AI, for all its intelligence, is not risk-free and requires your attention. Cloud-based AI is prone to avoidable toxic combinations that leave sensitive AI data and models vulnerable to manipulation, data tampering and data leakage, according to a report by exposure management company Tenable.

“Cloud and AI are undeniable game changers for businesses. However, both introduce complex cyber risks when combined,” the Cloud AI Risk Report 2025 report said.

The report throws light on the state of security risks in cloud AI development tools and frameworks, and in AI services offered by some top cloud providers.

For one, the report found CVE-2023-38545, a critical curl vulnerability, in 30 per cent of cloud AI workloads.

Many organisations are turning to cloud-based AI services to power their business. AI technologies increase cloud data volume and sensitivity, which can raise security and compliance risks.

Citing OWASP (Open Worldwide Application Security Project), the Tenable report said attackers seek to compromise AI models, manipulating their input data and the outputs they produce, exposing sensitive information, and causing models to behave in undesirable ways.

“Cloud AI workloads aren’t immune to vulnerabilities. About 70 per cent of cloud AI workloads contain at least one unremediated vulnerability,” it said.

“AI training data is susceptible to data poisoning, threatening to skew model results. About 14 per cent of organisations using Amazon Bedrock do not explicitly block public access to at least one AI training bucket and 5 per cent have at least one overly permissive bucket.

“When we talk about AI usage in the cloud, more than sensitive data is on the line. Suppose a threat actor manipulates the data or AI model. In that case, there can be catastrophic long-term consequences, such as compromised data integrity, compromised security of critical systems, and degradation of customer trust,” Liat Hayun, VP of Research and Product Management, Cloud Security, Tenable, said.

“Cloud security measures must evolve to meet the new challenges of AI and find the delicate balance between protecting against complex attacks on AI data and enabling organisations to achieve responsible AI innovation,” Liat said.

Shadow AI risks

The report also highlights the challenge of Shadow AI (private use of AI tools by employees). “It’s important to minimise shadow AI risk via centralised governance, education and monitoring. You must protect your organisation even further with policies that disallow unsanctioned AI applications, and educate employees on the risks, responsible AI use and approved alternatives,” it said.

It wanted organisations to monitor their cloud environments for shadow AI, limiting access as needed.

By admin

Leave a Reply

Your email address will not be published. Required fields are marked *