What is secure-by-design-AI?
A working definition from MIT Sloan
secure-by-design AI (noun)
A development methodology for AI systems that treats security as a foundational design principle rather than an add-on feature.
As organizations embed artificial intelligence across their operations, many are discovering that traditional IT security approaches fall short. AI systems introduce entirely new potential hazards — including model theft, prompt injection, data poisoning, and hallucinations — that can’t simply be patched over after the fact.
To address these AI risks, MIT Sloan senior lecturer and principal research scientist Keri Pearlson and Nelson Novaes Neto, an MIT Sloan research affiliate and CTO of Brazil-based C6 Bank, developed a framework for secure-by-design AI. Their approach condenses hundreds of technical considerations into 10 strategic questions that can help executives identify risks and align AI initiatives with business priorities, ethical standards, and cybersecurity requirements — before systems are too far along to be secured effectively.
When C6 applied the framework, it surfaced 19 critical design considerations and led the digital bank to develop a four-part platform architecture that separates experimental AI efforts from production-grade systems that interface directly with customers. The exercise also helped C6’s legal and compliance teams draft an AI-specific manual outlining expectations and regulatory risks.
The framework doesn’t eliminate all AI risk, but it provides a practical foundation for better questions, clearer decisions, and more resilient designs. “The most powerful thing about these 10 questions is that they force you to think ahead,” Pearlson said.
See the 10 questions at 'This new framework helps companies build secure AI systems'
AI Working Definitions
An Instagram series on ideas about AI and data science.
Leading the AI-Driven Organization
In person at MIT Sloan
Register Now
Cybersecurity
AI cyberattacks and three pillars for defense
By
MIT researcher argues for a response that goes beyond fighting AI with AI.
This new framework helps companies build secure AI systems
By
New guidance includes 10 questions that can help organizations build secure-by-design artificial intelligence.
5 cybersecurity priorities that demand your attention
By
Security leaders must strengthen their defenses against everyday threats while preparing for potentially devastating attacks. Here’s how to get it done.
5 new cybersecurity regulations to know about
By
Company leaders need to be on top of best practices and legal requirements for data protection, including mandatory incident reporting and bans on ransomware payments.