惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
F
Fortinet All Blogs
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
D
Docker
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
爱范儿
爱范儿
V
Visual Studio Blog
Last Week in AI
Last Week in AI
WordPress大学
WordPress大学
aimingoo的专栏
aimingoo的专栏
小众软件
小众软件
L
LangChain Blog
Vercel News
Vercel News
阮一峰的网络日志
阮一峰的网络日志
IT之家
IT之家
P
Proofpoint News Feed
博客园_首页
D
DataBreaches.Net
T
The Blog of Author Tim Ferriss
The GitHub Blog
The GitHub Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
C
Check Point Blog
Engineering at Meta
Engineering at Meta
Microsoft Azure Blog
Microsoft Azure Blog

Fortinet All Blogs

FortiSOAR 8.0 Unites Agentic AI and Automation to Revolutionize Security Operations | Fortinet Blog The Cybersecurity Hiring Challenge | Fortinet Blog Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers | FortiGuard Labs FortiManagement Cloud: Centralized Network and Security Control for Distributed SMB Operations | Fortinet Blog Fortinet Joins Project Watershed 250 to Strengthen National Water Cybersecurity Infrastructure | Fortinet Blog Fortinet and FIRST: Strengthening Cyber Resilience through Global Collaboration | Fortinet Blog Someone Else Is Using Your AI | FortiGuard Labs The Industrialization of Cybercrime in Africa | Fortinet Blog Join the 2026 SASE Summit: Building Autonomous Trust for the AI Era | Fortinet Blog Defending Critical Infrastructure in the Age of Internet-Connected Facilities | Fortinet Blog Black Hat and DEF CON 2026: When Autonomous AI Became Operational | Fortinet Blog Public-Private Partnership Must Move at the Speed of Cyber Risk | Fortinet Blog Secure by Design: Fortinet’s Continued Commitment and the Work Ahead | CISO Collective From Awareness to Action: Building A Behavior-Based Security Program | Fortinet Blog Multi-Functional Linux Botnet “Evooo1Bot” | FortiGuard Labs Cybersecurity Skills Gap: More Than Just a Workforce Challenge | Fortinet Blog Fortinet Achieves IEC 62443-4-2 Security Level 4 Certification for FortiOS 7.6 | Fortinet Blog QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | FortiGuard Labs From Threat Intelligence to Action: The First Cybercrime Bounty Is Now Live | Fortinet Blog While External Threats Are Driving Security Awareness, Internal Risks Are Growing | Fortinet Blog Canada Signs the UN Cybercrime Convention: Turning Global Agreement into Coordinated Action | Fortinet Blog Expert Density as Strategy: How 2F-IT Built One of Germany’s Deepest Fortinet Practices | Fortinet Blog From Awareness to Action: Helping Organizations Prepare for Post-Quantum Cryptography | Fortinet Blog A Conversation with Crime Stoppers International About Our Shared Cybercrime Bounty Initiative | Fortinet Blog Inside a TrickBot Variant Using DNS Tunneling for C2 | FortiGuard Labs Meeting the European Central Bank’s AI Cybersecurity Mandate | Fortinet Blog The TTF Trap: A Global Campaign of a Low-Detection Lua Loader | FortiGuard Labs Helping Law Enforcement Keep Pace with the Future of Cybercrime | Fortinet Blog FortiEndpoint Expands Security for the AI Era | Fortinet Blog Cyber Attacks Leveraging AI Require Behavior-First Security Training, Not Simply Better Awareness | Fortinet Blog
AI Security Is an Architectural Decision | Fortinet Blog
Russ Schafer · 2026-04-15 · via Fortinet All Blogs

As AI adoption accelerates, organizations face a critical architectural decision: extend existing security controls—identity, policy enforcement, observability, and data governance—to cover AI systems, or secure AI as a separate layer. The choice will determine whether AI introduces resilience or instability.

What began as experimentation with public generative AI (GenAI) tools has evolved into something foundational. Many enterprises have begun building private large language model (LLM) environments, integrating AI into core applications, and deploying agentic systems that retrieve data, interact with APIs, and initiate workflows across business systems. As a result, AI is no longer peripheral. Instead, it is becoming part of the infrastructure.

That shift requires a different security mindset.

