cybercarriere.nl

LLMs as a New Attack Surface: what does it mean for AI governance?

Nieuws
26-03-2026
Yuri Bobbert
Large Language Models (LLMs) are transforming industries, but their unique risks demand a new approach to security and governance. A groundbreaking paper co-authored by Anove Co-Founder Prof. dr. Yuri Bobbert and ethical hacker Kevin Zwaan from Q-Cyber exposes how traditional security controls fall short when AI behavior can be steered through plain everyday language.

A recent demonstration showed how an LLM could be "radicalized" over eight hours, bypassing safety guardrails to generate malware at scale. This wasn't a highly technical code-written software exploit; it was achieved through manipulation and persuasion, taking advantage of the model’s contextual learning to make it unlearn its security protocols, revealing a critical gap in AI security.

The paper highlights that AI's attack surface is broader than code. It includes the model, prompts, user interfaces, policies, and even the organizational context. When LLMs are integrated into workflows with access to tools, APIs, and sensitive data, the risks multiply, ranging from generating malicious content to enabling large-scale cyberattacks. AI systems are dynamic, made up of interconnected components that evolve rapidly. As a result, traditional governance can’t keep up. Static checklists and one-time audits aren’t enough (if they ever were). AI management must be continuous, automated, and evidence-based.

[....]

Lees verder op: anove.ai

Gerelateerde vacatures

Geïnteresseerd in een carrière bij organisaties in ditzelfde vakgebied? Bekijk hieronder de gerelateerde vacatures en vind de perfecte match voor jou!
BeFrank
550
Student
Amsterdam
Als Stagiair(e) Information Security Specialist bij BeFrank werk je in het Security Team aan monitoring van security events/incidenten, risk assessments, compliancechecks, procesverbetering & documentatie, awarenessupdates en een eigen security-opdracht.
Blue Sky Group
5.500 - 8.000
Senior, Medior
Amstelveen
Als IT Compliance Officer bij BSG identificeer, beoordeel en beheer je risico's om naleving van interne en externe regelgeving te waarborgen. Je ontwikkelt en implementeert risicobeheerstrategieën, onderhoudt het IT Control...
Ministerie van Defensie
5.863 - 7.575
Senior
Utrecht
Als Word Senior Cyber Adviseur - Cloud bij Defensie (COMMIT/JIVC) adviseer je CISO en stakeholders over cloudbeveiliging, risico’s en complexe cybervraagstukken, ontwikkel en implementeer integraal beleid, monitort incidenten/trends en rapporteert...
Top vacature
Groen Van Solinge
In overleg
Senior
Harderwijk
Als Manager Digitalisering bpfBouw speel je een cruciale rol in de digitale transformatie van een top 5 pensioenfonds met 750.000 deelnemers. Je coördineert digitalisering, IT, en informatiebeveiliging, rapporteert aan het...