LIVE
Study finds gender bias in GPT models is not reduced but reshaped across generations17/09/26 · OpenAI|Architectural tweaks may break conventional scaling law exponents16/09/26|OpenAI publishes a framework for reporting model misalignment16/09/26 · OpenAI|NVIDIA's Vera Rubin NVL72 Debuts in MLPerf Inference v6.116/09/26 · NVIDIA|OpenAI expands ChatGPT advertising with Sponsored Agents16/09/26 · OpenAI|OpenAI moves into advertising with 'Sponsored Agents'16/09/26 · OpenAI|Google DeepMind Introduces Gemini 3.8 Live and Its Extended Thinking Variant15/09/26 · Google DeepMind|What's at stake in AI's trillion-dollar infrastructure bet15/09/26|A Flaw in Chain-of-Thought Safety Monitoring14/09/26|Stellar Colosseum: A Multi-Agent System for Long-Horizon Mathematical Research14/09/26|Apple Code Hints Siri Could Be Swapped for ChatGPT or Claude14/09/26 · Apple|Anthropic says Houthi-linked actors used Claude Code for missile guidance software13/09/26 · Anthropic|Study finds gender bias in GPT models is not reduced but reshaped across generations17/09/26 · OpenAI|Architectural tweaks may break conventional scaling law exponents16/09/26|OpenAI publishes a framework for reporting model misalignment16/09/26 · OpenAI|NVIDIA's Vera Rubin NVL72 Debuts in MLPerf Inference v6.116/09/26 · NVIDIA|OpenAI expands ChatGPT advertising with Sponsored Agents16/09/26 · OpenAI|OpenAI moves into advertising with 'Sponsored Agents'16/09/26 · OpenAI|Google DeepMind Introduces Gemini 3.8 Live and Its Extended Thinking Variant15/09/26 · Google DeepMind|What's at stake in AI's trillion-dollar infrastructure bet15/09/26|A Flaw in Chain-of-Thought Safety Monitoring14/09/26|Stellar Colosseum: A Multi-Agent System for Long-Horizon Mathematical Research14/09/26|Apple Code Hints Siri Could Be Swapped for ChatGPT or Claude14/09/26 · Apple|Anthropic says Houthi-linked actors used Claude Code for missile guidance software13/09/26 · Anthropic|
Intermediate🛡️

Securing your business against AI risks in 2026

67% of businesses had an AI incident in 2026. Average cost €4.9M. We explain the 4 risk vectors, frameworks (SAIF, OWASP), AI Act, and 90-day action plan for CISOs/managers.

16 min readPublished May 5, 2026· Updated September 17, 2026

In one sentence

Your employees use ChatGPT, Claude and Copilot daily, with or without your approval. Your data may be going to OpenAI without your knowledge. Your CRM, emails, product specs are potentially exposed. In 2026, securing a company against AI is no longer optional: it's a discipline in its own right with its frameworks, tools and processes.

🛡️
The analogy that works
Securing a company against AI in 2026 is like protecting a bank that suddenly has 50 new secret doors. Your employees, out of enthusiasm, open these doors to move faster. Your job as CISO: identify all the doors, choose which ones to close, which ones to monitor, and train the guards so they know who's going through where.

🎣 Want to understand AI phishing attacks in detail?

Vishing, smishing, perfect emails: we dissect AI phishing with professional diagrams.

Read the AI phishing article

The 2026 context: why it's urgent

The figures are alarming:

AI incidents in enterprises (2024-2026)

Average cost of AI incident in healthcare12 300 000
Average cost of AI incident4 900 000
202667%
202551%
202432%
Today23%
202314%
% companies having suffered an AI incident0
% companies with mature AI governance0

Reading: 67% of companies suffered an AI incident in 2026, but only 23% have mature governance. The gap is massive. Average cost: €4.9M.

Mapping AI risks in the enterprise

The 4 AI risk vectors in the enterprise
YOUR COMPANY 🏢 Data • IP • Customers 🌊 SHADOW AI Undeclared AI usage • Employees on personal ChatGPT • Code copied to personal Copilot • Customer PDFs on NotebookLM Risk #1 (78% companies) 🪤 PROMPT INJECTION Chatbot hijacking • Bot exfiltrates customer data • Chatbot says nonsense to users • Override of rules OWASP LLM01 🧪 POISONING Data poisoning • Fine-tuning on corrupted data • RAG with malicious docs • Latent backdoors If you do fine-tuning 🤖 AI AGENTS Autonomous actions • Agent sends 1,000 emails • Computer Use misconfigured • Irreversible action Emerging risk 2026 4 AI attack vectors converge on your data and systems
Each vector has its own countermeasures. Holistic defence combines all 4.

