← Back to list

What Does “Secure AI” Actually Mean? No One Has Officially Decided.

Before germ theory, physicians treated disease caused by “miasma” — bad air, loosely defined, emanating from swamps and rotting matter. The…

Forcepoint in Force Multiplier · 2026-06-24 19:52 · 0 claps · 3.3 min read
#artificial-intelligence #cybersecurity #ai-security #national-security #technology-policy
Open on Medium ↗
Wiki topics: AI · AI · General CLI · Clinical Medicine CRY · Crypto & Web3 🔒 · Cybersecurity

What Does “Secure AI” Actually Mean? No One Has Officially Decided.

Before germ theory, physicians treated disease caused by “miasma” — bad air, loosely defined, emanating from swamps and rotting matter. The treatments were earnest, sometimes expensive, and occasionally useful by accident. They were also built on a threat model that was fundamentally wrong, or at least fundamentally incomplete. Nobody had yet agreed on what disease actually was, which made it impossible to agree on what a cure should do.

Organizations buying AI security products right now are in a version of that position. The threat is real. The spending is real. The definition of what they’re protecting against is not. Jake Braun — co-founder of DEF CON Franklin, former acting Principal Deputy National Cyber Director and guest across two recent episodes of the To the Point Cybersecurity Podcast — has watched this gap develop from both sides of the policy and hacker divide, and he is not understating it when he says it’s a crisis.

[embed]

What the hackers were saying a year ago

Every year, Braun and his collaborators at DEF CON produce the Hackers’ Almanack — a curated account of the most policy-relevant findings from the world’s largest hacker conference. Its value, he argues, is precisely that it surfaces what the enterprise security world won’t discuss for another year or more. Last year’s AI section documented something that hadn’t yet reached mainstream policy conversation: AI systems entering capture-the-flag competitions and placing in the top 10%. One researcher entered his system, forgot to start it on time because he was doing his dishes, and still placed well. The implication wasn’t subtle. Offensive AI capability was arriving faster than anyone outside the DEF CON community seemed to realize, and the defensive frameworks needed to contain it didn’t exist.

That was the state of play a year before offensive AI became the topic at every security conference. It is now the topic at every security conference, and the frameworks still don’t exist.

The standards vacuum at the center of everything

There is no NIST Cybersecurity Framework equivalent for AI. There is no list of critical controls, no agreed-upon definition of what AI red teaming means, no shared baseline for what a reasonable AI security program looks like. The question Braun asks is plain: when you say you’re red teaming an AI system, what exactly are you testing? The application? The model? The weights? The training data? The answer, across the industry right now, is: it depends who you ask.

That definitional vacuum has real consequences. Vendors are selling AI security products without any shared standard against which those products can be evaluated. Organizations are buying them without any way to verify whether what they’re purchasing constitutes adequate protection. And when something goes wrong — when an AI system is compromised, manipulated or misused in ways that cause measurable harm — courts will have no established standard of due care to apply. The absence of standards doesn’t just make organizations less secure. It makes accountability structurally impossible.

Why this is a threat multiplier, not just a policy gap

The offensive capability argument and the standards vacuum compound each other in a way that should concern anyone making AI security decisions right now. AI-generated attacks are accelerating. The Mandiant research placing infrastructure mapping at 22 seconds is one data point in a directional trend that DEF CON participants have been tracking for longer than the enterprise world has been paying attention. On the other side of that equation, organizations have no agreed-upon bar to meet, no external mechanism to drive improvement and no way to know whether their current posture would constitute reasonable care if tested in court.

That combination — rapidly advancing offense, undefined defense — is not a gap that narrows on its own.

[embed]

What a fix actually requires

The solution isn’t another sprawling framework. What the field needs is something closer in spirit to the 18 CIS critical controls — a multi-stakeholder group bringing together industry, government, academics and the hacker community to produce something actionable, auditable and enforceable through case law over time. The NIST Cybersecurity Framework took years and wasn’t perfect, but it gave organizations something to point to and gave courts something to work with. The AI equivalent of that process hasn’t meaningfully started.

The hacker community identified this problem first, as it usually does. The policy and standards community is catching up, as it usually does. The organizations spending money on AI security products in the meantime are doing the best they can with a threat model that nobody has officially written down — treating the symptoms of a disease that hasn’t yet been named.

Listen to Part 1 of the conversation with Jake Braun on the To the Point Cybersecurity Podcast. Part 2 is available here.


메타데이터
post_id
40dab488205d
slug
what-does-secure-ai-actually-mean-no-one-has-officially-decided-40dab488205d
url
https://medium.com/forcepoint-security/what-does-secure-ai-actually-mean-no-one-has-officially-decided-40dab488205d
canonical_url
https://medium.com/forcepoint-security/what-does-secure-ai-actually-mean-no-one-has-officially-decided-40dab488205d
author_url
https://medium.com/@forcepoint-security
status
ok
fetched_at
2026-07-09 20:10:33