Beyond the hype: The critical role of security in responsible AI development | Tech Radar
Overview
News, deals, reviews, guides and more on the newest computing gadgets
Start exploring exclusive deals, expert advice and more
Details
Unlock and manage exclusive Techradar member rewards.
Beyond the hype: The critical role of security in responsible AI development
AI pipelines need zero trust principles and continuous human oversight
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Unlock instant access to exclusive member features.
Get full access to premium articles, exclusive features and a growing list of member rewards.
The pressure to ship is the greatest enemy of due diligence. In the AI gold rush, the mandate is clear: Release implementations that are as powerful as possible and as fast as possible.
But this speed-first culture is creating a dangerous vacuum where proper testing, monitoring, and security reviews are being bypassed in both development and production phases. And the risk is compounded by a shift in where release authority sits, with non-technical product managers often leading AI initiatives.
This trend prioritizes market timing over technical integrity. High-pressure shipping is only sustainable if subject matter experts and security teams are empowered to veto a release based on risk.
AI governance under strain: what modern platforms mean for data privacy
This is the evolution of the Dev Ops security gap. In a standard Dev Ops pipeline, we manage predictable code. But in MLOps, we’re managing live, evolving models that require high-privileged access to data and Saa S environments to function. The risks are no longer confined to a simple misconfiguration.
We are now dealing with autonomous activities within the pipeline that are significantly harder to reign in. For developers, the stakes have changed: We’re building far more than just back-end models.
We are deploying internet-facing non-human identities with direct access to our most sensitive data. We must stop treating MLOps security as a secondary concern and start applying the architectural rigor these systems demand.
Before Gen AI became a must-have in every product, most AI implementations were internal. They were tucked safely behind layers of infrastructure, rarely seeing the light of the public internet. This isolation limited their exposure to data poisoning or unauthorized exfiltration.
But Gen AI changed the architecture. Today, AI implementations serve the end user directly and are frequently exposed to the internet. This shift has turned the AI pipeline into a primary attack surface.
Now consider that nearly all AI development happens in the cloud, and the majority of Saa S platforms offer AI applications. Without proper security measures in place, the barrier to entry for an attacker drops considerably when an AI system is exposed to the web.
This complexity grows as we integrate MCP tools to connect AI agents to external Saa S environments. We’re increasingly seeing agentic implementations where Gen AI autonomously uses these tools to move data. This can create a massive security gray area if foundational controls are absent.
Trust and judgement: the challenge facing the AI-driven SOC
The Human Risk Reckoning: Why security must evolve for an AI-augmented workforce
Securing AI infrastructure is critical – here's how to do it
Sensitive data now flows outside of your controlled environment and into external Saa S platforms via MCP. The risk is twofold. First: many MCP servers lack the native authentication controls that developers have come to expect from standard APIs.
Second, the non-deterministic nature of Gen AI means you cannot always predict how the model will interact with these tools. If your AI agent has high level permissions, such as edit or write, without rigorous monitoring, it might autonomously grant access or move data in ways that violate every security protocol in your stack.
There is a common misconception that building on top of major cloud providers solves the security problem. While it’s true these providers offer comprehensive MLOps tools, the responsibility for using them correctly lies entirely with the developer and security team, and their collaborators in the data engineering and Dev Ops teams.
Using a powerful MLOps platform doesn’t mean your pipeline is secure if your data flow is unmonitored or your access controls are overly permissive. You must treat every AI component not just as code, but as a digital identity.
And this identity requires the same zero trust principles you would apply to any human user or external Saa S application.
It’s tempting to use LLMs to automate the complexities of security. Asking an LLM to perform a code review, draft a monitoring plan, or conduct a security assessment can be a productive starting point. However, these outcomes should never be treated as a source of truth.
In MLOps, human expertise remains the only reliable oversight. LLMs are excellent at augmenting the work of an expert, but they cannot replace the nuanced understanding of a human security lead.
Use AI to surface potential issues, but ensure a human expert conducts deeper dives into those issues and guides the final production plan.
You can still minimize security risks without killing your deployment velocity:
-
Commit to a full MLOps lifecycle Security must be a baseline requirement, not a final hurdle. Incorporate rigorous testing and monitoring during both the development and production phases. Conduct a comprehensive security review of the entire pipeline before it goes into production to identify vulnerabilities before they’re exposed to the internet.
-
Perform a comprehensive data flow analysis You must understand where your data originates, how it’s accessed, where it’s altered and where it’s being saved. Map every intermediate step where data might be cached or processed by third-party services to ensure no sensitive information is leaking through the cracks, and understand where real customer data is used versus synthetic data.
-
Apply zero trust to AI identities Use least privilege access when defining read, edit, and write permissions for your AI agents. If your implementation involves external MCP tools or Saa S integrations, perform the same data access and authentication reviews on those external points as you do on your own internal systems.
-
Audit your tooling supply chain and SBOMs Your pipeline is only as secure as the libraries it uses. Regularly review your dependencies for known vulnerabilities that could allow for server hijacking or the loading of malicious datasets. Tracking SBOMs becomes even more important, with more open source and vendor libraries for ML being used.
-
Monitor for non-deterministic risk Because Gen AI can produce different results from the same input, traditional testing is insufficient. You need monitoring in production to catch anomalous behavior or unintended data exposure before it escalates.
The ultimate force multiplier: Secure innovation
The future of development is inseparable from AI, but the novelty of these tools is not an excuse for lax security. We’re moving toward an era where AI agents will be major, high-volume users within our Saa S environments.
If we don’t govern these identities with the same rigor we apply to our human employees, we’re not just building innovative products, we’re building liabilities.
Security must move from being a gatekeeper at the end of the pipeline to being the foundation upon which the pipeline is built. Because in the race to build the most powerful AI, the winners will not just be the fastest to market, but those that earn the most trust.
This article was produced as part of Tech Radar Pro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of Tech Radar Pro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro
You must confirm your public display name before commenting
1 The best i Phone ad Apple never made — watch NASA’s mind-blowing video of the Earth setting behind the moon, shot on an i Phone 17 Pro Max
2'We've identified a security incident': Vercel breach confirmed after hackers claim stolen data for sale online
3 New research suggests Air Pods with cameras can't happen — unless Apple makes a few major changes
4 What is the release date for The Boys season 5 episode 4 on Prime Video?
5I let Chat GPT and Gemini build my PC — here are the components each AI picked
Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.
Key Takeaways
-
News, deals, reviews, guides and more on the newest computing gadgets
-
Start exploring exclusive deals, expert advice and more
-
Unlock and manage exclusive Techradar member rewards
-
Beyond the hype: The critical role of security in responsible AI development
-
AI pipelines need zero trust principles and continuous human oversight



