cybercarriere.nl

LLMs as a New Attack Surface: what does it mean for AI governance?

Nieuws
26-03-2026
Yuri Bobbert
Large Language Models (LLMs) are transforming industries, but their unique risks demand a new approach to security and governance. A groundbreaking paper co-authored by Anove Co-Founder Prof. dr. Yuri Bobbert and ethical hacker Kevin Zwaan from Q-Cyber exposes how traditional security controls fall short when AI behavior can be steered through plain everyday language.

A recent demonstration showed how an LLM could be "radicalized" over eight hours, bypassing safety guardrails to generate malware at scale. This wasn't a highly technical code-written software exploit; it was achieved through manipulation and persuasion, taking advantage of the model’s contextual learning to make it unlearn its security protocols, revealing a critical gap in AI security.

The paper highlights that AI's attack surface is broader than code. It includes the model, prompts, user interfaces, policies, and even the organizational context. When LLMs are integrated into workflows with access to tools, APIs, and sensitive data, the risks multiply, ranging from generating malicious content to enabling large-scale cyberattacks. AI systems are dynamic, made up of interconnected components that evolve rapidly. As a result, traditional governance can’t keep up. Static checklists and one-time audits aren’t enough (if they ever were). AI management must be continuous, automated, and evidence-based.

[....]

Gerelateerde vacatures

Geïnteresseerd in een carrière bij organisaties in ditzelfde vakgebied? Bekijk hieronder de gerelateerde vacatures en vind de perfecte match voor jou!
PMT pensioenfonds Metaal & Techniek
Marktconform
Medior, Senior
Den Haag
Als Specialist Ketenregie bij PMT pensioenfonds Metaal & Techniek beheer je portefeuilles in interne beheersing, IT, informatiebeveiliging en kwaliteitsmanagement, en ondersteun je portfolio- en projectmanagement met planning, rapportages en stakeholdercommunicatie.
Meer lezen
KPN
5.190 - 7.803
Medior
Hilversum
Als Incident Handler / Threat Hunter bij KPN leid en coördineer je complexe security-incidenten, voer je diepgaande analyses en digitale onderzoeken uit, jaag je proactief op dreigingen en verbeter je...
ABN AMRO
5.847 - 8.353
Senior
Amsterdam
As a Chapter Lead Non-Financial Risk at ABN AMRO leid je engineers en werk je hands-on aan Azure-platformen; je stuurt IT-vakmanschap en HR aan, bepaalt NFR IT-visie/landschap, en borgt kwaliteit,...
Assets Only
Marktconform
Medior
Nederland
Als (Senior) Consultant Information Security vertaal je wet- en regelgeving naar processen en controls voor audits. Je voert gapanalyses uit, implementeert IT-controlraamwerken en maakt organisaties audit-ready. Werk samen met diverse...