Google's SAIF framework: the 2026 foundation

Google published SAIF (Secure AI Framework) in 2024, which has become the de facto standard. 6 pillars:

SAIF : Google's Secure AI Framework
1 Extend existing security Your security tools (SIEM, EDR, IAM) apply to AI too, don't start from scratch. → Audit existing, gap analysis, extend IAM 2 AI detection & response Logs of prompts/responses, jailbreak detection, anomalies in AI usage. → Tools: Lakera, Robust Intelligence 3 Automate defences Use AI FOR security: auto detection, incident classification, SOC triage. → SOAR with AI, augmented SIEM 4 Harmonised platforms A single platform to manage all AI access (models, data, prompts). → ModelGarden, Vertex AI, Azure AI Foundry 5 Adapt controls Feedback loop: new risks detected, controls updated rapidly. → AI penetration tests, quarterly red team 6 Contextualise risks Every AI must be assessed according to its usage context (criticality, data, users). → Risk scoring model per AI use case 📚 SAIF.google.com : Official Google framework, free, in 6 languages
6 AI security principles, applicable to any organisation

OWASP LLM Top 10: the 10 vulnerabilities to know

OWASP (the reference organisation in web security) published its Top 10 LLM vulnerabilities in 2024, updated 2025. This is THE reference for developers.

OWASP LLM Top 10 (2025 version)

 🔓Vulnerability💥Impact / Example
LLM01 - Prompt InjectionManipulate the LLM via malicious promptsBot says nonsense or exfiltrates data
LLM02 - Sensitive Info DisclosureLLM reveals secrets in responsesAPI keys, passwords in training data
LLM03 - Supply ChainCorrupted model/dataset upstreamMalicious HuggingFace model
LLM04 - Data & Model PoisoningTraining poisoningActivatable latent backdoors
LLM05 - Improper Output HandlingLLM generates dangerous code that's executedXSS, SQL injection via output
LLM06 - Excessive AgencyAI agent with too many permissionsAgent can delete files
LLM07 - System Prompt LeakageHidden system prompt leakCompetitor steals your business logic
LLM08 - Vector & Embedding WeaknessRAG flawVector database poisoning
LLM09 - MisinformationLLM generates false info at scaleFalse legal/medical responses
LLM10 - Unbounded ConsumptionNo limit on usage = DoS & costsBot consumes €100K of API in 1 hour

AI maturity: the 5 levels

AI governance maturity model
LEVEL 0 DENIAL 🙈 "We don't use AI" (false: they all use personal ChatGPT) • No policy • No training • No controls ~15% of French companies LEVEL 1 CHAOS 😵 "We let it happen, we'll see" • Vague charter • No inventory • Reactive (incidents) ~40% of French companies LEVEL 2 REACTIVE 🤔 "We have a charter, little read, little followed" • Written policy • 2FA deployed • Network filters ~22% of French companies LEVEL 3 PROACTIVE 😎 "We manage, monitor, and train" • Complete inventory • Regular training • AI security KPIs ~18% of French companies LEVEL 4 OPTIMISED 🏆 "AI is a strategic advantage" • AI red team • ISO 42001 • Mature AI Risk Mgmt ~5% of French companies 🎯 2026 goal: reach level 3 minimum (proactive). ROI gain: -70% incidents, +40% successful AI adoption 5 levels of AI governance maturity, where is your company?
Most companies are at level 1-2. 2026 goal: level 3+

Action plan in 90 days

📚Concrete compliance roadmap

📅 Month 1 : Audit & foundations

Week 1-2: Inventory

  • Anonymous survey: who uses which AI and for what?
  • Network logs: which AI domains are visited? (ChatGPT, Claude, Gemini, etc.)
  • Systems inventory: which chatbots/AI agents are deployed internally?
  • Map sensitive data (customers, financial, IP)

Week 3-4: AI Policy

  • Draft the company AI policy (1-2 pages, readable)

- Which uses are allowed (ChatGPT Enterprise OK, personal ChatGPT NO) - What data can be shared with an AI - Output validation rules

  • Get exec team approval (not just an IT doc)

