Point of view · April 29, 2025

Is AI Security a Distraction

And what is it costing you?

The Misplaced Focus on AI Security

The industry is obsessed with AI security. Every vendor, consultant, and CISO is racing to bolt on security solutions, patch vulnerabilities, and deploy red teams. But here’s the uncomfortable truth:

AI security alone is insufficient right now. Not because it’s unimportant, but because we’ve skipped the most crucial step: AI Safety.

We’re spending valuable resources protecting systems that were never designed to be safe in the first place. Let me emphasize this point: Securing unsafe systems is fundamentally misguided.

Why does this matter to you?

Because when safety is treated as an afterthought by the companies building AI, it’s your organization, your brand, reputation, and bottom line, that suffers. The vendor’s risk becomes your risk.

First, Build the Foundation

AI Safety is about designing controls to prevent harmful outcomes at their source. It begins with verifiable evidence that your AI system’s controls are in place, effective, and protected throughout its lifecycle. That’s the necessary foundation. Before hiring a red team or worrying about adversarial attacks, ask:

  • Does your AI system have robust alignment mechanisms in place: design features that ensure it pursues only intended goals?
  • Have you rigorously defined what constitutes a harmful outcome in your specific context?
  • Are there comprehensive guardrails to prevent harmful decisions?

No? Be careful, you’re entering territory where security investments become superficial and wasteful, like installing an expensive alarm system on a house with no walls.

Security’s True Purpose

You can’t secure away bad design. AI Security protects the controls that manage AI risk. When your AI system is properly aligned and safeguarded, security ensures those safety mechanisms cannot be bypassed or defeated. Attempting to secure an inherently unsafe system is merely addressing symptoms while ignoring the disease.

  • Without foundational safety mechanisms, security measures protect nothing of value.
  • When your AI system is properly aligned and safeguarded, then security ensures those safety mechanisms cannot be bypassed or defeated.
  • Attempting to secure an inherently unsafe system is merely addressing symptoms while ignoring the disease.

When Security Can’t Catch Safety Failures

A laptop screen showing an AI assistant prompt reading 'What can I help with?' with quick actions for Search, Reason, Brainstorm and Analyze data

Here’s an example we are all too familiar with: even in highly secure environments, large language models have produced harmful or misleading outputs, without any external breach.

In many cases, the systems were deployed behind firewalls, with access controls and monitoring in place. Yet when users interacted with the models, they received hallucinated content, sensitive internal references, or confidently wrong responses, sometimes even formatted as if they were authoritative company documents.

No one broke in. No code was compromised. The problem wasn’t a lack of security, it was the absence of safety constraints and alignment controls.

Security didn’t fail. Safety was never built.

This is the reality facing organizations deploying generative AI: even with traditional protections in place, AI systems can behave in unexpected, uncontrolled, and costly ways, if safety is treated as an afterthought.

Build AI Systems Worth Securing

Regulators and stakeholders aren’t asking if your AI system is “secured”: they’re asking if it’s safe, reliable, and verifiable. They want to know that your controls exist, they work, and they can’t be easily bypassed.

Securing unsafe AI is a waste. Build safe systems and products first. Prove it. Then protect them.

Three parallel painted lanes on dark asphalt, red, yellow and blue, running away into the distance
Like lanes on a track, AI safety, security, and assurance must stay aligned, or your system ends up in the wrong direction at full speed.

Talk to the people who'll do the work.

Book a consultation