Imperva Cyber Community

 View Only

Why AI Needs a New Kind of Security

By Tal OVADIA posted 15 days ago

  

By Michael Wright and Tal Ovadia | Imperva 

There is a moment every CISO is having right now, often without warning. A developer shows a working internal demo of an AI assistant trained on the company's own documents. The product team is already planning a customer-facing version. The board has signed off on the budget. And somewhere in the middle of the meeting, a quiet question lands: what is securing this? 

The honest answer, for most organizations today, is "nothing your existing stack was designed to do." 

This is not a critique of the security tools enterprises have spent years deploying. WAFs, EDRs, network firewalls, API gateways, identity platforms; these have evolved into a layered defense that genuinely works against the threats they were built for. But GenAI applications introduce a new attack surface that operates outside the boundary every one of those tools defends. 

The problem is not that AI threats are more dangerous than traditional threats. The problem is that they are categorically different. 

Why the old playbook doesn't cover this 

Traditional security tools all share a common assumption: attacks come in the form of malformed inputs, malicious payloads, suspicious traffic patterns, or unauthorized access attempts. A WAF inspects HTTP headers, query strings, and request bodies for known patterns. An EDR watches for binaries behaving badly. An API gateway enforces schema and authentication. 

An LLM-based application turns all of those assumptions on their head. 

The payload in a prompt injection attack is grammatically correct English. The malicious code in a data leakage attack is a polite question. The denial of service pattern in an unbounded consumption attack is a perfectly legitimate looking conversation. The threats that matter to a GenAI application live at the level of the model's logic, not at the level of the network or the HTTP request. 

Even more critically, the security tools that protect the application surrounding the model have no visibility into what happens at the interface. The WAF sees the request to your AI endpoint. It does not see what the model does with that request. The API gateway authenticates the user. It does not understand whether the user is trying to convince the model to reveal its system prompt. 

This is the gap that has emerged across enterprise security architectures over the last 18 months. It is not a minor blind spot. It is a category-level gap. Traditional security tools do not speak AI. 

What AI-native security actually means 

When we talk about AI-native security at Imperva, we are not talking about adding AI features to a traditional security product. We are talking about a purpose-built control plane that understands prompts, model responses, conversation context, and usage patterns the way our WAF understands HTTP. 

That distinction matters because AI security has to inspect the interaction itself. It has to understand what the user is asking for, how the model is likely to respond, whether sensitive data is being exposed, whether instructions are being manipulated, and whether usage patterns suggest abuse. This is inspection at the AI interaction layer rather than the network layer. 

Thales’s Imperva AI Application Security is engineered specifically for the architecture of AI and agentic applications. It sits between your applications and the models they call, giving teams flexible deployment options rather than forcing a single architecture. Every input and every output is analyzed in real time, against multiple security guardrails, with adaptive risk scoring that distinguishes legitimate use from manipulation attempts. 

Concretely, it addresses five of the OWASP Top 10 LLM threats: 

  • Prompt injection and jailbreaking attempts 

  • Sensitive information disclosure through model outputs 

  • System prompt leakage 

  • Improper output handling 

  • Unbounded consumption attacks that drive cost runaway and denial of service 

And critically, it does not replace your existing WAAP. It extends it. AI Application Security plugs into the same unified Imperva platform that handles your WAF, API security, bot management, and DDoS protection. The same console, the same policy model, the same role-based access controls. The AI threat surface becomes one more dimension of the security posture your team already manages, rather than a new tool, a new vendor, and a new operational silo. 

What this means for the next 12 months 

According to McKinsey, 78% of organizations are using AI in at least one business function, up from 55% two years ago; and according to the 2025 Thales Data Threat Report, 73% of organizations are investing in AI-specific security tools with either new or existing budgets. As organizations move from simple chat experiences toward autonomous agents capable of taking actions, the need for AI-specific security controls becomes even more critical. The teams that get this right will not be the ones who deploy more security tools. They will be the ones who recognize that AI applications are a new class of asset and treat them with a control layer designed for what they actually are. 

A WAF was the answer when applications moved from desktop to web. An API gateway was the answer when monoliths gave way to microservices. An AI Application Security layer is the answer for applications that no longer execute only predictable code, but interpret, generate, and increasingly act on language. 

That is the new kind of security your AI deserves. 

Ready to see what AI-native security looks like in practice? Talk to your Thales representative, comment below or visit imperva.com to explore AI Application Security. 


#AllImperva
0 comments
3 views

Permalink