Issue AI security risk is partitioned into data, model, application and infrastructure domains
Summary
Deloitte organises AI security risk into four domains, namely data, AI models, applications and infrastructure. Data risks include exposure of sensitive information, poisoning of training data and deliberate skewing to create backdoors or biases. Model risks include collapse when models are trained on synthetic data, theft of proprietary models, inversion attacks that reconstruct training data and generative applications taking excessive authority. Application risks cover ethical misuse, input injection and unauthorised access, while infrastructure risks include insecure interfaces, denial of service, third-party supply chain weaknesses, misconfigurations and lateral movement attacks. The report argues many existing practices, such as least-privilege access controls, model isolation, sandboxes and network hardening, can be adapted to these threats. It adds that organisations are still discovering the full scope of exposure and that the window for reactive approaches is closing.
Classification
Evidence 3
- Tech Trends 2026: As technology innovation and adoption accelerate, five trends reveal how successful organizations are moving from experimentation to impact Deloitte Insights (Deloitte Development LLC, US Office of the CTO) page=57;section=The AI dilemma: Securing and leveraging AI for cyber defense / Figure 4 2025-12 accessed 2026-07-26
- Tech Trends 2026: As technology innovation and adoption accelerate, five trends reveal how successful organizations are moving from experimentation to impact Deloitte Insights (Deloitte Development LLC, US Office of the CTO) page=56;section=The AI dilemma: Securing and leveraging AI for cyber defense / Figure 2 2025-12 accessed 2026-07-26
- Tech Trends 2026: As technology innovation and adoption accelerate, five trends reveal how successful organizations are moving from experimentation to impact Deloitte Insights (Deloitte Development LLC, US Office of the CTO) page=55;section=The AI dilemma: Securing and leveraging AI for cyber defense / From risk identification to risk mitigation 2025-12 accessed 2026-07-26
Constituent trends 1
Directly linked signals 1
Relation types: constitutes · direct_urgent
Public id: fm-4da2e2a87a68