The most common mistake is treating AI as a standalone application stack with separate controls. In reality, AI workloads depend on and influence identity systems, network policies, data governance, API enforcement, and operational workflows. Securing AI effectively requires embedding governance, traffic inspection, and policy enforcement at every control point across the architecture.

AI Expands the Attack Surface in Layers

AI risk is not confined to a single control point. It emerges across layers.

  • At the interface layer, public GenAI tools and user prompts create exposure through shadow AI use and poorly governed workflows.
  • At the knowledge layer, private LLM infrastructure—training data, vector databases, retrieval pipelines, and model logic—falls under enterprise responsibility. Once AI operates within enterprise systems, the organization assumes full responsibility for its integrity and protection.
  • At the action layer, agentic AI introduces autonomy. Agents retrieve data, transfer information across systems, call APIs, and trigger automated processes, often at machine speed.

These layers are not independent. Risk compounds as autonomy increases. The central challenge is not visibility in isolation but coordinated enforcement across the full stack.

The Sequencing Problem

How organizations adopt AI is just as important as what they deploy.

While some begin with controlled use of GenAI, establish governance for private LLM infrastructure, and introduce agentic autonomy only after developing policy and segmentation frameworks, others move directly from experimentation to automation, deploying agents before architectural guardrails are fully in place.

Industry forecasts indicate that many of these agent-first initiatives will be redesigned or abandoned—not because the underlying technology fails, but because governance was not integrated early. When autonomy outpaces architecture, organizations eventually face regulatory, security, or cost constraints that force redesign.

This is not a technical limitation. It’s a sequencing issue. Governance needs to scale before autonomy.

Runtime Is Where AI Risk Materializes

Development-time controls and pre-deployment testing are insufficient to prevent attacks on production AI. Once AI models are in production, new threats emerge, such as prompt injection, model manipulation, API abuse, and cross-system data exfiltration during inference.

Private LLMs face additional runtime risks, such as training data poisoning and model extraction. Agentic systems increase the potential impact by authenticating users, invoking enterprise APIs, and interacting directly with business systems. That’s why AI security requires continuous controls over users, agents, the network, and applications during operations. 

In practice, this means AI needs to be protected across the network, with policy enforced simultaneously at the firewall, API gateway, and SIEM with zero-trust network access (ZTNA).

Convergence as the Enabler

The broader implication is architectural.

Organizations with fragmented networking and security stacks will struggle to manage AI securely. When policy enforcement, telemetry, identity controls, and API inspection are spread across disconnected systems, AI creates security gaps and new vulnerabilities.

Secure networking convergence offers an alternative approach. A unified operating system foundation, a shared policy framework, and a coordinated telemetry model enable consistent enforcement across edge, cloud, and data center environments. AI workloads should follow the same discipline as any other critical system.

As the Fortinet platform has evolved, AI visibility, runtime guardrails, and agentic controls have been integrated into the converged foundation rather than developed as separate systems. The principle is simple: innovation should enhance the architecture, not divide it.

Governing Agentic Systems

Agentic AI represents the most consequential shift. These systems do more than generate insights. They take action by retrieving information, analyzing data, and interacting with APIs. Their decisions can also spread instantly across the entire managed environment.

That level of authority requires visibility into how agents communicate, the context of their identity, and how their actions align with enterprise policies. At a minimum, automation must remain accountable to governance frameworks, meaning agent systems should operate within established boundaries and not exceed them, and their actions must be logged, explainable, and auditable.

Preparing for What Comes Next

AI adoption will continue to expand. As more companies move their AI experiments into full production, AI infrastructure will grow in response to regulatory pressure and data residency concerns. Consequently, agentic systems will become more mature.

The organizations that succeed will not be those that rush to deploy isolated solutions, but those that choose a robust architectural framework with AI security embedded within it. As AI becomes part of your production environment, it must be governed as part of your architecture rather than as a separate component.

These themes will be central to the 2026 Fortinet AI Security Summit on April 21, where industry analysts, customers, and practitioners will examine how to secure AI across public GenAI use, private LLM deployments, and agentic operations. The focus will be on architectural discipline: maintaining visibility, enforcing policy, and scaling automation without creating new operational fault lines. 

Register now for the 2026 Fortinet AI Security Summit and join the discussion on how to secure AI at scale within the systems that already protect your enterprise.