Estimated reading time: 9 minutes
64% of organisations have deployed at least one generative AI application with critical security vulnerabilities (CISO Council’s Enterprise AI Security Index, January 2025). These concerning statistics emphasise the importance of AI Security policies for businesses that want to deliver sustainable value with AI.
An organisation’s approach to AI security evolves over time, and every stage is associated with different needs, risks and characteristics. To help CISOs and security leaders envision the path towards a truly secure AI future, our experts prepared a detailed guide, featuring our Cyber Trust AI Cube model.
But before jumping into solutions, it is worth asking yourself where exactly you are on your AI security journey. You can treat this expert view as an addition to our Secure AI, Sustainable Value whitepaper or as your starting point before you go deeper. We’ll break down each security maturity stage, revealing the elements you need. And you’ll see how to use the Cyber Trust AI Cube model as your trusted companion every step of the way.
The AI Security Maturity Journey
Let’s start by defining the stages of AI security maturity in organisation’s path to secure and sustainable AI. At Devoteam, we define four phases: Exploration, Formalisation, Integration and Excellence.
Each phase allows CISOs to better understand their current situation and visualise the next step.

1. Exploration
In this stage, organisations evaluate pilot tests, implementing AI tools with potential for adoption. It is a phase with low or no governance, where initiatives are usually dispersed and risks are high.
2. Formalisation
In this phase, organisations decide to adopt one or more AI solutions. A formal structure begins to be established, with first controls, policies, and visibility processes. This is where security starts to come into play, albeit initially.
3. Integration
The integration phase marks the point at which AI is fully incorporated into the organisation’s key processes. At this point, you must have clearly defined controls, and collaboration between teams (security, data, legal, IT, etc.) becomes essential to maintain consistency.
4. Excellence
In the final state, the organisation operates with a strategic view of AI. Security is continuous, proactive and measurable.
AI is governed from a central structure (such as an internal AI Agency), ensuring resilience, regulatory compliance and sustainable competitive advantage.
AI Security Maturity Stages: Traits, Risks and Focus Areas
We looked briefly at each stage of AI Security Maturity, time to make it more actionable! Below, I break down all the stages and describe the cybersecurity implications of each. Along with the characteristics, risks and focus areas, you will find recommended Devoteam’s Security Cubes. These cubes are focus areas that will help you address the potential risks and focus on what matters the most at each stage. You will find more information about our AI Cyber Trust Cube in the Secure AI, Sustainable Value whitepaper.
Stage 1: Exploration
- Initial experimentation

Initially, an isolated business unit tests AI without security oversight. Shadow AI initiatives, unknown data flows, and a lack of centralised inventory mark this phase. Organisations face risks such as regulatory exposure (e.g., GDPR violations) and data leakage. The focus at this point should be on launching a visibility campaign to understand AI usage and identify key risks related to data sensitivity and model exposure. Relevant Cyber Trust AI Cubes include Governance & Data Transparency and Security by Design.
- Emerging Awareness

As security teams become aware of these AI activities, they begin informal engagement. Traits of this sub-stage include scattered documentation, ad-hoc reviews, and a lack of shared standards. This leads to risks like misalignment between innovation and security, and unmanaged third-party models. Our recommendation at this stage? Establish a basic AI security playbook and map critical data paths and model locations. The relevant Cyber Trust AI Cubes are Observability and Regulatory Compliance.
Stage 2: Formalisation
- Policy Definition

In this stage, organisations move towards policy definition and governed visibility. AI-specific security policies and ownership structures start to emerge, with the first AI risk assessments, assigned stakeholders, and early threat models. However, organisations may still face inconsistent implementation and a lack of formal processes. The focus should be on defining roles across security, data science, and legal departments, and launching internal awareness and compliance campaigns. Relevant Cyber Trust AI Cubes include Multidisciplinary Coordination, Security by Design, and Regulatory Compliance.
- Governed Visibility

