Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI can think. AI can act. Secure the entire AI workflow.

Securing AI systems today means securing the whole AI process, from access, to prompt, to action. Explore A10's AI security offering, which ties the capabilities of AI Firewall, MCP discovery/protection, AI gateway, and ThreatX, all together into one cohesive end-to-end AI security solution.

A Prompt Is Not a Boundary: Lessons From the AI Eval Incidents

Three organizations had their production systems compromised by an AI model in April, and found out in late July when the model's developer called them. None of them had detected the activity. One was a security company whose own package scanner was the entry point. ‍ Anthropic published that account on July 30, nine days after OpenAI disclosed a related incident of its own.

Does Cyber Insurance Cover AI Incidents?

The answer changed on a specific date. Until the start of 2026, most organizations were covered for AI losses by silence rather than by grant, because policies neither affirmed nor excluded AI and the question would have been argued at claim time. On January 1, 2026 the standard forms organization introduced generative AI exclusion endorsements for commercial general liability, and carriers began attaching them at renewal. ‍

Best AI security tools for small and mid-sized businesses in 2026

The best AI security tools for small and mid-sized businesses do more than detect risky AI use: they show which generative AI tools employees actually use, they let you govern which AI apps are allowed, monitored or blocked, they stop sensitive data from leaving in a prompt, and they defend against harmful prompts, including prompt injection. Most organizations now run AI without that visibility or control. AI use has moved into the mainstream.

Why Securing AI Agents Is More Critical Than Ever

AI agents offer unprecedented capabilities, speed, automation, deep context, and hyper-personalization, that will transform how we work. However, these same capabilities make AI agents significantly more dangerous than traditional software when hijacked by cybercriminals. You simply cannot rely on yesterday's risk management playbooks to handle today's AI-driven threats.

AI Can't Do CTEM Alone (And Neither Can You)

AI can meaningfully power Continuous Threat Exposure Management (CTEM), but only for specific stages of the cycle: prioritization, validation, and remediation routing. AI can’t replace the underlying data integration work, and it can’t turn CTEM into a single product, because Gartner defines CTEM as a continuous five-stage program (scoping, discovery, prioritization, validation, mobilization), not a tool you install.

AI Security Posture Management: What It Covers and What It Misses

AI Security Posture Management arrived as a term before it arrived as a definition. Vendors announced products under the label through 2025 and in volume at RSA Conference 2026, each describing a somewhat different scope, and buyers now evaluate a category whose boundaries depend on who is selling. The lineage is evident, since AI-SPM follows cloud and data security posture management, and the inherited assumptions are where the difficulty starts.

Ep. 73 - EU AI Act-What Actually Lands on August 2nd, and What Slipped to 2027

The EU AI Act's August 2nd, 2026 deadline just changed shape. Host Tova Dvorin and offensive security engineer Adrian Cully separate what actually lands—Article 50 transparency duties and GPAI enforcement powers—from the high-risk obligations that slipped to December 2027. Inside: Article 15 writes MITRE ATLAS and the OWASP LLM Top 10 into binding law, the DORA / NIS2 / AI Act overlap that makes one incident reportable three times, penalties up to 7% of global turnover, and the five things a CISO should do this week. Part 1 of 2.

Is your AI system secure enough? MITRE ATLAS Is Now Law.

For the first time anywhere, the MITRE ATLAS framework and the OWASP Top 10 for LLM applications are written into binding law. Article 15 names data poisoning, model poisoning, adversarial examples, model evasion and confidentiality attacks as threat classes you must have technical measures against—and must be able to evidence to a regulator. The question is no longer whether you have thought about AI security. It is whether you can prove your AI system holds.

Coding Agent Risk for CISOs: Blast Radius, Governance, and Where to Start

Claude Code, Cursor, GitHub Copilot, and Gemini CLI are running on developer machines across your enterprise right now. They're browsing the web, writing to your filesystem, committing code to your repositories, and calling external APIs under the identity of your engineers. Most security teams have no visibility into any of it. This isn't a future problem.