top of page

When Trust Has No Security, AI Risks Everything

  • ICIT Research
  • 11 minutes ago
  • 2 min read

July 2026

By Malcolm Harkins


Artificial intelligence is rapidly becoming embedded into the operational core of healthcare, finance, critical infrastructure, government, and enterprise decision-making. Organizations are deploying large language models, AI assistants, autonomous agents, and agentic workflows at unprecedented speed. Yet many are doing so under a dangerous assumption that existing cybersecurity controls, compliance certifications, and governance frameworks are enough to secure AI systems. They are not.


Traditional cybersecurity was designed to protect infrastructure, networks, endpoints, applications, identities, and data. AI changes the threat model. Models can be manipulated through language, prompts, images, embeddings, documents, retrieved content, and semantic interactions. In agentic environments, compromised AI systems can act through legitimate credentials, approved workflows, and trusted business logic, creating risks that may bypass traditional security tools entirely.


Key findings include:

  • Compliance is not security: Certifications such as SOC 2, ISO 27001, HIPAA, GDPR, NIST CSF, or PCI DSS can coexist with serious AI-specific exposure.

  • Runtime risk is the gap: Leading AI governance frameworks emphasize pre-deployment assessment, but often lack protections for live model behavior, prompt injection, semantic attacks, and agentic workflow compromise.

  • Language becomes an attack vector: AI systems can be manipulated without malware, credential theft, or traditional exploit chains.

  • Agentic AI expands the blast radius: Autonomous systems that access tools, APIs, data stores, and workflows can become attack infrastructure if compromised.

  • Trust must be operational: AI cannot be considered trustworthy unless it can resist, detect, and recover from adversarial manipulation while it is running.


The paper calls on organizations, boards, executives, security teams, and regulators to move beyond the illusion that responsible AI policies or conventional cybersecurity controls are sufficient. Trustworthy AI requires operational assurance: runtime visibility, behavioral monitoring, semantic threat detection, agentic workflow protection, auditability, and real-time response. As AI becomes more deeply connected to critical systems and business decisions, the standard must be clear: AI trust cannot exist without AI security.






About ICIT

The Institute for Critical Infrastructure Technology (ICIT) is a nonprofit, nonpartisan, 501(c)3think tank with the mission of modernizing, securing, and making resilient critical infrastructure that provides for people’s foundational needs. ICIT takes no institutional positions on policy matters. Rather than advocate, ICIT is dedicated to being a resource for the organizations and communities that share our mission. By applying a people-centric lens to critical infrastructure research and decision making, our work ensures that modernization and security investments have a lasting, positive impact on society. Learn more at www.icitech.org.



The Institute for Critical Infrastructure Technology is a non-partisan 501(c)3 not-for-profit organization. 

EIN #47-5294309

Follow Us

  • LinkedIn
  • Youtube

Important Links

 Support

+  Privacy Policy

Get the latest news & expert opinions delivered straight to your inbox

Keeping People at the Center of Critical Infrastructure

© 2026 by The Institute for Critical Infrastructure Technology (ICIT)

bottom of page