📅 Month 2 : Tools & training

Week 5-6: Tech

  • Deploy ChatGPT Team / Enterprise or Claude for Work (alternative to personal accounts)
  • 2FA everywhere on AI tools
  • DLP (Data Loss Prevention): tools that detect data leaks to AI
  • List of authorised usernames per AI use case

Week 7-8: Training

  • 1-hour flash training for all (video + quiz)
  • 4-hour in-depth training for techs (devs, ops, CISO)
  • "VIP" training for exec team (90 min, focus business risks)
  • Internal communication kit (intranet, posters)

📅 Month 3 : Tests & governance

Week 9-10: Tests

  • Simulated AI phishing: send phishing emails/SMS to measure click-through rate
  • AI pentest: test deployed chatbots (prompt injection, leaks)
  • Shadow AI audit: verify unauthorised uses have decreased

Week 11-12: Sustainability

  • Establish monthly AI committee (CISO, DPO, IT, Business)
  • Define AI security KPIs (incidents, reporting rate, training rate)
  • 6-month plan ahead (red team, ISO 42001, etc.)

🎯 Expected deliverables

At the end of 90 days, you must have:

  • ✅ AI policy validated and published
  • ✅ Complete inventory of AI uses (authorised + Shadow)
  • ✅ ChatGPT Enterprise (or equivalent) deployed
  • ✅ 80%+ employees trained
  • ✅ AI helpline in place
  • ✅ AI incident response plan
  • ✅ Active monthly AI committee

The CISO's tools in 2026

Essential AI governance tools

 🛠️CategorySolutions
ChatGPT Enterprise / Claude for WorkCorporate versions of LLMs with data control€20-60/user/month
Lakera GuardReal-time prompt injection detectionFor securing your own bots
Microsoft Purview AI HubVisibility of AI usage in organisationIncluded in M365 E5
Robust IntelligenceAI adversarial testingFor those deploying their own models
Calypso AI / GleanAI-specialised DLPPrevents data leaks to public ChatGPT
Zscaler AI SecurityTraffic filtering to AI servicesGlobal visibility + blocking
ISO 42001 / NIST AI RMFOfficial frameworksReference standards

The European AI Act: what you MUST do

Legal obligations in France
The AI Act came into force in 2025-2026, with obligations depending on the risk level of your AI systems: 🔴 UNACCEPTABLE risk (prohibited): - Social scoring, cognitive manipulation, biometric surveillance in public places 🟠 HIGH risk (heavily constrained): - AI in HR (recruitment, evaluation), education, justice, critical healthcare - → Obligation: conformity assessment, register, documentation, human oversight 🟡 LIMITED risk (transparency): - Chatbots, deepfakes, consumer AI - → Obligation: clearly inform the user they're interacting with an AI 🟢 MINIMAL risk: - Classic AI (spam filters, recommendations) - → No specific obligation Sanctions: up to €35M or 7% global turnover depending on infringement. More severe than GDPR. Action: AI compliance audit for AI Act = 2026 priority.

The metaphor that sums it all up

🏗️
Building a skyscraper vs adding floors
Doing AI security in 2026 is like renovating a building under construction. You can't stop everything ("we ban AI"), but you can't let everyone go up without a plan either. The good CISO in 2026: - 🏗️ Maps what exists (Shadow AI, declared uses, systems) - 📐 Establishes plans (AI policy, SAIF framework) - 👷 Trains the workers (employees, devs) - 🔍 Inspects regularly (red team, pentest) - 🚨 Plans for firefighters (incident response) → No impenetrable wall (impossible with AI). But a solid architecture that withstands shocks.

Key takeaways

  • 67% of companies suffered an AI incident in 2026
  • 4 vectors: Shadow AI, prompt injection, poisoning, agents
  • Frameworks: SAIF (Google), OWASP LLM Top 10, NIST, ISO 42001
  • EU AI Act: sanctions up to €35M, compliance priority
  • 90-day plan: audit → policy → tooling → training → tests
  • Target level: maturity 3 (proactive), the majority are still at level 1-2

AI security is no longer optional. It's become a discipline in its own right with its tools, standards and professions (AI Risk Manager, AI Auditor).

🧠 Quiz
Question 1 of 3

Which Google framework has become the de facto standard for AI security in 2026?

Further reading

Tags
CybersécuritéRSSIAI ActGouvernance IAOWASP

Read next