The AI security layer
The threats your CISO will ask about on page one, framed for campus, each mapped to the OWASP LLM Top 10 with a concrete control.
Prompt injection
LLM01Hidden instructions in user input or fetched content hijack the model's behavior.
On campusA student pastes text that makes a grading assistant ignore its rubric, or a malicious web page redirects a research agent.
ControlTreat all model input as untrusted, constrain tool/permission scope, and keep a human on any consequential action.
Sensitive information disclosure
LLM02The model surfaces data it shouldn't, to the wrong user, or to a vendor that retains it.
On campusStaff paste FERPA-protected records into a personal AI account; a chatbot returns one student's data to another.
ControlDLP at the boundary, no sensitive data into unvetted tools, and contractual no-training / no-retention terms.
Improper output handling
LLM05Model output is trusted and passed downstream, into SQL, shell, HTML, or emails, without validation.
On campusAn AI feature's output is rendered straight into a page or used to build a query, opening injection or XSS.
ControlValidate and encode every output before it touches another system; never execute model output unguarded.
Excessive agency
LLM06The system can take more actions, with more autonomy, than the risk justifies.
On campusAn agent wired to the SIS can modify records, not just read them; an integration has write scope it never needs.
ControlLeast privilege on every integration, read-only by default, and explicit approval gates for state changes.
Supply-chain & embedded risk
LLM03Risk inherited from vendors, plugins, and AI features switched on inside existing systems.
On campusAn LMS or productivity-suite update activates AI that now processes student work under new data terms.
ControlInventory embedded AI, track subprocessors, and re-review vendor terms when features change.
Unbounded consumption & cost
LLM10Unmetered usage drives runaway spend or denial-of-wallet, and enables model abuse.
On campusA looping agent or exposed API key burns thousands in tokens over a weekend before anyone notices.
ControlRate limits, budget caps with alerts, key rotation, and per-app quotas at the gateway.