* [![perspectives](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com.au/perspectives)
* Are Enterprises Securing the Wrong Layer of AI?

# Are Enterprises Securing the Wrong Layer of AI?

![Are Enterprises Securing the Wrong Layer of AI?](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Securing-the-Wrong-Layer-featured.jpg)  
**By [Ian Swanson](https://www.paloaltonetworks.com.au/perspectives/author/ian-swanson/ "Posts by Ian Swanson")** | **5 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=Are Enterprises Securing the Wrong Layer of AI?\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com.au%2Fperspectives%2Fare-enterprises-securing-the-wrong-layer-of-ai%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com.au/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com.au/perspectives/are-enterprises-securing-the-wrong-layer-of-ai/?pdf=download&lg=en&_wpnonce=4139c4630b "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/02/Ian-BW-Headshot.jpeg)  
  Ian Swanson is Vice President of AI Security Products at Palo Alto Networks, where he leads strategy and product innovation to secure the next generation of artificial intelligence applications. He joined Palo Alto Networks following its acquisition of Protect AI, the company he founded and led as CEO, which became the industry's leading platform for managing risk and securing AI and machine learning environments end-to-end. Before founding Protect AI, Ian built and scaled global AI businesses at Amazon Web Services, where he led worldwide AI and ML, and at Oracle, where he served as Vice President of Machine Learning. Earlier in his career, he was the CEO and Founder of DataScience.com, an enterprise data science platform acquired by Oracle in 2018, and the CEO of Sometrics, acquired by American Express. Ian has also held executive roles at American Express and Sprint....

[Learn more](https://www.paloaltonetworks.com.au/perspectives/author/ian-swanson/)

## IN THIS ARTICLE

Not long ago, I joined a call with one of the largest software companies in the world. It was the kind of meeting where cameras were off and everyone was multitasking. The AI research team was on the line, and so was the application security team. They were technically in the same meeting, but strategically they were in different worlds.

About 10 minutes in, an AI researcher spoke up. "This security discussion doesn't really apply to us. We are experimenting. Nothing is in production."

Before I could respond, the head of application security stepped in. "Are you sourcing models from external repositories?"

"Yes."  
"Are you training them on customer data?"  
"Yes."  
"Are you running this in our cloud environment?"  
"Yes."

There was a long silence. "You are importing significant risk," the security leader said, "and you do not even realize it."

That exchange reflects what is happening inside many enterprises today. AI innovation is accelerating at extraordinary speed. Boards are asking how fast the organization can move. Meanwhile, security leaders are trying to determine what is running in their environment.

The conversation now is about understanding what is under the hood, not slowing innovation.

## We Secured the Fuel, but We Ignored the Engine

For more than a decade, enterprise security strategy has focused on protecting data. In the context of AI, data is the fuel. Organizations have invested heavily in data protection, encryption, governance and privacy controls. Those investments were necessary.

But if data is the fuel, the machine learning model is the engine.

Today, enterprises routinely download pretrained models from public repositories, integrate them into internal systems, fine-tune them with proprietary data and deploy them into production environments. In many cases, these models are treated as opaque components. They are assumed to be safe because they are popular or open source. This assumption is flawed.

Public model hubs host millions of models. The ecosystem drives remarkable innovation, but it also creates opportunity for abuse. We have observed models impersonating trusted brands through name squatting techniques. Some of these models were downloaded thousands of times before anyone recognized that they attempted to exfiltrate credentials or execute malicious code. In these scenarios, the compromise is in the model itself.

When I ask CISOs how many machine learning models exist in their environment, I often hear confident estimates in the low hundreds. After scanning cloud storage, developer endpoints and container registries, the actual number is frequently in the tens of thousands. In one financial institution, the gap between perception and reality was more than 90,000 models.

That level of blind spot would be unacceptable in any other domain of cybersecurity.

## The Velocity Problem

At the same time, development velocity has changed. Generative AI tools are amplifying productivity across engineering teams. Developers are using AI to write code, refactor systems and build new services at unprecedented speed.

In the right hands, this acceleration creates a significant competitive advantage. Speed without control, however, introduces risk.

