The security company SentinelOne has released a new AI security posture management (AI-SPM) tool that provides greater visibility into both the known and unknown uses of AI across an organization.
“The power and benefits of generative AI are undeniable. Yet, the very tools and cloud services that simplify and accelerate GenAI adoption are simultaneously opening up a brand new attack surface and potential regulatory risk,” said Ely Kahn, vice president of product management at SentinelOne. “With AI-SPM, we’re empowering customers to unleash the distinct advantages of GenAI, while giving security teams the visibility, insight, and tools needed to protect the sensitive data behind these powerful cloud applications.”
It can discover all AI services, training, deployed models, and pipelines from cloud services, including AWS, Google Cloud, and Microsoft Azure.
AI-SPM also helps companies discover misconfigurations in their AI infrastructure that could potentially lead to data exfiltration and unauthorized access.
According to SentinelOne, data theft is one of the most common AI-related security issues. For instance, a developer might create an Amazon Bedrock job to train a machine learning model, but not attach it to a Virtual Private Cloud, which would expose that job to the Internet and potentially give attackers access to company data or personally identifiable information (PII).
Further, AI-SPM’s graph explorer provides a visual representation of attack paths in AI workloads to help organizations better understand how attackers could move through their environment.
“Misconfigured AI systems, such as exposed endpoints or improper access controls, are low-hanging fruit that threat actors look to exploit, potentially leading to model manipulation or data compromise. Proactive security measures like SentinelOne’s AI-SPM become key in protecting business-critical data and ensuring the integrity of AI workloads across quickly changing AI-based threats.” Anand Prakash, head of cloud security at SentinelOne, wrote in a blog post.