Artificial Intelligence (AI) security strategy

Artificial Intelligence (AI) security strategy: 1,265% AI-enhanced phishing growth, prompt injection as highest-severity agentic vulnerability, and the New Zealand (NZ) regulatory guidance gap

2026-03-05 · security-risk governance-policy · medium · source → · wiki →
key claims
  1. AI-enhanced phishing grew 1,265% in volume following widespread generative AI availability, with 82% of phishing emails assessed as AI-generated content in 2025, and average phishing-related breach costs now standing at $4.8–4.88 million per incident
  2. Business Email Compromise scams, substantially enabled by AI-generated content and voice deepfakes, generated $2.7 billion in US-reported losses in 2024, representing a quantifiable economic harm directly attributable to AI-enhanced social engineering
  3. The NIST AI 100-2e2023 taxonomy defines four canonical attack categories against AI systems — evasion, poisoning, privacy, and abuse — providing the foundational vocabulary for AI security governance; MITRE ATLAS operationalises this into 66+ techniques across 15 tactics, with 30% of ATLAS mitigations requiring AI-specific controls not found in traditional cybersecurity frameworks
  4. Prompt injection, ranked #1 in the OWASP LLM Top 10, is the highest-severity AI-specific vulnerability for deployed LLM systems; OpenAI has stated indirect prompt injection in AI browser agents may never be fully patched, and real-world CVEs with CVSS scores above 9.0 have been exploited in GitHub Copilot and Microsoft Copilot via this attack vector
  5. AI applied to security operations delivers measurable ROI: HSBC's AML system reduced false positive alerts by 60% and doubled confirmed financial crime detection; JPMorgan achieved 95% false-positive reduction with fraud detected 300× faster; Microsoft Security Copilot trials demonstrated 30% reduction in SOC mean time to resolution
  6. NZ NCSC published "Engaging with Artificial Intelligence" in January 2024 in partnership with 14 international agencies including CISA, NSA, and ASD, providing AI security guidance for organisations using (not building) AI systems; a follow-on joint advisory "Deploying AI Systems Securely" (April 2024) co-endorsed by NZ adds controls for model weight protection, supply chain evaluation, and AI-specific monitoring
  7. NZ NCSC mandated 10 Minimum Cyber Security Standards for public agencies effective October 2025 — including MFA, anomaly detection, and least privilege — that apply to AI systems as ICT assets, but no NZ-specific AI security standards have been issued separately
  8. FMA's 2024 AI research report and RBNZ's 2025 Financial Stability Report both flag AI security risks for NZ financial institutions — FMA expects governance, cybersecurity controls, and disclosure; RBNZ highlights third-party concentration risk and correlated model failure — but neither has issued prescriptive rules; NZ financial institutions operate under principle-based expectation, not rule-based obligation, for AI security

Research Question

Which organisations have developed coherent AI strategies with security as the primary objective — either using AI to enhance security posture or governing the security risks that AI systems themselves introduce — and what frameworks, architectures, and governance structures characterise effective approaches?

Findings

Executive Summary

AI security strategy in 2025–2026 requires parallel governance architecture for two distinct problems: AI as an attack-amplification tool in adversaries' hands, and AI systems as a novel attack surface within organisations. AI-enhanced phishing has grown 1,265% in volume since generative AI became broadly available, with $2.7 billion in BEC losses in the US in 2024 alone, while the per-attack cost to adversaries has collapsed. Internally, prompt injection — particularly indirect injection targeting AI agents with tool-use capabilities — is the highest-severity AI-specific vulnerability, with no complete architectural fix known. NZ organisations have actionable guidance from NCSC joint advisories (January 2024) and the CISA/Five Eyes "Deploying AI Systems Securely" standard (April 2024), but no mandatory AI-specific security regulation exists in NZ as of March 2026; FMA and RBNZ have expressed expectations without prescribing controls.

Key Findings

  1. AI-enhanced phishing grew 1,265% in volume following widespread generative AI availability, with 82% of phishing emails assessed as AI-generated content in 2025, and average phishing-related breach costs now standing at $4.8–4.88 million per incident. [confidence: high; multiple industry reports converge]

  2. Business Email Compromise scams, substantially enabled by AI-generated content and voice deepfakes, generated $2.7 billion in US-reported losses in 2024, representing a quantifiable economic harm directly attributable to AI-enhanced social engineering. [confidence: high; FBI IC3 data cited in multiple sources]

