Learn how we use AI responsibly across our business and cybersecurity services.
AI is having a profound effect on organisations of all types and doing so at a dizzying pace. Furthermore, AI is redefining cybersecurity. It is transforming how attackers and defenders fundamentally operate, and how organisations across the globe protect themselves. AI-powered tools and workflows are amplifying threats but also defensive capabilities, changing the speed, scale, and sophistication of cyber operations from both sides.
Threat actors are using AI to move faster and scale operations.
Defenders must also take full advantage of AI. However, we must absolutely avoid inadvertently introducing additional vulnerabilities or compromising the overall integrity and quality of security efforts.
The disruptive nature of AI and the speed of its advancement have brought chaotic noise, persistent myths, and both radical over‑adoption and paralysing conservatism amongst cybersecurity operators, leading to a harmful neglect of rigorous implementation and governance best practices. It is important for us to clearly explain the foundational principles underlying how we use AI at CSIS.
At CSIS, the way we use AI is built on a single, uncompromising promise:
This promise applies to all our services, capabilities, functions and teams.
AI outputs can be plausible but wrong and they are subject to bias. An unverified error can have serious security, financial, and reputational impact.
Human governance is needed to enforce data classification, decide what can/cannot be processed by AI, and ensure regulatory (e.g. GDPR) and contractual obligations are met.
AI models are not liable for their outputs. People and organisations are. Decisions about risk tolerance, incident handling, data processing, and reporting must be traceable and justifiable.
Strong human governance ensures our AI use does not create a supply-chain risk vector for our clients and preserves the integrity of our Information Security Management System, asset management, and third-party risk controls.
Some activities we undertake (e.g., advising clients, communicating sensitive intelligence, coordinating responses to breaches) involve the application of ethical considerations and contextual judgement that AI cannot reliably perform on its own.
AI is in its infancy, and humans must be accountable for the inevitable learnings and improvements stemming from early-stage implementations.
Our AI promise is anchored with the following foundational principles:
We use AI as an enabler for human expertise – not as a replacement. For example, AI assists in collection, correlation, enrichment, rule generation, and research drafting, so analysts concentrate on the aspects that requires human judgment. As such, all outputs (e.g. deployments, reports, recommendations, etc.) are always verified and owned by a human.
AI has the same governance and oversight applied to it as every other tool in our stack. Every AI enabled workflow and agent action is logged and held to the same standards as any other data. AI outputs summarise visible evidence, not hidden reasoning — analysts must always be able to verify, override, and explain each step of its implementation.
Security is paramount. Everything that reaches our AI systems is treated as untrusted and agent workflows are designed to resist prompt injection by keeping tool access constrained and instructions separated from data. We test our own AI workflows adversarially on a recurring basis and hold AI model providers to the same supply chain security standards as any other vendor. We do not run unrestricted AI agents against client systems, and AI cannot define or change the agreed scope of any engagement.
AI is tooling — every deployment meets the same engineering, security, and governance standards as everything else in our stack, with no separate rules or accountability structures. Every AI capability affecting security decisions has a named owner, a documented risk assessment revisited whenever conditions change materially and is evaluated against representative data before going near production. When an AI workflow produces a harmful or erroneous output, we have a defined response: severity classification, a named owner, and a customer notification obligation where warranted.
Your data stays in Europe for both storage and processing — we never train foundation models on your raw data, and while anonymised aggregated data may inform detection logic improvements, your raw intelligence is never shared. We prefer open-weight models on European infrastructure, and where we use non-European foundation models they must have demonstrable EU data residency and be explicitly covered in our DPAs. We also do not rely on a single AI solution, rather we leverage diverse AI infrastructure that encompasses numerous models and agents delivering appropriate resource management, risk mitigation, and cross validations.
The principles explained here enable us to embrace the transformative power of AI without compromising the human expertise that underpin our services and our focus on the quality and integrity of security.
Progressive but responsible use of technology that enhances human capabilities has always been the foundation of our work, and AI has not changed this approach.
We will continue to harness technological advancements to ensure we deliver the highest quality cybersecurity and intelligence services to keep our customers protected from evolving cyber threats.