You need both.

Here’s an oversimplified 4-step playbook to use them together (Friday edition):

  1. Build the Foundation (Google SAIF). Establish AI Governance Controls and an Acceptable Use Policy, enforced by an AI platform across the entire lifecycle from training to deployment. Now you have a model and agent inventory, a secure vault for artifacts, and enforcement rails.
  2. Prioritize Protecting From The Top 3 Techniques (Cisco):

The OWASP folks will reasonably ask "what about identity?" So, add Unauthorized Access (AITech-14.1) to your list.

  1. Deploy Technical Controls (Google SAIF). Map defenses directly to the prioritized vectors.
  1. Red Team & Validate (Cisco). Controls are theoretical until tested. Get a third party’s help from an AI-native player to stress-test your AI system. The findings will help prioritize next steps.

Your cyber insurance provider will also ask you questions soon regarding how AI is governed and how AI decisions are made.

Great news: there’s a growing ecosystem of AI-native cybersecurity companies that aim to address emerging risks. See my earlier post on AI for application security.

Cisco AI Security and Safety Framework

A great post from Anton Chuvakin Google SAIF in Cloud