AIS Logo
← Back to Library
Securing Generative AI Systems: Threat-Centric Architectures and the Impact of Divergent EU–US Governance Regimes
(2026) AI Processed Human Approved

Securing Generative AI Systems:Threat-Centric Architectures and the Impact of Divergent EU–US Governance Regimes

Vijay Kanabar and Kalinka Kaloyanova
This study presents a threat-centric security analysis that maps adversarial techniques across a five-layer reference architecture for generative AI systems. The authors combine architectural decomposition and threat taxonomy mapping with a comparative analysis of EU and US governance frameworks to evaluate security controls. Problem Generative AI systems introduce security risks that fundamentally differ from traditional software due to probabilistic outputs, emergent failure modes, and expanded attack surfaces from tool and retrieval integration. Conventional perimeter-based and policy-only controls are insufficient because many GenAI vulnerabilities are structural rather than configurable. Outcome - High-impact generative AI risks are structural properties inherent to architectural design rather than isolated, patchable bugs.
- Effective risk mitigation requires a layered defense-in-depth model that combines traditional cybersecurity controls with AI-specific mechanisms such as context separation and tool sandboxing.
- Transatlantic regulatory divergence establishes EU frameworks as the de facto technical baseline for multinational deployments, driving global architectural convergence.
What it means for you
  • CIO / IT Executive: On Monday morning, initiate a review of the current generative AI system architecture and identify which of the five layers (e.g., prompt engineering, model, data, tools, infrastructure) represent the highest structural risk based on the research's threat taxonomy. Prioritize a pilot project to implement context separation and tool sandboxing for a critical generative AI application.
  • IT Manager: On Monday morning, schedule a team meeting to map the specific adversarial techniques identified in the research (e.g., prompt injection, data poisoning, model evasion) to the current generative AI tools and integrations in use. Document which of these techniques pose the most significant structural risk to your deployed systems.
  • Business Strategist: On Monday morning, begin researching the EU's AI Act and its implications for generative AI deployments. Identify how the research's findings on divergent EU-US governance regimes suggest that adopting EU-like technical security baselines will be crucial for global market access and competitive advantage.
  • Researcher: On Monday morning, focus on replicating the research's methodology by attempting to map a specific novel adversarial technique against a widely used generative AI reference architecture, documenting any emergent failure modes observed and comparing them to the research's findings.
  • Policymaker: On Monday morning, analyze the comparative governance analysis presented in the research, specifically focusing on how the EU's framework is driving global architectural convergence. Draft a memo outlining potential legislative actions to align US generative AI security regulations with the EU's technical baseline to foster transatlantic interoperability and responsible innovation.
Transcript
Host: Welcome to A.I.S. Insights — powered by Living Knowledge. I'm your host, Anna Ivy Summers. Today, we are exploring a crucial topic for any organization deploying artificial intelligence: how to properly secure Generative AI systems. We're looking at a landmark study titled "Securing Generative AI Systems: Threat-Centric Architectures and the Impact of Divergent EU–US Governance Regimes." Joining me to break this down is our lead analyst, Alex Ian Sutherland. Welcome, Alex.

Expert: Thanks, Anna. It's great to be here. This study provides a vital reality check for business leaders who think securing AI is just about applying traditional software firewalls or adding simple output guardrails.

Host: Let's start with the big problem. Most companies are rushing to integrate Generative AI—like chatbots, retrieval systems, and autonomous agents—into their core business operations. Why doesn't traditional cybersecurity work for these systems?

Expert: Traditional software security relies on predictable, deterministic code and clear boundaries between code and data. Generative AI flips that upside down. It processes natural language, which acts as both data and control instructions. That creates what the study calls structural vulnerabilities. For instance, the study points to real-world threats like "EchoLeak," a zero-click attack where malicious instructions hidden inside an incoming marketing email trick an enterprise AI assistant into accessing confidential internal data and exfiltrating it—all without the user ever clicking a link or noticing a thing.

Host: That sounds alarming. So how did the authors of the study approach analyzing these complex vulnerabilities?

Expert: The researchers decomposed Generative AI systems into a five-layer reference architecture—stretching from training pipelines and foundation model weights, down through retrieval mechanisms like RAG, orchestration tools and agents, all the way to runtime user interactions. They mapped established threat frameworks like OWASP and MITRE ATLAS against these layers, categorizing risks as either "configurable"—meaning you can fix them with access rules or policy settings—or "structural," which means they are baked into the core design of how models and tools interact.

Host: What were the major findings from this layered approach?

Expert: The primary finding is that high-impact AI risks are structural properties, not just isolated software bugs you can quickly patch. When an AI model is connected to external tools—like sending emails, querying databases, or executing code—it becomes a "confused deputy." An attacker can manipulate the model using indirect prompt injection to execute privileged actions on their behalf. You cannot solve this simply by filtering prompts at the perimeter.

Host: That makes sense. What about the governance side? How does the regulatory environment impact how businesses build these systems?

Expert: This is where the study highlights a critical strategic insight regarding transatlantic regulatory divergence. The European Union has implemented binding, prescriptive regulations like the EU AI Act and NIS2, requiring ex-ante risk assessments, strict documentation, and rapid incident reporting. Meanwhile, the United States relies primarily on voluntary frameworks like the NIST AI Risk Management Framework and sectoral enforcement.

Host: So if an enterprise operates globally, how do they navigate these two very different legal landscapes?

Expert: The study demonstrates that EU frameworks are effectively becoming the de facto global technical baseline for multinational deployments. Because EU regulations impose strict compliance and auditable evidence requirements, building to the EU standard naturally satisfies or exceeds US expectations. Organizations are adopting a "dual-track" strategy: maintaining a single, EU-aligned technical baseline globally, while tailoring legal reporting and governance locally.

Host: That is a huge takeaway for international enterprise strategy. What specific steps should business and technology leaders take based on these insights?

Expert: First, prioritize architectural controls over policy overlays. That means isolating data from instructions, enforcing strict least-privilege access for AI tools, and sandboxing code execution environments. Second, treat security assurance as an operational requirement rather than a one-time audit. Organizations need complete logging of the full causal chain—from prompt to retrieved document, tool call, and final output. Finally, bridge the internal skills gap by updating the secure development lifecycle and training developers, architects, and security operations teams on AI-native threat vectors.

Host: So to wrap it up: Generative AI security is an architectural engineering challenge, not a simple policy checklist. Designing to strict standards like the EU AI Act while embedding defense-in-depth across the entire system stack is the most resilient path forward.

Expert: Exactly right, Anna.

Host: Alex, thank you so much for breaking down this important study for us. And thank you to our listeners for tuning into A.I.S. Insights — powered by Living Knowledge. Join us next time as we continue to translate cutting-edge technology research into actionable business intelligence.
Generative AI Security, Cybersecurity Architecture, AI Governance, EU AI Act, NIST AI RMF, OWASP LLM Risks, MITRE ATLAS