Rising to the GenAI security challenge

Don’t expect the hype merchants to solve the problems they create

Steve Jones
2 min readApr 17, 2024

Great to see Privacera announce a governance and security solution for GenAI, particularly focused on the wonder that is Vector Databases and therefore their use within RAG and other GenAI solution approaches.

One of the reasons I think this is super important is that I just don’t see the hype merchants who are selling the core models actually addressing these sorts of things. There is an awful lot of “we will solve world hunger” without either solving world hunger, or addressing the systemic problems that GenAI can introduce into an enterprise. The hype might get people excited, but irresponsible hype that isn’t backed by enterprise grade governance that protects the business is not going to end well.

Two of the things I’m particularly glad to see in this announcement are the introduction of fine-grained access control, and the classification filtering and privacy controls they are adding to Vector databases. This is something that I really think is required as we look to zero-trust LLM approaches

So as you look to build your team around your GenAI solution, that means thinking about what is being done to manage all of this information in the different ways it needs to be represented for transactional, analytical and AI execution. The idea of “only one copy” of data has long since gone away, so having a security and governance approach that recognizes that reality is essential.

You need a team, don’t rely on the model

At the heart of this is the need to build a team around your AIs and start preparing for a world where AI to AI collaboration will be making a large number of decisions in your business, and that as with most other areas of security, it isn’t a great idea to trust the core of the solution to manage all of those security and trust aspects, particularly when the challenge can be spread, as with data security and control.

Privacera are clearly staking out their role as part of the team that governs GenAI.

A sleek athletic robot checks a list in front of a much larger, less athletic, robot, indicating protection of the latter by the former,

--

--

My job is to make exciting technology dull, because dull means it works. All opinions my own.