IT security intelligence. Since 2006.Cloudflare services ↗
AI, automation & data

AI security, red teaming & governance

Understand the new risks introduced by AI systems and define how they will be controlled. Examine models, data, integrations, and human decisions as one connected system.

Discuss your requirements
Reviewers examining AI evaluation results and a testing checklist

Test the whole AI system

Security evaluation extends beyond the model. We review data sources, retrieval permissions, prompts, tools, output handling, and the actions an agent can perform. Authorised red teaming explores how untrusted content or unexpected requests could cause data exposure or actions outside the intended scope.

Testing includes realistic failure scenarios and distinguishes model behaviour from weaknesses in the surrounding application. Findings are prioritised by impact and paired with controls such as restricted permissions, safer output handling, monitoring, and human approval.

Create a workable governance framework

An AI inventory helps identify systems, owners, intended uses, providers, and affected people. We support policies for acceptable use, supplier assessment, evaluation, documentation, incident handling, and change management. AI Act readiness can form part of this work where relevant to your role and use case.

Governance needs to match the application. A drafting assistant and a system used in a consequential decision require different controls. Legal classification and obligations should be confirmed with qualified advisers; technical testing alone does not demonstrate regulatory compliance.

Model the risks of your specific application

A public chatbot, an internal document assistant and an agent with write access have different exposure. We map users, trusted components, external content, sensitive data and possible actions before selecting tests. The assessment considers misuse of the application as well as ordinary errors with business consequences. It identifies where access control, source validation and deterministic application logic must carry responsibilities that should not be left to a model’s instructions alone.

Run controlled adversarial and boundary testing

The authorised test plan can cover instructions hidden in retrieved material, cross-user data access, unsafe tool use, sensitive output and attempts to bypass the intended workflow. We use defined test accounts and data, document the result and link each finding to a concrete impact. Remediation is verified through repeatable test cases. The report states the tested version and scope; it does not claim that passing a finite test set makes an AI system universally safe.

Make governance an operating process

We define accountable owners, acceptable uses, supplier review, evaluation evidence and escalation for incidents or material changes. Business, technical, privacy and legal teams need a shared view of the AI inventory and its dependencies. Documentation should be proportionate to the use case and maintained with the system. Technical readiness work can support a legal assessment, while applicable obligations and regulatory classifications are determined with qualified advisers.

Connect oversight to release decisions

Governance becomes useful when it changes a decision: which data can be used, which action requires approval, what evidence permits rollout and when a service should be paused. We help define release gates, monitoring signals and incident exercises around these questions. Executive reporting summarises material risks, unresolved findings, ownership and progress, giving leadership an actionable view without requiring it to interpret raw model test transcripts.

Assess the path from untrusted content to an action

An AI assistant may read a supplier document, a retrieved webpage or an incoming message before calling a business tool. We map where that content enters the application and which decisions it can influence. Controlled testing can examine whether the system preserves the separation between reference material, user instructions and authorised actions. Findings are tied to the application’s actual tools and information boundaries.

Review AI access across documents, tools and users

A secure-looking chat interface can still expose information through retrieval, exports or a broadly privileged integration. We examine the relationship between a user’s access and the information or actions available to the assistant. Tests should include different roles and changes in entitlement, with a documented decision about which controls belong in the application, the identity platform and the connected system.

Prepare an AI supplier and release review

Before adopting or expanding a system, the organisation needs a clear account of its purpose, data flows, evaluation results and operational owner. We can help organise questions about retention, subprocessors, model changes, testing access and incident handling. A release review records unresolved risks and the person responsible for accepting or resolving them. A technical review informs wider governance; it does not replace a legal applicability assessment.

What you receive

  • AI system inventory and threat assessment
  • Authorised red-team findings and remediation guidance
  • Evaluation, approval, and monitoring requirements
  • AI governance roadmap and supporting documentation
  • Application-specific AI attack-surface and permission review
  • Release decision record with unresolved risks and accountable owners

Common questions

What is prompt injection?

It is an attempt to make an AI application follow untrusted instructions, for example from a document or webpage. The impact depends on what data and actions the application can access.

Does an AI security test establish AI Act compliance?

No. It can support risk assessment and technical evidence, but compliance also depends on the organisation’s role, the use case, documentation, and other requirements.

Can you test an internal AI assistant before staff use it?

Yes. We agree the intended users, documents, connected tools and permitted test methods. A controlled environment and representative roles allow findings to be addressed before broad access is introduced.

Does filtering the prompt solve AI security?

A prompt filter is only one possible control. Assessment needs to consider the complete application, including access checks, retrieved content, tool permissions, output use and human approvals.

Further reading: OWASP GenAI Security Project · NIST AI Risk Management Framework

Further reading: Official guidance

What’s your next
technology challenge?

Talk to our team