Estimated reading time: 5 minutes
This article was originally published in “Líder Magazine” in Portugal, click here for the Portuguese version.
When the first automobiles began to circulate, it was a revolution. Suddenly, people could travel faster and farther than ever before. But there was a critical detail: no traffic signs, no efficient brakes, no clear rules. The enthusiasm for this new technology was so great that safety came later — and at the cost of many accidents.
The problem: security as an optional accessory?
Today, we are experiencing a similar moment with Artificial Intelligence (AI). The technology is advancing at an astonishing pace, promising unprecedented gains in productivity and innovation. But there is a problem: many continue to treat cybersecurity as an optional accessory.
In the early 20th century we had cars without brakes, today we have AI systems running without any security control. On the digital road of AI, the impact of accidents can be global.

Rui Shantilal
Cyber Trust Vice President
The recent case of DeepSeek, a Chinese startup that publicly exposed databases containing sensitive information, is yet another reminder of AI’s fragility when security is neglected. Among the exposed data were user conversation histories, secret API keys, and backend service metadata. In an era where we increasingly rely on AI to make critical decisions, these errors equate to selling a car without brakes. All while expecting no one to get hurt.
The problem is not isolated. Many companies prioritise scalability and the performance of their AI models. But they ignore essential security measures such as data encryption, robust authentication, access segmentation, continuous monitoring, and protection against manipulation. But that alone is not enough.
Without a holistic approach that includes incident response, continuous auditing, and risk-based access control, AI systems remain exposed to a minefield of vulnerabilities:
- Chatbots can be manipulated to disclose sensitive data or generate harmful responses;
- Machine Learning models can be contaminated with manipulated data, leading them to provide incorrect or even dangerous information;
- Unsecured APIs can be exploited to steal proprietary models.
We should not be building a new digital era on fragile foundations. History has taught us that when you ignore security at the outset, the price to pay later is much higher.
Just as the automotive industry eventually adopted seat belts, airbags, and ABS, AI needs to integrate cybersecurity from the ground up. We cannot continue to treat security as an afterthought. All stakeholders—providers, consumers, creators, regulators, and users—have a fundamental role in this mindset shift.
Understanding these dangers is the first critical step. The next is to build a robust defence. Discover the structured approach your organisation can take by exploring our guide to AI Security Maturity, your path from risk to resilience.
What AI providers and AI users can do to guarantee security
AI providers must ensure a Security by Design and Zero Trust approach from conception, guaranteeing data encryption and API security. They must also conduct adversarial testing to detect vulnerabilities before attackers do, comply with international standards such as ISO 27001 and NIST CSF, and establish transparent security and data protection policies.
AI users, in turn, must assess risks before adopting new AI-based solutions, ensure compliance with regulations such as the GDPR, define clear rules for storing and deleting sensitive data, and implement AI techniques that preserve privacy—such as those that allow model training without centralizing sensitive data—and create governance structures to monitor data collection and usage.
The DeepSeek case reinforces a critical warning: innovation without security is a disaster waiting to happen. The industry must recognize that cybersecurity is not an obstacle but an essential pillar for AI sustainability.
Read our insights on strengthening AI security to match innovation to understand how to actively counter these risks and bolster your AI defences.
Regulators, such as the European Union, are already responding with stricter laws, such as the AI Act and the NIS2 Directive, but simply creating regulations is not enough; a broader shift in mindset is necessary to ensure that AI does not become a source of unpredictable risks. Companies that adopt security as a core principle now will better prepare themselves to lead this technological revolution responsibly and sustainably.
The choice is clear: either we integrate security into AI now. Or… we face a future filled with risks and avoidable crises. The difference between a car without brakes and a safe car is not the technology. It is the responsibility with which we apply it. AI should be no different.
If we are going to accelerate toward the future, let’s make sure the brakes are working properly.
Secure AI, Sustainable Value: Your CISO’s Guide to AI Risk Management

Get your free Whitepaper if you want to:
- Learn to identify and manage unique AI security challenges
- Implement Devoteam’s AI Cyber Trust Cube – our framework for trusted and secure AI deployments
- Align AI with your organisation’s sustainability goals
- Gain insights from Devoteam’s leading AI security experts.