  3. The NIST AI 100-2e2023 taxonomy defines four canonical attack categories against AI systems — evasion, poisoning, privacy, and abuse — providing the foundational vocabulary for AI security governance; MITRE ATLAS operationalises this into 66+ techniques across 15 tactics, with 30% of ATLAS mitigations requiring AI-specific controls not found in traditional cybersecurity frameworks. [confidence: high; primary source NIST and MITRE]

  4. Prompt injection, ranked #1 in the OWASP LLM Top 10, is the highest-severity AI-specific vulnerability for deployed LLM systems; OpenAI has stated indirect prompt injection in AI browser agents may never be fully patched, and real-world CVEs with CVSS scores above 9.0 have been exploited in GitHub Copilot and Microsoft Copilot via this attack vector. [confidence: high; multiple primary and secondary sources]

  5. AI applied to security operations delivers measurable ROI: HSBC's AML system reduced false positive alerts by 60% and doubled confirmed financial crime detection; JPMorgan achieved 95% false-positive reduction with fraud detected 300× faster; Microsoft Security Copilot trials demonstrated 30% reduction in SOC mean time to resolution. [confidence: high; disclosed case studies; corroborated in prior research item]

  6. NZ NCSC published "Engaging with Artificial Intelligence" in January 2024 in partnership with 14 international agencies including CISA, NSA, and ASD, providing AI security guidance for organisations using (not building) AI systems; a follow-on joint advisory "Deploying AI Systems Securely" (April 2024) co-endorsed by NZ adds controls for model weight protection, supply chain evaluation, and AI-specific monitoring. [confidence: high; primary source NCSC NZ website confirmed]

  7. NZ NCSC mandated 10 Minimum Cyber Security Standards for public agencies effective October 2025 — including MFA, anomaly detection, and least privilege — that apply to AI systems as ICT assets, but no NZ-specific AI security standards have been issued separately. [confidence: high; Industrial Cyber reporting confirmed against NCSC]

  8. FMA's 2024 AI research report and RBNZ's 2025 Financial Stability Report both flag AI security risks for NZ financial institutions — FMA expects governance, cybersecurity controls, and disclosure; RBNZ highlights third-party concentration risk and correlated model failure — but neither has issued prescriptive rules; NZ financial institutions operate under principle-based expectation, not rule-based obligation, for AI security. [confidence: high; primary sources FMA and RBNZ publications]

  9. Singapore's 2024 Model AI Governance Framework for Generative AI is the most operationally detailed reference governance standard for AI security, requiring: adversarial prompt red-teaming, supply chain security for model weights, structured incident reporting, and continuous monitoring — exceeding the depth of NCSC's advisory-level guidance. [confidence: medium; based on framework documentation and analysis, Singapore's own enforcement model is voluntary]

  10. Agentic AI systems (AI with tool-use, memory, and API access) present a qualitatively larger attack surface than passive LLMs because a successful prompt injection translates into capability to send emails, access databases, and execute code; MITRE ATLAS added new agentic AI attack techniques in 2025, tracking ahead of most organisations' current governance frameworks. [confidence: medium; based on research reports and CVE evidence, not yet widely documented in primary regulatory guidance]

Assumptions

Analysis

The evidence supports a clear structural finding: AI security strategy is not a single discipline but two separate governance domains with different control architectures. Conflating them — or treating AI-enhanced threat defence as sufficient without also governing AI systems as attack surfaces — leaves organisations exposed on the second vector.

The threat-landscape evidence is robust. The phishing statistics are consistent across five independent sources despite methodological variation. The financial loss data ($2.7B BEC) is FBI-sourced primary data. The Microsoft Digital Defense Report is the largest single dataset on adversary AI use, and its 200+ adversarial AI-content-generation instances per month from nation-state actors is consistent with the broader pattern.

For AI as security tool, the disclosed case evidence is strong: HSBC and JPMorgan are named cases with specific metrics, corroborated in prior research. Microsoft Security Copilot's 30% MTTR reduction is internally published research, not a press release. KPMG's survey of 85% SOC-leader confidence is large-n survey data. The pattern is convergent.

For AI system security, the weakest evidence is on governance adoption rates — there is no survey data on what percentage of organisations have deployed MITRE ATLAS-aligned controls or adversarial testing regimes. The evidence is strong on the attack taxonomy and on specific incidents (CVEs, RAG poisoning), weaker on what proportion of organisations have operationalised defences.

Singapore's framework is chosen as the benchmark governance reference over NIST Cyber AI Profile because the NIST profile is in preliminary draft (December 2025) and Singapore's framework is the only one with specific security controls in final-form documentation.

Risks, Gaps, and Uncertainties

Open Questions


sources


Connected items

Loading…

View full knowledge graph →