What are AI security best practices?
By Identra · Updated
AI security best practices are the controls and habits that protect data, identities and systems when people and agents use AI. They tie approved use cases to limited access, data protection, controlled agent actions and tested incident response.
Why isn't approving the AI vendor enough?
Approving ChatGPT Enterprise says nothing about the employee who pastes the same customer list into a personal ChatGPT login at home. Or about the Microsoft 365 Copilot rollout that surfaces a SharePoint file someone shared with the whole company years ago.
Risk sits in the workflow. Which account, what data it can reach, what its connections are allowed to do, and where the output lands.
Employee uses an AI chat app
- Main exposure
- Sensitive content goes into the wrong account
- Control to verify
- Approved workspace and upload restrictions
Assistant searches company documents
- Main exposure
- Overshared files reach the wrong person
- Control to verify
- Source permissions and retrieval scope
Agent edits files or calls business tools
- Main exposure
- Its credentials allow changes nobody intended
- Control to verify
- Narrow permissions and per-action approval
Where do you start?
Find what's already running. AI sites and the accounts signed into them, browser extensions, desktop apps, coding agents, connected SaaS apps. Include the MCP servers sitting in files like ~/.cursor/mcp.json, plus the skills and plugins that widen what an agent can reach. Compare all of it with what you approved. The difference is your shadow AI.
Fix live exposures first, even while the inventory is half done. An API key pasted into a prompt. A connector with write access to production.
- Give every approved app, agent and connection a named owner.
- Approve public content and confidential data as separate decisions.
- Make requesting a new tool fast. Otherwise people keep using the one they already have.
- Retire entries when the business purpose ends.
How do you keep sensitive data safe?
Decide what data can go where, per use case. Read the provider's terms on retention, training, deletion and admin access for the tier you actually pay for. Then put it in an AI acceptable use policy with examples people recognize from their own jobs.
Enforcement has to sit where data moves. AI data loss prevention in the browser won't see a desktop client or an automated retrieval job, so test browser prompts, file uploads, desktop apps and connectors separately. Use synthetic secrets for the tests.
Output is untrusted too. Validate it, escape it for wherever it ends up and review generated code before anything runs it.
What controls do AI agents need?
Apply least privilege to every tool, file path, network destination and credential an agent gets. Keep development and production access apart. Put authorization in the tool service. A model deciding to call a tool is not permission to run it.
Retrieved pages, documents and tool responses can all carry prompt injection. Filters catch some of it and miss some of it, so the permission boundary has to hold by itself. Before enabling an MCP server, skill or plugin, check its publisher, the access it requests and its dependencies.
Keep secrets out of model context and prefer short-lived credentials. Test revocation for real. Turning off someone's SSO login doesn't necessarily end the OAuth grants they already gave third-party apps.
- Require approval for external sends, destructive changes and permission changes.
- Show the approver the exact action, destination and data.
- If the action changes after approval, the approval no longer counts.
What does testing one workflow look like?
Say a support team wants an assistant that drafts replies from Zendesk tickets and internal docs. Scope it to the team's queue. No credentials in its context, no access to unrelated customers, no permission to send mail or change account settings. Drafts land in a review queue.
Now plant a synthetic ticket telling it to export every customer record to an outside address. If the model goes along with it, the tool service should still refuse, because the agent has no export permission. That's AI agent authorization doing its job.
Six months later the team wants auto-send. Treat it as a new capability and rerun the malicious ticket.
How do you prepare for an AI incident?
Keep an AI audit trail that ties each user or agent to its account, the action it requested, the target, the policy decision and the result. Don't let those logs turn into a second pile of exposed secrets.
Retest controls whenever models, tools, permissions or provider settings change.
- Name responders and write down how to stop runs, disconnect integrations and revoke access.
- Rehearse two cases: a sensitive file upload and a compromised agent connection.
- Rotate exposed credentials and check what changed downstream.
- Retest the control that failed before restoring access.
How Identra thinks about it
Identra shows AI use across the browser, macOS and Windows endpoints, and connected identity, SaaS and cloud services. Teams can allow, redirect or block supported browser AI apps by work or personal account, check prompts on the device before they're sent and check agent tool calls against policy. Every endpoint agent run is recorded with its outcome for follow-up.
Go deeper: AI security, built on identity
Frequently asked questions
Where should an enterprise start with AI security?
Find the AI tools, accounts, agents and connections already in use. Deal with exposed credentials, sensitive uploads and broad permissions first, then assign owners and offer approved options.
Can a system prompt enforce security policy?
No. A system prompt shapes behavior but it isn't an authorization boundary. Enforce access and action limits in the systems that hold the data and run the tools.
Do internally hosted models eliminate AI security risk?
No. Self-hosting gives you more control over deployment and data handling. You still need access control, protected infrastructure, constrained tools, output validation and incident response.
How should teams evaluate an AI vendor?
Review the exact service, contract, account tier and configuration in use. Check data handling, access controls, connector permissions, logging, deletion and incident notification.
Should every agent action require human approval?
No. Match approval to consequence. Routine, narrow actions can run on predefined permissions. Destructive changes, sensitive disclosures and access changes get a human.
