Skip to content
Cyber Strategy and Governance

AI Security

Adopt AI with confidence — governed, tested and secure.

AI Security
Govern · Test · Protect
Overview

AI is already inside your organisation, whether you've sanctioned it or not. Staff are pasting work into chatbots, teams are wiring language models into products, and vendors are adding AI features to tools you already run — each one a new place for sensitive data to leak and a new surface for attacks that conventional security testing was never designed to find.

Avocado brings AI security specialists together with the governance, testing, privacy and delivery consultants behind our other Cyber services, working to recognised frameworks including ISO/IEC 42001, the NIST AI Risk Management Framework and the OWASP GenAI Security Project, aligned with the Australian Government's Guidance for AI Adoption.

Who is this for?

You'll recognise the situation

Staff are already pasting work into chatbots and vendors are adding AI features to tools you run, whether you've sanctioned it or not.

You don't know what AI is in use across your organisation, or who's accountable for it.

You're deploying AI applications or agents without testing them against AI-specific attacks like prompt injection and data leakage.

You need to protect personal and sensitive information flowing into prompts, models and training data ahead of incoming transparency obligations.

What's included

Govern, test, adopt and protect

AI Governance and Risk

Govern AI use with policies, risk assessment and frameworks your board can stand behind.

AI Security Assessment

Test AI applications and integrations against AI-specific attacks, from prompt injection to data leakage.

Secure AI Adoption

Discover shadow AI, set guardrails for everyday AI use, and build with secure-by-design patterns.

AI Data Protection

Protect the personal and sensitive information flowing into prompts, models and training data.

In detail

How each capability works

01

AI Governance and Risk

AI governance in Australia is a moving target — guidance has already been replaced once, mandatory national standards have been announced, and existing laws apply in the meantime. We track that landscape so you don't have to, and build governance structured so tomorrow's mandatory standards land as an adjustment rather than a rebuild.

Our approach
  • AI use policy and acceptable-use rules for staff, systems and suppliers.
  • AI governance framework aligned with the Guidance for AI Adoption's six essential practices — accountability, impact assessment, risk management, transparency, testing and monitoring, and human control.
  • AI system inventory and register, with a named owner for every AI system in use.
  • Use-case risk assessment using the NIST AI Risk Management Framework and its Generative AI Profile.
  • ISO/IEC 42001 AI management system readiness — gap assessment, AIMS design and preparation for certification by an accredited certification body.
  • Board and executive reporting on AI risk, and alignment with obligations that already reach AI systems through our Governance, Risk and Compliance service.
02

AI Security Assessment

AI applications fail in ways conventional testing doesn't look for. A web app scanner won't find a prompt injection that talks your chatbot into leaking customer records, and a code review won't catch an agent with more access than any employee would ever be given. We assess AI systems with people who understand both application security and AI attack classes.

Our approach
  • Threat modelling for AI systems: what the model can see, what it can do, and who can influence it.
  • LLM application assessment against the OWASP Top 10 for LLM applications: prompt injection, sensitive information disclosure, insecure output handling and excessive agency.
  • RAG and data pipeline security review: what your retrieval layer exposes, and to whom.
  • AI supply chain review: third-party models, APIs, plugins and the permissions they arrive with.
  • Agentic workflow risk assessment: tool access, delegation chains and human-in-the-loop controls.
  • Guardrail effectiveness testing: whether your filters and controls actually hold under adversarial input.
03

Secure AI Adoption

Banning AI doesn't stop AI — it just stops you seeing it. Staff who are told no keep using personal accounts, and the data keeps leaving, invisibly. We take the enablement path: discover what's actually in use, sanction tools that can be governed, and set guardrails that make the safe way the easy way.

