Our State of Authorization: AI Edition is now available Get it now »

Securing AI and LLMs: The road to governance

Explore why AI pilots are failing and how enterprises can secure AI agents with policy-driven authorization.

With all the excitement due to the uprising of generative AI, more organizations are exploring ways that they can leverage this exciting technology. However, while there are many AI pilots, most of them actually fail due to security issues and inability to meet governance. In fact, a whopping 95% of AI pilots never make it off of the ground.

These statistics clearly show that there is a gap organizations are not fulfilling when it comes to AI. Axiomatics has partnered with the Imago Platform by Automagicians to explore why these pilots are failing and how enterprises can secure AI agents with policy-driven authorization.

Why do AI pilots fail?

At the start of these pilots, there’s so much excitement about what the future holds. But, what many organizations fail to recognize is that there’s much more to these technologies than meets the eye. One of the biggest hurdles is implementing fine-grained access controls that ensure employees only see the data they’re authorized to access, even when it’s surfaced through an AI system to adhere to governance requirements. Without that level of precision and trust, pilots stall and deployments never take off.

This is because AI and Large Language Models (LLMs) introduce a two-sided problem. When an LLM queries information, it often operates with broad, near-unrestricted privileges. This allows it to gather helpful, benign data but it can just as easily pull in highly sensitive information. In return, when responding to a user prompt, the model’s objective is to provide the most relevant answer as quickly as possible. If sensitive data has already been ingested or retrieved, the model may surface that information in its response, even when the user is not authorized to see it.

For example, a user might ask,“How much does the CFO make?” If the LLM has access to internal compensation data and no guardrails are in place, it may return that precise figure — even if the requester has no permission to view executive salary information.

This two-sided problem introduces security challenges that end up halting AI pilots including:

  • AI agents unintentionally accessing data far beyond what users are not permitted to view;
  • Existing role-based access controls (RBAC) allowing agents to execute sensitive operations without proper safeguards;
  • Audit and compliance gaps as activities cannot be reliably linked to actual users or validated consent, undermining auditability; and
  • Credential leaks due to keys and tokens appear in prompts or workflows where attackers could capture them.

The best way to keep a secret is to not tell it; it is the same with an LLM. Once information is put in the LLM, it can be difficult to control the way it comes out when the AI prompts a return. This is why the sensitive information should never reach the model and where Axiomatics’s partnership with Automagicians comes into play.

Inside the architecture: Enforcing fine-grained authorization for AI agents

On the left side of the architecture is the Imago Platform’s user interface, which interacts with its underlying agents. An agent is a system component responsible for executing instructions — it determines how to process information, what actions to take, and in what sequence. Each agent can leverage a variety of tools, such as sending emails or conducting research, and it relies on LLMs to help complete its tasks.

To perform these tasks, the agent must retrieve information from various data sources. In a default setup, agents are often connected directly to the underlying databases. This direct access is where the core security problem begins.

High level architecture of Axiomatics and Imago Platform

 

To address this issue, the Imago Platform introduced a query filter between the agent and the database, integrated with Axiomatics. This means that before the agent can retrieve any information, the user’s identity and other required attributes (user, resource, and/or actions) are evaluated by the Axiomatics’ Authorization Management Platform (AMP). This enforces dynamic, fine-grained authorization, ensuring the agent can access only the data the user is permitted to see.

From the agent’s perspective, this filter is completely transparent. The agent (and the LLM behind it) believes it is communicating directly with the database. In reality, every request is intercepted, evaluated, and sanitized. Any information that the user is not authorized to access is removed before it ever enters the system, providing a critical layer of protection.

For example there could be two different users: A CFO and a developer. Both users log onto the platform the same way and enter the same prompt: “Show me the last 10 deals”. By using attributes that are assigned to users, Axiomatics checks them against policies in real time ensuring guardrails are in place so information isn’t shared with the wrong party.

When the CFO enters the prompt, they will be given a table which shows the following information about the 10 latest deals: the deal name, the deal value, the company, the stage it is at, the deal owner, and the source. But, when the developer enters the prompt, they will be able to see everything except the deal value.

If the developer were to suddenly get promoted to an executive level, attributes would be able to be changed in real-time allowing them to view the deal values. By having these guardrails put into place, organizations can be confident that individuals are given the right amount of access at the right time.

If you’d like to see this integration in action, check out the full demo below:

A seamless experience with security that “Just Works”

The demo feels clean and effortless — and that’s intentional. Security should protect users and their data without forcing them to navigate complexity. The moment security becomes cumbersome, people find ways around it, and the entire system fails.

With fine-grained authorization, all of the heavy lifting happens behind the scenes. Access decisions are enforced in the backend, never exposed to the user, so the experience stays frictionless while the security posture stays strong.

The road to AI governance

Just as there was an evolution with the internet, there will also be an evolution of AI. But here’s the critical question:If you ask your LLM sensitive questions about your organization, does it reveal more than it should?

If your model is returning information that users shouldn’t have access to, that’s a signal to take a closer look at your safeguards around AI.

If you’re ready to see the next steps of AI governance, check out the full webinar here, or reach out to our solution experts with any questions you have.

Have 30 minutes? Let's show you a demo!

See how our award-winning solution can help you meet today's access control and Zero Trust needs.

Request a demo

  Join us on LinkedIn for more insights
Archived under:
About Axiomatics

The world’s largest enterprises and government agencies continually depend on Axiomatics’ award-winning authorization platform to share sensitive, valuable and regulated digital assets – but only to authorized users and in the right context.