News Security Technology

AI’s Threat Isn’t Tech, But Failure Of Access Control: Experts

Frictionless access control
The argument, put forth by Arti Raman, the CEO of security firm Portal26, suggests that the primary vulnerability is a lack of control over user permissions

A new report has highlighted a critical blind spot in the rush to adopt artificial intelligence, with experts arguing that the technology’s biggest security risk is not its sophistication but a fundamental human failing: inadequate access controls. The findings challenge the prevailing focus on the inherent risks of AI models, instead redirecting attention to how organisations manage who can interact with the technology and what data they can access.

The argument, put forth by Arti Raman, the CEO of security firm Portal26, suggests that the primary vulnerability is a lack of control over user permissions. This concern is particularly acute for public institutions, with major AI providers like OpenAI and Anthropic reportedly offering their services to the US government at significantly reduced costs. “The central problem is not the technology itself, but how we use it and, more importantly, how we govern who has access,” Raman said. “The biggest threat to AI security isn’t some complex attack on the model—it’s the simple human element and the absence of proper access controls.”

The report raises questions about how sensitive government data will be managed and protected within these systems.

A recent study by IBM found that 97 per cent of organisations that had experienced an AI-related security incident lacked proper access controls. This security gap directly led to data compromises in 60 per cent of cases and disrupted operations for 31 per cent of the affected businesses. For government agencies, already a prime target for cyber-attacks, these vulnerabilities are magnified.

The findings underscore the urgent need for a shift in approach. Rather than focusing solely on the technology, industry leaders must invest in robust, real-time training and education for employees. The report also identifies a clear market opportunity for innovators to develop new solutions for AI access and identity control, ensuring that a model’s capabilities are carefully aligned with the data it is permitted to handle.

Leave a Reply

Your email address will not be published. Required fields are marked *