What I see looking across the cockpit out of my sailboat is chaos involving seven jet skis, a pontoon boat, and nobody over the age of 25, and they are all intoxicated and sunburned. Looking at my watch, it’s just lunch as I start typing. I always keep that seaborn Florida man behavior in mind as I think about esoteric things like AI security.
Every CISO I know has the same stack of reading on their desk right now. The NIST AI Risk Management Framework sits next to the OWASP LLM Top 10 and some vendor white paper promising AI-powered defense against AI-powered attacks. A board member forwarded them something from BCG about how 89% of companies reported AI-enabled attacks last year and cyber spending climbed 12%. After reading all of it, they still don’t know what to do differently on Monday morning.
The existing AI security space is almost entirely governance, risk, and compliance. It tells you what to worry about and how to organize your worrying, but not how to defend against a specific AI-augmented threat using the tools you already own. This series is my attempt to close that gap.
What Already Exists
Like a drunk 20-something looking for more White Claw. I went looking for operational AI security guidance written for practitioners at small and mid-sized companies. Actual defensive technique, not program-level strategy or vendor evaluations or risk registers. This section maps what exists as of September 2026, organized by what each category actually delivers to a working security team.
Governance and strategy frameworks dominate the space. The NIST AI RMF and its Generative AI Profile (AI 600-1) provide four functions: Govern, Map, Measure, and Manage. Every verb in that framework describes assessment, documentation, or oversight. ISO 42001 is an AI management system standard, which is governance by definition. The EU AI Act is regulatory classification and conformity assessment. The most operationally oriented document in this category is the SANS/CSA “AI Vulnerability Storm” briefing from April 2026, produced over a single weekend by more than 60 contributors and reviewed by more than 250 CISOs. It delivers a 13-item risk register mapped to four industry frameworks, an 11-item priority actions table, and a board briefing section. Its first priority action, pointing AI agents at your own code this week, comes closer to operations than anything else in this category. None of it tells you how to build detection for a specific threat with the SIEM you already run.
Vendor playbooks come closer but serve a different purpose. The Security Boulevard “CISO’s AI Defense Playbook” from August 2026 structures its guidance as five phases with budget splits and vendor scorecards. Palo Alto published “Resilience by Design” touching graceful degradation. Wiz offers an “AI Threat Readiness” operating model. SentinelOne addresses shadow AI detection. Each vendor covers one slice of the problem from the perspective of their product category. When a company that sells endpoint protection writes about AI threats, you get a document about how AI threats affect endpoints, and it ends with a recommendation to improve your endpoint protection.
Attack taxonomies catalog what adversaries do to and with AI systems. MITRE ATLAS, which moved to monthly content releases in 2026, contained 16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations, and 73 case studies as of its September 2026 release (v2026.09). OWASP publishes the LLM Top 10 (2026) and the Agentic Top 10 (2026). The MAESTRO framework maps agentic AI threats across seven layers. STRIDE-AI adapts the classic STRIDE model for AI systems. ATLAS in particular gives defenders a structured vocabulary modeled on the ATT&CK framework that security teams already know. But as a 2025 risk-scoring paper summarized the critique, ATLAS is strong on taxonomy and weak on risk prioritization and impact-weighted scoring. A security team can build a complete ATLAS-based threat model and still have no runtime defenses protecting those attack pathways in production.
Academic research tackles narrow problems in depth. A 2025 arXiv paper proposes the AIJET principles for training humans against AI cognitive manipulation. It is a single-problem research paper written for peer review, not operational guidance for a CISO running a three-person team.
Industry threat reports provide the statistics that frame the conversation. CrowdStrike’s 2026 Global Threat Report puts average eCrime breakout time at 29 minutes. Darktrace’s 2026 survey says 96% of security professionals agree AI improves their speed, while 92% worry about security implications of AI agents across their workforce. Good data for understanding the scale of the problem. No methodology for doing anything about it.
What’s Missing
Two pieces published in April 2026 came close to the argument this series makes, and both stopped short.
A CIO.com piece from Red Canary described AI-powered threats as “more of an evolution in speed and automation than a revolution in attack methodology” and argued that the core tenets of information security remain the most effective defense. The framing is right. But they never built the operational bridge between that principle and specific defensive actions for each threat category. A GTK Cyber article from the same month argued that AI-enhanced attacks requiring a fundamentally different defensive posture are still low frequency relative to traditional exploitation, and called out the governance gap, shadow AI risk, and the fact that nobody owns the intersection. A single article making an argument, not a methodology.