Our approach
  • Shadow-AI discovery — which AI tools are actually in use, by whom, with what data.
  • Sanctioned tool selection and secure configuration — enterprise controls, data handling and retention settings.
  • Guardrails for everyday AI use — what can and can't go into a prompt, enforced by controls rather than memos.
  • Secure-by-design patterns for teams building with AI — least-privilege model access, output validation and human-in-the-loop checkpoints.
  • AI usage training and awareness, delivered with our Cyber Security Training service.
  • Ongoing review cadence, so new tools and features are assessed before they spread.
04

AI Data Protection

Most AI risk lands on data: personal information pasted into prompts, customer records swept into training sets, model outputs that reveal more than anyone intended. We assess AI data handling against the OAIC's guidance on privacy and generative AI, working hand in hand with our Privacy Advisory service — privacy decides what your organisation may do with personal information; this capability makes sure your AI systems actually do only that.

Our approach
  • AI data flow mapping — what enters prompts, training and fine-tuning, and where outputs go — assessed against the OAIC's guidance on privacy and generative AI.
  • Vendor AI data handling review — whether your suppliers train on your data, and what your contracts actually say.
  • De-identification and minimisation controls for AI pipelines, and readiness for incoming automated decision-making transparency requirements.
How do we deliver it?

Govern, test, enable, protect

01

Govern

Govern AI use with policies, an AI system inventory, and use-case risk assessment.

02

Test

Test AI applications and integrations against AI-specific attacks — prompt injection, sensitive information disclosure, insecure output handling and excessive agency.

03

Enable

Enable secure adoption — discover shadow AI, sanction tools that can be governed, and set guardrails that make the safe path the easy one.

04

Protect

Protect the personal and sensitive information flowing into prompts, models and training data, ready for incoming transparency obligations.

Book a discovery

Book a discovery with our cyber team

Tell us where AI is showing up in your organisation — we'll tell you what to govern, test and protect first.

What tools and technology do we use?

Aligned to recognised AI frameworks

AI governance is aligned with the Australian Government's Guidance for AI Adoption and ISO/IEC 42001. Assessment and testing follow the NIST AI Risk Management Framework and its Generative AI Profile, and the OWASP Top 10 for LLM applications and broader GenAI Security Project. AI exposure can be quantified in dollars using FAIR, so AI risk competes for budget on the same terms as every other security risk.

What outcomes can you expect?

What you walk away with

Approve AI use cases quickly, on evidence rather than enthusiasm.
Find the AI-specific flaws conventional testing was never designed to catch.
Say yes to AI faster, because the guardrails already exist.
Use your data in AI without compromising your customers' trust.
How is this engagement structured?

Not sure what AI is already in use across your organisation? Start with a shadow-AI discovery. Contact us for a tailored quote.

FAQ

Common questions

What is prompt injection?

A class of attack specific to AI applications where crafted input manipulates a model into ignoring its instructions or revealing information it shouldn't — one of the AI-specific attack types conventional security testing isn't designed to catch.

Is mandatory AI regulation already in force in Australia?

Not yet. The Australian Government has announced it will legislate national AI standards — currently scoped around AI infrastructure and training data rather than general obligations on organisations deploying AI — and existing laws (privacy, consumer, critical infrastructure) already apply to AI systems in the meantime. The nearer obligation is the Privacy Act's incoming automated decision-making transparency requirement.

Should we ban staff from using AI tools until we have governance in place?

Banning tends to push usage underground rather than stopping it, and the numbers back this up — recent industry research puts the share of organisations with employees using unsanctioned AI tools close to universal, with usage climbing rather than falling as seniority increases. The recommended approach is enablement — discover what's actually in use, sanction tools that can be governed, and set guardrails that make the safe path the easy one.

How is this different from Avocado's AI Governance Framework (AI and Data)?

This page covers AI security specifically — governance, testing, adoption and data protection through a security lens. AI Governance Framework (under AI and Data) covers the broader build-and-implement governance engagement. The two are designed to work together, not duplicate each other.

Does this cover agentic AI specifically?

Yes — agentic workflow risk assessment covers tool access, delegation chains and human-in-the-loop controls for AI agents specifically, alongside conventional LLM application testing.

Deliver with certainty

Move fast on AI — safely

Talk to our AI security specialists about governing, testing and protecting the AI your organisation is already using.