itinfinance.nl

LLMs as a New Attack Surface: what does it mean for AI governance?

Nieuws
26-03-2026
Yuri Bobbert
Large Language Models (LLMs) are transforming industries, but their unique risks demand a new approach to security and governance. A groundbreaking paper co-authored by Anove Co-Founder Prof. dr. Yuri Bobbert and ethical hacker Kevin Zwaan from Q-Cyber exposes how traditional security controls fall short when AI behavior can be steered through plain everyday language.

A recent demonstration showed how an LLM could be "radicalized" over eight hours, bypassing safety guardrails to generate malware at scale. This wasn't a highly technical code-written software exploit; it was achieved through manipulation and persuasion, taking advantage of the model’s contextual learning to make it unlearn its security protocols, revealing a critical gap in AI security.

The paper highlights that AI's attack surface is broader than code. It includes the model, prompts, user interfaces, policies, and even the organizational context. When LLMs are integrated into workflows with access to tools, APIs, and sensitive data, the risks multiply, ranging from generating malicious content to enabling large-scale cyberattacks. AI systems are dynamic, made up of interconnected components that evolve rapidly. As a result, traditional governance can’t keep up. Static checklists and one-time audits aren’t enough (if they ever were). AI management must be continuous, automated, and evidence-based.

[....]

Lees verder op: anove.ai

Gerelateerde vacatures

Geïnteresseerd in een carrière bij organisaties in ditzelfde vakgebied? Bekijk hieronder de gerelateerde vacatures en vind de perfecte match voor jou!
PGB Pensioendiensten
7.541 - 10.056
Senior
Amstelveen
Als Information Security Officer (ISO) bij PGB Pensioendiensten stuur je op informatiebeveiliging en risicomanagement: beleid, raamwerk en compliance (DORA, AVG, ISO 27001), risicoanalyses, incidentregistratie, monitoring/rapportage, security by design en bewustwording.
NN
Marktconform
Medior
Arnhem
Als Medior Cloud / Infra Engineer (AWS & Kubernetes) (Freelance Nederlandstalig) bij het NN Retail Service Team beheer en verbeter je AWS- en Kubernetes-platformen: incidenten oplossen, deployments draaien, security/compliance borgen,...
NN
4.324 - 5.765
Junior, Medior
Den Haag
As a Junior/Medior Information Security Officer at NN, you manage information security risks with DevOps and product owners, perform risk assessments, verify security controls, support audits, conduct threat modelling, review...
Achmea
4.664 - 6.578
Medior
Apeldoorn
Als DevOps Engineer - Analyse Platform Azure bij Achmea optimaliseer en schaal je het Azure-analyseplatform end-to-end, migreer je naar Fabric, borg je security/monitoring/compliance, los je complexe incidenten op (RCA) en...