Advanced AI tooling is a high-performance vehicle. Experienced engineers can use it to build resilient, secure systems. Less experienced practitioners can unknowingly introduce vulnerabilities, insecure dependencies and flawed model integrations at scale.

The objective is to ensure that governance, visibility and control mechanisms evolve at the same pace as innovation. In security terms, velocity demands stronger control planes.

## Moving Beyond Experimental AI

Many enterprises still treat AI as a pilot initiative. It is viewed as experimental or contained within innovation teams. That framing is increasingly inaccurate. AI systems now influence customer interactions, operational workflows, financial decisioning and product development.

When AI moves from the lab into enterprise infrastructure, it inherits the same accountability requirements as any other critical system, which is where Machine Learning Security Operations becomes essential. MLSecOps applies operational discipline to the unique characteristics of AI systems. It recognizes that models are probabilistic, they can contain hidden behaviors, and they may originate from complex supply chains.

For CISOs, three imperatives stand out:

1. **Establish Comprehensive Visibility**  
   You cannot protect what you cannot inventory. Model discovery must extend across cloud storage, developer workstations, build pipelines and runtime environments. Organizations need to know precisely how many models exist, where they reside and how they are being used.

2. **Assess the Model Itself**  
   Traditional application testing is insufficient. Security teams must evaluate models for prompt injection susceptibility, data leakage risk, hidden backdoors and supply chain manipulation. The model is an executable intelligence layer.

3. **Unify Research and Security Functions**  
   In many enterprises, AI research teams and security teams operate in parallel. That separation creates risk. Cross-functional governance, shared review processes and aligned accountability structures are critical. Security cannot be an afterthought once experimentation becomes deployment.

AI is arguably the most transformative technology of this era. It has the potential to reduce costs, increase efficiency and unlock new revenue streams. But, transformative technologies also reshape the threat landscape.

Data security remains foundational, although it is no longer sufficient. The enterprise must secure both the engine and the fuel.

AI models should not be treated as mysterious black boxes. They are powerful computational systems that require inspection, validation, continuous monitoring and governance before they are trusted in production.

Speed and security are not opposing forces. In the AI era, security is what enables sustainable speed. AI should not be in any enterprise without an AI security strategy embedded at its core.

**Editor's note:** Ian shared these thoughts in the Threat Vector podcast, "Securing the AI Supply Chain." Catch the whole story and [listen to the full podcast](https://www.paloaltonetworks.com/resources/podcasts/threat-vector-securing-the-ai-supply-chain).

Curious about what else Ian has to say? Check out his other articles on [Perspectives](https://www.paloaltonetworks.com/perspectives/author/ian-swanson/) and [AI Security Nexus](https://www.paloaltonetworks.com/ai).

* [AI](https://www.paloaltonetworks.com.au/perspectives/all-articles/?cat=ai)
* [Business Transformation](https://www.paloaltonetworks.com.au/perspectives/all-articles/?cat=business-transformation)
* [Secure AI Usage](https://www.paloaltonetworks.com.au/perspectives/all-articles/?cat=secure-ai-usage)

## Related Content

![](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://www.paloaltonetworks.com.au/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://www.paloaltonetworks.com.au/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Weaponized-Intelligence-featured.jpg) BLOG

### AI

**Weaponized Intelligence**

We are building the foundation that makes defense possible....

[Nikesh Arora](https://www.paloaltonetworks.com.au/perspectives/author/nikesh-arora/ "Posts by Nikesh Arora")
[](https://www.paloaltonetworks.com.au/perspectives/weaponized-intelligence/)  
![](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/RFP-Bottleneck-featured.jpg) BLOG

### AI

**From Weeks to Minutes: How We Applied an AI-First Transformation to the RFP Bottleneck**

Understanding why manual efforts burn hundreds of hours and are bottlenecki...

[Sandeep Uttamchandani](https://www.paloaltonetworks.com.au/perspectives/author/sandeep-uttamchandani/ "Posts by Sandeep Uttamchandani")
[](https://www.paloaltonetworks.com.au/perspectives/from-weeks-to-minutes-how-we-applied-an-ai-first-transformation-to-the-rfp-bottleneck/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* AU  
  Select your language
