AI Security
Prompt injection is ranked first in the OWASP Top 10 for LLM applications, and conventional controls were not built to inspect a prompt or a response. We threat-model, test and protect AI systems where they meet your data.
The question we answer
What stops a prompt, a document or a tool response from turning your AI system against your own data?
AuthoritativePrompt injection is ranked first (LLM01) in the OWASP Top 10 for Large Language Model Applications.
AuthoritativeThe EU AI Act’s Article 50 transparency obligations have applied since 2 August 2026 to AI systems that people interact with.
InterpretationConventional controls — data loss prevention, web filtering, network segmentation — were not built to inspect a prompt or a model’s response. AI systems need controls at the model boundary as well.
What we assess
- Threat model for each AI application and agent
- Exposure to prompt injection and data leakage
- Coverage of existing security controls at the model boundary
- Adversarial testing of priority systems
What we implement
- Runtime protection for LLM applications and agents
- Data-leakage controls on prompts and responses
- AI red-teaming as a repeatable exercise
- Monitoring and response playbooks for AI incidents
Evidence you keep
- AI threat model and risk register
- Adversarial test results with remediation status
- Control coverage map at the model boundary
Maps to
Resources for this practice
Our thinking, published.
Sourced notes and open working material. Use them in your own programme — you do not need to engage us to benefit from them.
Note
Nobody asks for the drill record
An empty AI incident log looks the same whether the month was quiet or nobody wanted to write the failure up. The evidence that tells them apart is somewhere else.
Read · 4 minPublished method
Governed private LLM reference architecture
Where runtime controls sit between users, models, tools and data
OpenOther practice areas
Labels show what is traceable to a regulator or standards body (Authoritative) and what is our professional reading of it (Interpretation). Where an engagement involves technology from a vendor Aegis holds a commercial relationship with, we disclose that interest in writing before recommending it.
