AI Security Specialist

Immagine creata con IAAI-generated image

AI Security Specialist: attacks that resemble no other, and those who must stop them

Prompt injection, data poisoning, model evasion: Artificial Intelligence systems have an attack surface of their own, so specific that it has earned dedicated taxonomies from NIST, the OWASP project and MITRE. Guarding it is the craft of the AI Security Specialist, in a European market where security specialists are already in short supply, even before AI makes them indispensable.

At the top of the risk ranking for generative-AI applications there is not a traditional programming flaw, but an attack that three years ago did not even have a settled name: “A Prompt Injection Vulnerability occurs when user prompts alter the LLM’s behavior or output in unintended ways”, so the Open Worldwide Application Security Project (OWASP) dedicated to generative AI (OWASP). It is the sign of something new: AI systems err, and are attacked, in ways that resemble no other. Hence the profile of the AI Security Specialist, responsible for protecting AI systems from threats, vulnerabilities and attacks across the entire life cycle.

Dedicated taxonomies: NIST and MITRE

That the security of AI does not coincide with traditional cybersecurity is attested by the most authoritative sources. The National Institute of Standards and Technology (NIST), in the report of its Trustworthy AI series devoted to adversarial machine learning, declares: “This NIST Trustworthy and Responsible AI report provides a taxonomy of concepts and defines terminology in the field of adversarial machine learning (AML)” (NIST): poisoning of the training data, evasion at inference time, attacks on the confidentiality of data and models, abuse of generative capabilities. And the MITRE ATLAS knowledge base presents itself as “a public knowledge base of adversary TTPs targeting AI systems”, cataloguing tactics and techniques observed against real systems.

The practice of defence

In practice, four safeguards define the mature profile. The modelling of specific threats: mapping the system, from the data to the interfaces, onto the dedicated taxonomies, identifying the scenarios relevant to the concrete case. Controlled offensive testing: simulated-attack tests and red-teaming campaigns on generative applications, treating the model as an untrusted component until proven otherwise; for models with systemic risk, indeed, adversarial testing is an express obligation of Regulation (EU) 2024/1689 (the AI Act). Defence in depth: filters on inputs and outputs, privilege separation for software agents, human approval for high-impact actions, and telemetry and abuse detection, because the security of the model is not enough if the system around it is defenceless. Finally, alignment with governance: contributing to the risk management and documentation required by the regulatory framework, including, for the entities covered by it, the obligations of the European rules on the cybersecurity of networks and information systems.

A market in structural deficit

As for demand, the European context starts from a documented deficit: “In 2023, 57.5% of EU enterprises that recruited or tried to recruit ICT specialists had difficulties in filling ICT vacancies”, with peaks of 72.41 per cent in Germany (Eurostat). Onto this general deficit grafts the transformation brought by AI: the European Centre for the Development of Vocational Training (CEDEFOP) describes it as “the next general-purpose technology reshaping labour markets, jobs and skills” (CEDEFOP), and security competences are among those the transformation makes most critical, because every new AI application is, at the same time, a new attack surface. Those who can unite the craft of security with the specificities of machine learning stand, today, at the intersection of two scarcities.

The Italian benchmark

The UNI 11621-8:2026 standard recognises the AI Security Specialist as a standalone profile among the twelve of AI, with competences set out according to the methodology of the European e-Competence Framework, the UNI EN 16234-1 standard; the assessment and certification of professional competences take place at bodies accredited under the UNI CEI EN ISO/IEC 17024 standard, within the framework of Accredia Information Circular DC No. 21/2026.

Conclusions

The AI Security Specialist defends systems that err in new ways from adversaries that attack in new ways: this is why the discipline has given itself dedicated taxonomies and knowledge bases, and why the profile deserves the standalone recognition the Italian standard has assigned it.

In the light of the above, one wonders whether organisations will extend to AI systems the security maturity so laboriously built on traditional software, before the adversaries – as happens ever more often – see to demonstrating its necessity.


AI AnthropoCosmic In evidenzaAI AnthropoCosmicCall for Paper aperta fino al 15 settembre 2026. Un progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicCall for Paper open until 15 September 2026. An international project for an AI at the service of humanity, the environment and the cosmos. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article