Nobody is writing serialized, threat-model-specific operational content that starts from what you already have deployed, works forward through where those tools break against AI-augmented adversaries, and arrives at what you can build with an LLM API call, a Python script, and the data your existing infrastructure already collects.
The Analytical Structure
Each article in this series examines one specific AI-augmented threat using a four-part structure.
Threat Model defines how an AI-augmented adversary executes a particular class of attack against a particular class of target. The constraints receive as much attention as the capabilities. This is the foundational premise of the entire series: AI attackers are human-like, not godlike. They need infrastructure, they generate network traffic, and they move through the kill chain in order. The physics of the network haven’t changed. The economics of the attack have. An AI attacker whose reconnaissance takes minutes instead of days and whose phishing campaign reaches every employee simultaneously instead of five at a time is a known adversary whose cost structure has collapsed. Modeling the threat at this level, bounded and specific rather than apocalyptic, lets defenders identify exactly where to interfere.
Traditional Tools takes an honest inventory of what most small and mid-sized companies actually have deployed and what those tools were designed to catch. Email gateway with content filtering. Endpoint protection with behavioral detection. A SIEM collecting logs that nobody has time to review past the first page of alerts. Firewall with default deny on some outbound ports. MFA on some systems. Annual awareness training. Quarterly vulnerability scans. Most AI security content implicitly tells you to throw away everything you have and buy a new platform. This section says here is what you already paid for and what it was built to do.
The Gap is the analytical core of each article. It answers one question: which operational constraint did your existing tools rely on that AI has now removed?
Your email gateway catches phishing with bad grammar and known-bad sender domains. It relied on the constraint that personalized, grammatically perfect phishing at scale was expensive and slow. Your endpoint protection catches known malware signatures and some behavioral patterns. It relied on the constraint that generating new evasive variants took a skilled developer meaningful time. Your SIEM alerts on threshold violations. It relied on the constraint that pre-attack reconnaissance generated enough noise per target to cross those thresholds. When an AI correlates public data sources without ever touching your network, no threshold fires.
In each case, the tools aren’t bad. They were designed for an adversary who operated under constraints that no longer apply, and the gap analysis identifies, with precision, which constraint fell and what it exposed.
AI Augmentation is what you build on top of what you have. A specific capability built with the tools your team can access today, layered onto the infrastructure you already operate, something a reader could prototype in a week. But the augmentation proposals are not consequence-free. Every AI capability you add creates a new dependency, a new assumption that can fail, a new surface an adversary could target. This series addresses those risks as each augmentation is introduced, because pretending they don’t exist would undermine the entire argument.
The Thesis Underneath the Structure
AI defense creates its own attack surface.
Every AI tool you deploy for defense adds a dependency your team didn’t have before. Your detection now requires a cloud API that can go down. Your analysts trust model output they cannot independently verify. Your behavioral baseline might be slowly absorbing an attacker’s pattern as normal. Your cost structure is exposed to an adversary who can spike your API bill. Your analytical capability depends on a network connection an adversary could sever at the worst possible moment.
The existing frameworks address the governance of AI systems and the taxonomy of AI attacks. They do not address what happens when the defender’s own AI becomes a single point of failure, a target for manipulation, or a dependency that erodes the team’s ability to operate without it. One full article in this series is dedicated to that problem, but the concern runs through every piece. Each time an AI augmentation is proposed, the article identifies what breaks if that augmentation fails, what an adversary could do to cause that failure, and what the manual fallback looks like.
The Series
Ten chapters follow, each using the four-part structure to examine one threat. A closing chapter answers the question every resource-constrained CISO asks after absorbing all ten: where do I start?
The ten threat models:
AI-augmented social engineering. AI-compressed reconnaissance and attack planning. AI-powered detection evasion. Shadow AI and AI-enabled data exfiltration. Data integrity attacks. AI defense dependency and operational resilience. Behavioral baselining and anomaly detection from neglected data. AI-enabled supply chain compromise. AI attacks on identity and authentication systems. AI-accelerated post-compromise operations.
Each chapter stands alone as a complete analysis of one threat with defensive guidance you can act on. Together they build an operational framework for AI security that starts from what you already own, acknowledges the constraints you actually operate under, and builds capabilities your team can sustain.
