these shadow or zombie APIs may not have been designed securely or in line with the organization’s current governance policies, leading to data loss or other unintended consequences. This was a major challenge even before Mythos changed the game for systems defenders and adversaries alike. With frontier models capable of discovering vulnerabilities and chaining exploits at a whole new speed and scale, the task of securing APIs is even more urgent.



Source link