How to Secure AI Workflows Against Fraud, Data Exposure, and Misuse

Summary
The article argues that AI security must address business fraud, sensitive data exposure, and the varied authority of AI systems. It recommends starting with a high-risk workflow and clarifying what AI can access, disclose, and change.
Key points
- A 2024 Hong Kong fraud used a pre-recorded deepfake video conference and follow-up messages to trick an employee into authorizing transfers totaling about HK$200 million.
- Valid credentials and functioning systems do not ensure transactions are legitimate; AI agents need business-context limits, such as payment thresholds and approval requirements.
- Assess AI workflows by what they can read, reveal, and change, and track sensitive information as it moves into summaries, responses, logs, or drafts.
- Content an agent reads can influence its actions, so business documents and other inputs must not be allowed to override the agent’s intended boundaries.
- Different AI applications can have very different data access, tools, authority, and impact—even when they use the same model provider.
- The article recommends beginning with one high-risk workflow, such as supplier payments, customer refunds, or contract reviews, and defining how errors would be detected and stopped.
Article Details
- Topic
- Business risks of AI systems, including fraud, data exposure, and governance of agent permissions and workflows.