Deflected Blog

AI Security & Post-Quantum Insights

40 in-depth, practitioner-written guides on securing the AI layer — from prompt injection and AI governance to post-quantum encryption and deepfake fraud. Written and reviewed by the Deflected Security Team.

AI Security

Securing the models, prompts, agents, and pipelines behind your AI.
AI Security

AI Agent Security: Managing Excessive Agency & Tool Risk

How to secure AI agents: managing excessive agency, tool-use risk, and prompt injection in agentic AI. A practical security model for LLM agents from Deflected.

Read the guide →
AI Security

AI Data Leakage: How Sensitive Data Escapes Model Output

AI data leakage explained: how sensitive information escapes through LLM output, RAG, logs, and providers — and how to build defense-in-depth against exfiltration.

Read the guide →
AI Security

AI Incident Response: A Practical Guide for Security Teams

A practical AI incident response guide: why AI incidents differ, how to adapt the NIST SP 800-61 lifecycle, detection signals, containment, forensics, and comms.

Read the guide →
AI Security

AI Red Teaming vs Penetration Testing

AI red teaming vs penetration testing: how they differ in scope, objectives, methodology, cadence, and outputs — and why AI systems need continuous adversarial testing.

Read the guide →
AI Security

AI Red Teaming, Explained

AI red teaming is adversarial testing of AI systems. Learn what it is, how it differs from pen testing, the technique spectrum, frameworks, metrics, and how to build a program.

Read the guide →
AI Security

Adversarial Machine Learning Attacks

Adversarial machine learning attacks manipulate AI models through evasion, poisoning, extraction, and prompt-level inputs. Learn the threats and the defenses.

Read the guide →
AI Security

Deepfake & Voice-Clone Fraud: How to Defend Your Business

A practical guide to deepfake fraud, voice clone fraud, and AI-enabled business email compromise — and the layered process, people, and technology defenses that stop it.

Read the guide →
AI Security

How to Secure LLM Applications: An Enterprise Checklist

A practical LLM security checklist for engineers and security teams: prompt-injection defense, output handling, RAG isolation, least privilege, and the OWASP LLM Top 10.

Read the guide →
AI Security

Indirect Prompt Injection & RAG Poisoning, Explained

Indirect prompt injection turns retrieved documents, web pages, and tool output into hidden instructions. Learn how RAG poisoning works and how to defend against it.

Read the guide →
AI Security

Insecure Output Handling

Insecure output handling explained for the enterprise: why unsanitized LLM output causes XSS, SQL injection, command execution, SSRF, and data exfiltration — and how to defend it.

Read the guide →
AI Security

Jailbreaking LLMs: How Guardrail Bypasses Work

An LLM jailbreak bypasses a model's safety guardrails. Learn how jailbreaking LLMs works, why guardrails are probabilistic, and how to defend AI in depth.

Read the guide →
AI Security

LLM Guardrails: A Practical Guide for Enterprise AI Security

What LLM guardrails are, the input and output controls that make them work, why they are probabilistic and not a security boundary, and how to design and test them.

Read the guide →
AI Security

Model Extraction & Inversion Attacks: Stealing Models and Training Data

A model extraction attack reconstructs your proprietary model through API queries. Learn extraction, model inversion, membership inference, and the defenses.

Read the guide →
AI Security

Post-Quantum Cryptography, Explained for Enterprises

A clear enterprise guide to post-quantum cryptography: the quantum computing threat, harvest now decrypt later, NIST PQC standards, and a practical migration roadmap.

Read the guide →
AI Security

Securing RAG Systems

A practical guide to RAG security: the risks unique to retrieval-augmented generation — prompt injection, knowledge base poisoning, permission bleed, embedding leakage — and how to defend them.

Read the guide →
AI Security

Shadow AI: The Hidden Risk of Unsanctioned AI Tools

Shadow AI — employees using unsanctioned AI tools without oversight — is the AI-era evolution of shadow IT. A practical guide to the risks and how to govern it.

Read the guide →
AI Security

The AI Attack Surface

The AI attack surface, mapped for the enterprise: models, prompts, RAG, agents, supply chain, and APIs — walked through the OWASP Top 10 for LLM Applications.

Read the guide →
AI Security

Training-Data Poisoning: Risks to AI Models & Defenses

Training data poisoning corrupts AI models at the source. Learn how data poisoning attacks and model backdoors work, the AI supply-chain risk, and how to defend.

Read the guide →
AI Security

What Is AI Security? A Complete Guide for Enterprises

What is AI security? A complete enterprise guide to securing AI systems: the AI attack surface, threats like prompt injection and data leakage, governance, and defense.

Read the guide →
AI Security

What Is Prompt Injection? The Top LLM Security Risk

Prompt injection is the #1 LLM security risk. Learn how prompt injection attacks work, direct vs. indirect injection, real-world impact, and how to defend AI.

Read the guide →
AI Security

What Is an AI Gateway?

An AI gateway is the inline control point between your apps and models — inspecting prompts, blocking injection, redacting PII, enforcing policy, and routing.

Read the guide →
AI Security

Zero Trust for AI: Securing the Layer Where the Requests Are Language

A practical guide to zero trust AI: applying never-trust/always-verify, least privilege, and assume-breach to prompts, retrieval, model output, and agents.

Read the guide →

Encryption & Post-Quantum

Quantum-ready cryptography and the migration ahead.

AI Governance & Compliance

Frameworks, audits, and audit-ready evidence.
AI Governance

Answering AI Security Questionnaires

A practical enterprise guide to answering the AI security questionnaire — SIG, CAIQ, and VSA frameworks, the categories buyers probe, and building a reusable evidence library.

Read the guide →
AI Governance

Building an AI Governance Framework

How to build an AI governance framework: guiding principles, roles and RACI, an AI inventory, policies, lifecycle controls, and mapping to NIST AI RMF, ISO 42001, and the EU AI Act.

Read the guide →
AI Governance

ISO/IEC 42001 Explained: The AI Management System Standard

ISO 42001 explained: what the ISO/IEC 42001 AI management system standard is, its structure and Annex A controls, how it relates to 27001 and the EU AI Act, and the certification path.

Read the guide →
AI Governance

SOC 2 for AI Companies: A Practical Guide

SOC 2 for AI companies: what the attestation is, Type I vs Type II, the Trust Services Criteria, AI-specific controls, a readiness roadmap, and how it maps to AI rules.

Read the guide →
AI Governance

The AI Compliance Checklist

A practical AI compliance checklist covering data governance, model governance, security controls, oversight, and framework mapping to SOC 2, NIST AI RMF, EU AI Act, and ISO 42001.

Read the guide →
AI Governance

The EU AI Act Explained: What It Means for Your AI

A plain-English guide to the EU AI Act: its risk-based tiers, high-risk AI obligations, GPAI rules, the phased timeline, penalties, and a practical readiness checklist.

Read the guide →
AI Governance

The NIST AI Risk Management Framework: A Practical Guide

A practical guide to the NIST AI RMF: what the framework is, its trustworthy AI characteristics, the GOVERN, MAP, MEASURE, and MANAGE functions, and how to operationalize it.

Read the guide →
AI Governance

What Is AI TRiSM? Trust, Risk and Security Management, Explained

A clear, enterprise guide to AI TRiSM (AI Trust, Risk and Security Management): its four pillars, why it matters, and how it complements NIST AI RMF, ISO 42001 and the EU AI Act.

Read the guide →

Fraud & Social Engineering

Deepfakes, voice clones, and AI-driven fraud.

Industry & Reference

Sector guides and reference material.