SECSEC-001 — Model Security Vulnerabilities
AI Systems Exposed to Harmful Content via Malicious External Tool Integration
3/5Sector: OtherGeography: GlobalStage: OperateIngested: —
Executive Summary
General-purpose AI systems face escalating attack surfaces as plugin and tool integrations allow malicious external inputs to introduce harmful content at scale. Boards must mandate supplier assurance and integration controls or accept liability for downstream harms enabled by third-party tool ecosystems.
Domain
Security & Privacy
Blindspots in model security, data poisoning, privacy leakage, infrastructure, model theft, and incident response.
Source
MIT AI Risk Repository — Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) ↗https://airisk.mit.edu/
Could this happen in your organisation?
A Velinor AI Audit maps your active AI portfolio against the 50+ blindspots and benchmarks against documented sector failures like this one. A board-ready foresight document in 5 weeks.