Jonathan Magee
AI Security Consultant, Palo Alto Networks
Artificial intelligence is rapidly moving from experimental capability to a core component of enterprise operations. Across industries, organisations are using AI to accelerate analysis, improve productivity, and support decision-making at a scale that was previously not possible. Tasks that once required significant human effort can now be completed in seconds, and AI systems are increasingly embedded directly into business workflows.
This shift is not simply an efficiency gain. It represents a structural change in how digital systems operate inside organisations.
The question facing security leaders is no longer whether AI will be adopted, but how its behaviour can be understood, constrained, and trusted once it becomes part of core operational environments.
Why AI Security Is Different
Traditional cybersecurity has been built around a relatively stable assumption: systems behave predictably. Security controls focus on protecting infrastructure, enforcing access policies, and detecting malicious activity within defined technical boundaries. Artificial intelligence breaks that assumption.
AI systems do not simply execute predefined logic. They interpret context, generate outputs, and increasingly interact with external systems. As organisations move toward agentic AI — systems that can reason, plan, and execute tasks autonomously — the distinction between information processing and action begins to disappear. Security teams are no longer dealing only with system compromise or data protection. They must now consider behavioural risk: what an AI system might infer, decide, or do when exposed to specific inputs, and how those behaviours can be manipulated.
A useful way to frame this is that organisations are moving from securing systems to securing decision pathways. The primary risk no longer only concerns infrastructure compromise — it extends to the integrity of the decisions AI systems produce.
Techniques such as prompt injection highlight this evolution. Rather than exploiting a software vulnerability, attackers embed instructions within content an AI system processes, influencing its behaviour without ever touching the application layer. In 2025, a vulnerability in a widely deployed enterprise AI assistant demonstrated this precisely: a specially crafted email caused the system to silently access internal files and transmit their contents externally — without user interaction and without triggering a single security alert. It was the first confirmed real-world case of this attack type causing actual data theft in a live production environment.
Cybersecurity Risks in AI-Enabled Enterprises
Data has always been central to cybersecurity, but AI changes how it can be exposed. To deliver value, AI systems are integrated across enterprise knowledge sources, communication platforms and business applications. This expands the pathways through which sensitive information may be accessed — sometimes by design, sometimes by accident.
This is particularly relevant in Ireland, where organisations in financial services, pharma and the public sector already face strict data protection obligations. Even well-intentioned AI use creates compliance risk if governance has not kept pace. Employees at one major organisation discovered this when proprietary source code shared with a public AI tool was later found to have been retained — with no awareness until an internal audit surfaced it.
Three risks now define the AI security landscape:
Uncontrolled adoption.
AI tools are being integrated into daily workflows at significant speed, often outside formal governance structures. While this improves productivity, it creates visibility gaps. Sensitive information may be processed through systems that are not monitored, controlled, or fully understood by security teams.
Autonomous AI agents.
AI is increasingly shifting from advisory systems to operational systems. Agents can now execute tasks, interact with enterprise applications, and initiate actions across multiple environments. This introduces a new risk profile where system behaviour is not just reactive, but active and continuous. Security controls must evolve to define not only what these systems can access, but what they are permitted to do.
Manipulation of AI behaviour.
AI introduces attack patterns that differ fundamentally from traditional security threats. Instead of exploiting code, adversaries can influence outcomes by shaping the inputs an AI system relies on. Prompt injection is one example of this category of risk. It demonstrates that the integrity of AI outputs depends not only on system security, but on the trustworthiness of the information the system processes.
In practice, this means attackers are increasingly targeting decision-making rather than infrastructure.
What Security Leaders Should Do Now
The shift described in this article demands a corresponding shift in how security is practised. Visibility comes first — you cannot govern AI behaviour you cannot see. That means mapping every AI tool, model and agent across your environment, including the ones your teams adopted without asking. For most organisations, the inventory alone will change the conversation.
From there, treat AI interactions as a new category of security telemetry. Every prompt in and every response out is an auditable event. If you cannot inspect it, you cannot defend it. Runtime protection for AI systems — sitting between users, agents and the data they can reach — is no longer optional for organisations operating at scale.
Most critically, accept that the threat model has changed. The adversary is no longer just trying to breach your perimeter. They are trying to manipulate your AI systems into doing their work for them — through the documents your agents read, the emails your assistants process, the tools your agents invoke. Defending against that requires controls at the reasoning layer, not just the network layer.
For Irish security leaders, the window to get ahead of this is now. The incidents are already happening. The organisations that respond before the breach will define what good looks like — and Ireland has the talent and the ecosystem to be among them.
Jonathan Magee is an AI Security Consultant at Palo Alto Networks, specialising in securing AI systems and agentic applications for enterprise organisations.