As organisations establish governed visibility, they begin to put in place initial monitoring and compliance controls for selected AI projects. This includes model registries and limited audit logs, with a model-centric governance approach. Risks at this stage include compliance gaps (e.g., with the AI Act) and a lack of incident response readiness. Organisations should implement continuous monitoring and model logging, and initiate readiness planning for AI-specific threats. The relevant Cyber Trust AI Cubes are Observability, Governance & Data Transparency, and Adversarial Resilience.
Stage 3: Integration
- Operational Embedding

This stage involves operational embedding and cross-functional maturity. At this stage, you have pushed your AI systems into production, with security woven into the MLOps lifecycle. Traits include risk management frameworks that include AI, and CI/CD pipelines with model testing. Organisations may face risks such as adversarial attacks on inference and inconsistent security coverage. The focus should be on strengthening SOC capabilities for AI and embedding threat modelling into MLOps pipelines. Relevant Cyber Trust AI Cubes are Security by Design, Observability, and Adversarial Resilience.
- Cross-functional Maturity

At the cross-functional maturity level, security, engineering, legal, and data teams work as a cohesive unit. This is characterised by shared dashboards, incident playbooks, and defined escalation paths. Risks include operational friction and delayed responses to novel AI threats. Organisations should create joint governance forums (e.g., AI Risk Councils) and implement AI-specific red teaming and backdoor testing. Relevant Cyber Trust AI Cubes are Multidisciplinary Coordination, Adversarial Resilience, and Innovation at Scale.
Stage 4: Excellence

At the Excellence stage, an organisation views the security of its artificial intelligence systems as a necessary element that sets it apart from competitors. The primary focus shifts towards ongoing adaptation to new threats, demonstrating a clear and measurable impact of security efforts, and establishing robust governance frameworks that will remain effective in the future.
They typically have a dedicated AI Security Office or an internal AI Agency, signifying a strong commitment and specialised expertise in this domain. Organisations’ capabilities at this stage are also sophisticated. They implement automated Governance, Risk, and Compliance (GRC) processes specifically tailored for AI systems. Furthermore, they conduct continuous adversarial testing to proactively identify and address vulnerabilities, and they have established efficient pipelines for adapting to evolving regulatory requirements.
At this stage, organisations achieve measurable resilience against threats, translating into a sustainable competitive advantage in the marketplace. AI security becomes a topic of importance at the highest levels of the organisation, with clear visibility and alignment at the board level.
The relevant Cyber Trust AI Cubes that are emphasised at this stage include all seven, highlighting the comprehensive nature of their security posture. However, there is a particular focus on “Innovation at Scale,” reflecting their ability to integrate security seamlessly into the development and deployment of AI at scale; “Regulatory Compliance,” underscoring their proactive approach to meeting evolving legal and ethical standards; and “Multidisciplinary Coordination,” emphasising the importance of collaboration across different teams to ensure holistic AI security.
Conclusions
This practical guide, together with our Secure AI and Sustainable Value whitepaper, will help you to position your organisation on its current journey to secure AI and chart a clear path to move forward with confidence.
And it’s definitely worth investing in moving forward – Gartner predicts that by 2026, organisations with comprehensive AI security programs will experience 76% fewer AI-related breaches compared to those using traditional security approaches for AI systems.
“This process is not about speed, it’s about direction and consistency. It’s an endurance race, not a speed race.”
At what stage is your organisation?
No matter where you are, Devoteam can help you strengthen your AI security maturity and adopt industry best practices. See how we helped other organisations like yours!
Secure AI, Sustainable Value: Your CISO’s Guide to AI Risk Management

Get your free Whitepaper if you want to:
- Learn to identify and manage unique AI security challenges
- Implement Devoteam’s AI Cyber Trust Cube – our framework for trusted and secure AI deployments
- Align AI with your organisation’s sustainability goals
- Gain insights from Devoteam’s leading AI security experts.

