More The Secure Disclosure episodes

Practical AI Security & Adversarial Machine Learning with Dr Harriot Farlow thumbnail

Practical AI Security & Adversarial Machine Learning with Dr Harriot Farlow

Published 17 Sept 2026

Duration: 00:32:16

"Examines unique AI security risks, industry misconceptions, governance gaps, ethical concerns, and the urgent need for tailored solutions and global cooperation."

Episode Description

Most security teams treat AI flaws like standard code vulnerabilities, but machine learning can't simply be patched. On this episode of The Secure Dis...

Overview

The podcast discusses key challenges and misconceptions in AI security, emphasizing that traditional cybersecurity approaches are insufficient for addressing AI-specific risks. AI systems, particularly machine learning models, are inherently difficult to secure due to their probabilistic nature and optimization processes, making many vulnerabilities unpatchable in the conventional sense. A major issue is the widespread conflation of AI with large language models (LLMs), which limits understanding of broader AI risks. Experts highlight the need for new terminology - such as moving beyond "prompt injection" - to accurately describe fundamental flaws in AI systems rather than treating them like classical software vulnerabilities.

Organizations often prioritize rapid AI adoption over governance, leading to significant security gaps. Many lack awareness of AI-specific threats like rogue agents, model theft, and unpredictable system behaviors, while also struggling to implement effective policies due to siloed decision-making and skill shortages. The discussion underscores the importance of education, clear terminology, and tailored security frameworks to address both immediate operational risks and long-term systemic challenges. Despite concerns, there is optimism about AI's potential, especially for startups and education, though ethical considerations, job market disruptions, and the need for international cooperation in AI governance remain critical issues.

What If

  • What if you treated your AI-powered product like a frontier AI lab?

    • Move: Implement model access controls, audit trails for prompts/responses, and isolate model inference behind an internal gateway - just like a high-security AI lab would.
    • Why Now?: As a solo developer, your AI system is already vulnerable to data leakage, prompt extraction, or misuse; waiting until you scale means retrofitting security when it's costlier and riskier.
    • Expected Upside: Prevent unauthorized access or model theft early, build investor- and user-trust faster, and position your product as secure-by-design in a market where most AI apps are wide open.
  • What if you stopped calling AI flaws "bugs" and started treating them as inherent system weaknesses?

    • Move: Replace traditional bug bounty thinking with adversarial testing: run red-team exercises focused on data drift, prompt manipulation, and unintended optimization - not just code injection.
    • Why Now?: The industry still mislabels AI failures as patchable software bugs, but they're often unfixable by code updates; recognizing this now lets you design around failure modes instead of pretending they can be patched.
    • Expected Upside: Build more resilient AI features by design, reduce post-deployment surprises, and differentiate your product by documenting and mitigating known AI-specific failure paths.
  • What if you launched a micro-SaaS that teaches practical AI security using AI-generated course content?

    • Move: Use your own AI tools to generate, simulate, and deliver short, actionable training modules (e.g., "Prompt Injection Lab") hosted on a secure platform with built-in tracking and access control.
    • Why Now?: Demand for AI security knowledge is rising, but most training is theoretical or enterprise-focused; as a solo dev, you can move faster than big players and use AI to scale content creation ethically and affordably.
    • Expected Upside: Capture early-mover advantage in a niche market, generate recurring revenue with low overhead, and establish authority in AI security by demonstrating secure AI use in practice.

Takeaway

  • Audit your AI systems for shadow AI usage by documenting all tools and models currently in use across your projects.
  • Treat AI vulnerabilities as inherent design limitations rather than patchable bugs, and design system boundaries accordingly.
  • Adopt precise, AI-specific terminology (e.g., avoid "prompt injection" as equivalent to SQL injection) to improve threat modeling accuracy.
  • Implement minimal viable AI governance policies, such as acceptable use guidelines, before scaling AI in your products.
  • Prioritize education on adversarial machine learning fundamentals to identify and mitigate system-level AI risks proactively.

Recent Episodes of The Secure Disclosure

3 Sept 2026 Email Security in the Age of AI | Josh Kamdjou, Sublime Security CEO

"Email security faces growing threats from AI-driven phishing, prompt injection, and malicious calendar invites, outpacing traditional defenses; Sublime Security's real-time, agentic approach offers a solution, while cyber warfare increasingly exploits human cognitive vulnerabilities."

19 Aug 2026 Tearing Down Vendor Fluff: The Real State of AI Security | James Berthoty

"AI's rapid adoption in cybersecurity, driven by executive pressure and fear of obsolescence, contrasts with slower cloud security uptake, as vendors overpromise solutions while breaches persist; AI both enables attacks (like supply chain malware) and enhances defenses, reshaping security roles and workflows, with governance and real-world gaps (e.g., Hugging Face breach) remaining critical."

14 Jul 2026 How to Stop Supply Chain Attacks Without Destroying Developer Productivity

"Cybersecurity threats, especially supply chain attacks on developers and open-source packages, demand balanced mitigation strategies, AI-driven security challenges, and early integration of security in development, with collaboration and adaptability key to addressing evolving risks."

More The Secure Disclosure episodes