cybercarriere.nl

LLMs as a New Attack Surface: what does it mean for AI governance?

Nieuws
26-03-2026
Yuri Bobbert
Large Language Models (LLMs) are transforming industries, but their unique risks demand a new approach to security and governance. A groundbreaking paper co-authored by Anove Co-Founder Prof. dr. Yuri Bobbert and ethical hacker Kevin Zwaan from Q-Cyber exposes how traditional security controls fall short when AI behavior can be steered through plain everyday language.

A recent demonstration showed how an LLM could be "radicalized" over eight hours, bypassing safety guardrails to generate malware at scale. This wasn't a highly technical code-written software exploit; it was achieved through manipulation and persuasion, taking advantage of the model’s contextual learning to make it unlearn its security protocols, revealing a critical gap in AI security.

The paper highlights that AI's attack surface is broader than code. It includes the model, prompts, user interfaces, policies, and even the organizational context. When LLMs are integrated into workflows with access to tools, APIs, and sensitive data, the risks multiply, ranging from generating malicious content to enabling large-scale cyberattacks. AI systems are dynamic, made up of interconnected components that evolve rapidly. As a result, traditional governance can’t keep up. Static checklists and one-time audits aren’t enough (if they ever were). AI management must be continuous, automated, and evidence-based.

[....]

Gerelateerde vacatures

Geïnteresseerd in een carrière bij organisaties in ditzelfde vakgebied? Bekijk hieronder de gerelateerde vacatures en vind de perfecte match voor jou!
Hermans & Partners
Marktconform
Medior
Rotterdam
Als Lead Cybersecurity Consultant/ vCISO (MKB) bij WeSecureIT bouw je een nieuwe cybersecurity business unit op, adviseer je directies strategisch, voer je assessments en risicoanalyses uit, ontwikkel je roadmaps en...
Rabobank
5.994 - 8.563
Senior
Utrecht
As a Technology & Innovation Risk (Project) Managers; focus on Business Resilience bij Rabobank, challenge en monitor je BCM- en Third Party-risico’s, meet en rapporteer je risk exposure en trends,...
AZL
7.023 - 10.032
Medior, Senior
Heerlen
Als Lead Enterprise Architect bij AZL verbind je strategie, dienstverlening en IT tot één visie en stuur je de modernisering naar een cloud-based, event-driven landschap. Je adviseert CIO/directie, borgt architectuurgovernance...
NN
4.324 - 5.765
Medior
Den Haag
The Customer & Digital security team seeks a medior Information Security Officer to manage information security risks, support DevOps teams, and ensure compliance with security standards and guidelines.