Skip to content
All insights

AI Security

6 min

Your AI system is an architecture, not a model

Most AI security effort is aimed at the model. Almost every real failure we see happens somewhere else in the chain.

Ask an organisation how they secure their AI and you will usually hear about the model: which one, hosted where, with what guardrails. It is the wrong unit of analysis. The model is one component in a system that also contains an application, a retrieval pipeline, a set of tools, an agent loop and, at the end of it, production data.

Compromise rarely requires touching the model at all. A document lands in the retrieval corpus carrying instructions. The agent reads it as content, acts on it as direction, and calls a tool it was legitimately granted. Nothing was jailbroken. Every component behaved exactly as designed.

This is why we assess AI as an architecture. The questions that matter are structural: what can reach the retrieval layer, what can the agent invoke without a human, what scope did the MCP server inherit, and what data sits inside the blast radius when all of it behaves normally.

The practical consequence is that guardrails at the model boundary are necessary and insufficient. The controls that hold are the boring architectural ones: scoped tool permissions, provenance on retrieved content, human approval on high-impact actions, and a data boundary you can actually point at.

Next step

Want this applied to your environment?

That is what an assessment is.

The positions above come out of engagements. If any of them describe a problem you recognise, the next step is a scoping conversation.