Works Cited
Aydin, Y. (2025). “Think first, verify always”: Training humans to face AI risks (arXiv:2508.03714). arXiv. https://arxiv.org/abs/2508.03714
CrowdStrike. (2026, February 24). 2026 CrowdStrike Global Threat Report: AI accelerates adversaries and reshapes the attack surface [Press release]. https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/
Darktrace. (2026, March 26). State of AI Cybersecurity 2026: 92% of security professionals concerned about the impact of AI agents. https://www.darktrace.com/blog/state-of-ai-cybersecurity-2026-92-of-security-professionals-concerned-about-the-impact-of-ai-agents
European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
Evron, G., Lee, R. T., & Mogull, R. (2026). The AI vulnerability storm: Building a Mythos-ready security program. Cloud Security Alliance, SANS Institute, [un]prompted, and OWASP GenAI Security Project. https://labs.cloudsecurityalliance.org/mythos-ciso/
Givre, C. (2026, April 24). What CISOs get wrong about AI risk. GTK Cyber. https://gtkcyber.com/blog/what-cisos-get-wrong-about-ai-risk/
Gupta, D. (2026, August). The CISO’s AI defense playbook: A practical framework. Security Boulevard. https://securityboulevard.com/2026/08/the-cisos-ai-defense-playbook-a-practical-framework/
Huang, K. (2025, February 6). Agentic AI threat modeling framework: MAESTRO. Cloud Security Alliance. https://cloudsecurityalliance.org/blog/2025/02/06/agentic-ai-threat-modeling-framework-maestro
International Organization for Standardization. (2023). ISO/IEC 42001:2023 Information technology: Artificial intelligence: Management system.
Mauri, L., & Damiani, E. (2021). STRIDE-AI: An approach to identifying vulnerabilities of machine learning assets. In Proceedings of the 2021 IEEE International Conference on Cyber Security and Resilience (pp. 147–154). https://doi.org/10.1109/CSR51186.2021.9527917
MITRE. (2026). ATLAS data releases [Data set]. GitHub. https://github.com/mitre-atlas/atlas-data/releases
MITRE. (2026, September 14). ATLAS data, version 2026.09 [Data set and changelog]. GitHub. https://github.com/mitre-atlas/atlas-data
Muhammad, A. E., Yow, K. C., Baili, J., Cho, Y., & Nam, Y. (2025). CORTEX: Composite overlay for risk tiering and exposure in operational AI systems (arXiv:2508.19281). arXiv. https://arxiv.org/abs/2508.19281
National Institute of Standards and Technology. (2023). Artificial intelligence risk management framework (AI RMF 1.0) (NIST AI 100-1). https://doi.org/10.6028/NIST.AI.100-1
National Institute of Standards and Technology. (2024). Artificial intelligence risk management framework: Generative artificial intelligence profile (NIST AI 600-1). https://doi.org/10.6028/NIST.AI.600-1
O’Niell, C., Troha, C., Lyon, V., Chen, A., Chopra, S., Jain, I., Asen, A., & Mitchell, S. (2026, August 27). Cybersecurity budgets are growing fast. AI threats are growing faster. Boston Consulting Group. https://www.bcg.com/publications/2026/cybersecurity-spending-ai-threat-trends
OWASP GenAI Security Project. (2025, December). OWASP Top 10 for agentic applications for 2026. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
OWASP GenAI Security Project. (2026). OWASP GenAI LLM Top 10 2026. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/
Palo Alto Networks. (2025, August 1). Resilience by design: Security in the age of offensive AI. https://www.paloaltonetworks.com/blog/cloud-security/resilence-by-design/
Red Canary. (2026, April 10). The state of AI security in 2026. CIO. https://www.cio.com/article/4157398/the-state-of-ai-security-in-2026.html
SANS Institute. (2026, April 14). SANS Institute, Cloud Security Alliance, [un]prompted, and OWASP GenAI Security Project release emergency strategy briefing [Press release]. https://www.sans.org/press/announcements/emergency-strategy-briefing-ai-driven-vulnerability-discovery-compresses-exploit-timelines
SentinelOne. (2026, March 25). What is shadow AI? Risks, challenges and governance strategies. https://www.sentinelone.com/cybersecurity-101/cybersecurity/what-is-shadow-ai/
Wiz. (2026, May 8). AI threat readiness framework. https://www.wiz.io/blog/ai-threat-readiness-framework