Frequently asked questions about AI Security

Answers about AI Security

AI Security FAQ: Risks of GenAI, Shadow AI and AI agents

GenAI tools and AI agents such as ChatGPT, Copilot or Claude Code create new opportunities, but they also introduce new security risks – from data leakage via prompts to excessive access rights for autonomous agents. Our FAQs answer questions about identifying Shadow AI and using AI securely and in a controlled way within the company.

Symbol für KI-Sicherheit und vernetzten Schutz

The biggest risks are data leakage via prompts, for example when confidential information is entered into external models, compliance violations when processing personal data, and a lack of transparency about which employees are using which AI tools at all, also known as Shadow AI. Without control mechanisms, companies lose visibility over sensitive data leaving the organisation.

No. A policy provides important guardrails, but it cannot replace technical controls. An effective AI security concept combines governance and responsibilities with awareness, technical protection measures and continuous monitoring.

Secure AI usage starts with transparency and clear rules. Companies should know which AI services are being used, what data flows into them and which use cases are permitted. Based on this, technical controls, governance, training and monitoring can be established in a targeted way.

With an Asecus “AI Discovery & Risk Check”, you receive an analysis of the AI tools in use and of your ability to detect them. This gives you a fact-based overview of which tools are being used, by whom, and what risks are associated with them - as a basis for a company-wide AI policy.

In addition to clear guidelines, a combination of technical and organisational measures is required: DLP solutions that detect AI applications and control data input, CASB/SSE functionalities to manage access to AI services, as well as clear policies and awareness training for employees. It is important to consider not only known web applications, but also AI functions in SaaS applications, development tools, agents and plugins.

Agentic AI describes AI systems that can independently perform actions, call tools and make decisions - not just generate text. As a result, agents often receive extensive permissions, such as access to systems, APIs and data. This creates new attack surfaces, including prompt injection, unintended action chains and privilege escalation. Governance and access controls must therefore be expanded accordingly.

AI agents can independently access data, applications and interfaces and carry out actions. This creates new risks around permissions, data leakage, manipulated inputs, unintended actions and a lack of traceability. It is therefore essential to treat agents similarly to privileged digital identities and to consistently control their access.

AI coding agents often receive extensive access to source code, repositories, environment variables and sometimes even production systems in order to perform tasks independently. This increases the risk of unintended leakage of trade secrets and credentials, the introduction of insecure or vulnerable code, and unintended actions caused by faulty agent logic or prompt injection from manipulated code or dependencies. In addition, many companies lack transparency about which agents are in use and what permissions they have.

Proven measures include clearly defined permission boundaries based on least privilege, especially separated from production systems and without direct access to secrets, mandatory human code review before every merge, and automated scans such as SAST and secret scanning for agent-generated code. In addition, a company-wide policy for the use of coding agents is recommended, including logging and monitoring of agent activities in order to detect anomalies at an early stage.

The first step is an inventory: Which AI tools and use cases already exist, what data is being processed, and what risks arise from this? Only with this transparency can companies decide where organisational or technical measures are actually needed. This is exactly the approach followed by the Asecus “AI Discovery & Risk Check”.