ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Building secure AI from the inside out

AI systems are now embedded in businesses, influencing daily decisions in almost all sectors, from finance to public services, and are becoming far more difficult to govern. The vulnerabilities that arise are very rarely in the form of some dramatic breach that causes a catastrophic failure. Instead, they become apparent through gaps in training and siloed teams. 

 

In this light, security depends less on the code itself and more on the habits and coordination of the teams that are being built around AI. 

 

 

Shifting the lens 

When talking about the security behind AI, most people picture technical roadblocks, like resilient models and strong algorithms. They understandably think the most significant risks live in code as they are tangible components.  

 

But in reality, the majority of these risks arise from gaps in coordination. The risks tend to build slowly when updates aren’t logged, when models move between teams without context, or when no one is quite sure who made the last change.  

 

The UK’s Cyber Security and Resilience Bill is a step forward in formalising how digital infrastructure should be secured. It sets new expectations for operational assurance and incident responses, especially for service providers that support critical systems. But legislation like this is still largely aimed at infrastructure. It hasn’t fully caught up with the way AI systems are developed and deployed inside organisations. 

 

This matters because in certain sectors, such as healthcare and finance, models are already influencing high-stakes decisions. They’re often built in environments where roles shift, tools change rapidly, and governance struggles to keep up. In these contexts, risk is less about broken code and more about broken coordination. 

 

 

Small changes can have big consequences  

AI is rarely confined to one singular team. Models are retrained, reused, and adapted as needs shift. While that kind of flexibility is a key part of its value, it also adds layers of complexity. 

 

Seemingly small changes can have wide-reaching effects. One team might update the training data to reflect new inputs. Another might adjust a threshold to reduce false positives. A third might deploy a model without checking how it was configured before. 

 

Individually, none of these actions is wrong. But when organisations can’t trace decisions back to their origin, or even when it’s unclear who approved a change, their ability to respond to crises quickly dissolves. 

 

The problem isn’t faulty code or flawed architecture. It’s that the practices for building, adapting, and handing over systems haven’t kept pace with how widely AI is now deployed. When working culture lags behind adoption, risks become harder to see and even harder to contain. 

 

 

Turning culture to infrastructure 

Resilience must be built in the same place that risk accumulates. And as it often arises in day-to-day habits, culture must become a mechanism for maintaining control, especially as systems scale. 

 

That principle is reflected in regulation. The EU AI Act sets requirements for high-risk systems, including conformity assessments and voluntary codes of practice. Yet the real responsibility for embedding governance into everyday routines still falls to the organisations deploying AI. 

 

In the UK, the Department for Science, Innovation and Technology’s AI Cyber Security Code of Practice follows a similar approach, pairing high-level principles with practical guidance that helps businesses turn policy into working norms. 

 

Research and recognition programmes point in the same direction. Studies of real-world AI development, such as the UK’s LASR (Laboratory for AI Security Research) initiative, show how communication, handovers, and assumptions between teams’ shape trust as much as the models themselves. Initiatives such as the National AI Awards then highlight organisations that are putting cultural governance into practice and establishing clearer standards of maturity. 

 

Businesses must now look within themselves and task themselves with the challenge of making cultural clarity a more integrated part of operational design. When teams rely on visible ownership, shared norms, and consistent decision-making, AI systems will only become more resilient and easier to govern as they scale. 

 

 

Looking ahead  

It’s clear that AI is no longer a side project. It’s becoming a part of everyday decision-making, which means the risks and responsibilities tied to it cannot be managed at just the model level. 

 

For leaders, the real test will lie in whether their organisation will have the discipline to keep a system’s performance reliable over time. That requires investments in both technology and the connective fabric that holds the teams together. This includes the routines, shared practices, and checkpoints that make development predictable even as tools and roles change. 

 

Progress in this space doesn’t happen overnight. It comes from building a culture where accountability is visible, ownership is clear, and decisions are traceable. 

 

This cultural structure is what will ultimately shape security. Through embedded habits that make risk easier to see, surface and act on, as AI becomes more pivotal to how today’s businesses operate. When that foundation is in place, security stops being reactive and becomes part of the way AI is built and used every day. 

 


 

Darren Lewis is National AI Awards Advisory Board Member and Senior Lead at Plexal

 

Main image courtesy of iStockPhoto.com and tadamichi


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543