Aug 20, 2026
Who Secures AI When It Touches Every Security Team?
Learn how organizations can develop relevant offensive knowledge across every security function responsible for AI systems.
An AI system may be tested by the red team, monitored by the SOC, secured by engineering, and investigated by incident response. Each team owns part of the risk, but no team sees the whole attack path alone.
That means AI security cannot be the responsibility of a small group of specialists. Organizations need to develop relevant offensive knowledge across every function responsible for how AI systems are built, operated, and defended.
Attackers do not approach systems according to internal team structures. They look for a weakness, determine what it gives them access to, and continue until they reach their objective.
Offensive thinking helps security teams view AI systems in the same connected way. It shows how an individual weakness could be exploited, which controls an attacker may try to evade, and what activity a successful attack could create elsewhere in the environment.
A shared attacker perspective makes offensive findings easier to act on. Engineers can test controls against realistic attacker behavior, detection teams can connect signals to likely objectives, and incident responders can reconstruct how an attacker moved between systems.
Offensive thinking does not turn every security professional into a red teamer. It gives each function the attacker perspective relevant to its responsibilities; and the skills required will differ by role.
The value changes depending on the decisions each role owns.
| Security Function | Value of Offensive Thinking |
| Security architecture | Identifies risky trust relationships, access paths, and design assumptions |
| Security engineering | Tests how controls behave when attackers evade or combine them |
| SOC and detection engineering | Connects isolated signals to attacker behavior and objectives |
| Threat hunting | Grounds hypotheses in plausible paths through the environment |
| Incident response | Reconstructs attack progression and identifies access that may remain active |
| Security leadership | Prioritizes investments based on the paths creating the greatest exposure |
Together, these perspectives give the organization a more complete view of AI risk. Testing identifies potential attack paths, engineering determines how controls respond, and defensive teams prepare to detect and contain the resulting activity.
That shared understanding also determines whether human oversight works when an AI system behaves unexpectedly.
Keeping a human in the loop only adds protection when that person understands what could go wrong.
Security professionals need to recognize when outputs may have been manipulated, when an AI-enabled action exceeds its intended scope, and when unusual behavior requires investigation. General AI awareness does not provide that level of judgment.
Teams need practical experience examining how AI systems behave under attack. Without it, human oversight can become an approval step performed without enough information to challenge the system. Developing that judgment requires more than AI awareness. It requires opportunities to apply security skills in practice.
Hiring a small number of AI security specialists cannot distribute this knowledge across every team that touches AI risk. Those specialists cannot make every architecture decision, investigate every alert, or support every incident.
Organizations need to develop AI security skills in the people already responsible for those decisions. That need is becoming increasingly visible: the 2025 ISC2 Cybersecurity Workforce Study found that 95% of cybersecurity professionals reported at least one skills gap on their team, while 41% identified AI as the most pressing gap.
The required depth will vary.
- A security architect may need to identify risky trust relationships around an AI application.
- A SOC analyst may need to recognize signs of model or data manipulation.
- A red team operator will need the advanced technical skills to assess and exploit AI systems directly.
A workforce development strategy should account for those differences. Clear development paths allow each employee to build the capabilities relevant to their role. Hands-on practice gives them experience applying those skills, while assessments confirm when they are ready to advance.
This creates AI security capability across the organization without expecting every employee to follow the same path or become the same type of specialist.
Developing AI security capability across the workforce also means building deeper expertise in the roles responsible for testing AI systems directly.
OffSec’s AI Red Teaming Upskill Program gives Learn Enterprise customers a structured path for developing that specialized talent internally.
The six-stage program takes learners from cybersecurity foundations to the AI Red Team Operator role. Guided learning builds the required knowledge in sequence, hands-on labs provide practical experience, and assessments validate readiness before learners advance.
It’s one example of how organizations can use structured workforce development to build specialized capabilities from within while giving employees clear paths to grow into the roles the business needs.