How AIDR Helps Organizations Secure Generative AI

AI Detection and Response (AIDR) Explained

Key Takeaways

  • AIDR is detection and response pointed at the AI layer, meaning the tools staff use, the prompts and data moving through them and the agents acting with real credentials.
  • OWASP published its 2026 Top 10 for LLM Applications on 3 August 2026. Prompt injection stayed at number one and excessive agency rose from sixth to third.
  • IBM’s 2026 Cost of a Data Breach report found more than 20% of organisations had a breach targeting their own AI models or applications, most often through compromised APIs, applications or plug-ins and cloud misconfigurations at 27% each.
  • 68% of breached organisations had no process to govern AI use or detect shadow AI, and only 38% required IT approval before an AI tool was deployed.
  • EU AI Act penalties have applied since 2 August 2025. Most breaches, including the Article 50 transparency duties, sit at up to EUR 15 million or 3% of worldwide turnover.
  • AIDR does not replace MDR. The question is coverage of a layer that endpoint and identity monitoring were never built to see.

The Coverage Gap Most Teams Think They Have Already Closed

In a 2025 Enterprise Strategy Group survey, 74% of IT and security professionals said their existing managed detection and response provider could meet their AI security needs. In the twelve months to February 2026, IBM’s Cost of a Data Breach study found more than one in five breached organisations had an incident targeting their own AI models or applications.

Both can hold at once, and that is the problem. AI detection and response, or AIDR, exists because the layer where AI fails sits outside what most monitoring contracts cover. If your people use copilots, or anything in your estate can act on its own, this is your question.

The reason is a shift in what enterprise AI is. Two years ago it was a chat window, and the risk was an employee pasting customer data into a public model. What changed is that AI became something that acts, holding credentials and moving data between systems.

What is AIDR?

AI detection and response, usually shortened to AIDR, is the practice of monitoring and responding to security events in an organisation’s AI layer. That layer covers the AI tools staff use, the prompts and data passing through them, the models the organisation runs and the agents acting on its systems with real credentials.

Be clear about what that is not. AIDR is not a better model, a policy document or a governance exercise. Governance says what should be true. Detection and response says what is happening now.

The category does have a shared vocabulary behind it, which matters when you assess vendor claims. OWASP’s Top 10 for LLM Applications, whose 2026 edition was published on 3 August 2026, ranks the risks and maps them to NIST, MITRE ATLAS and CWE. A companion list for agentic applications followed in December 2025.

The Dates That Matter

2 Aug 2025EU AI Act penalties became applicable.
15 Jan 2026Cybersäkerhetslagen (SFS 2025:1506) brought NIS2 into Swedish law.
1 Jul 2026Sweden’s cyber operations moved from MCF (formerly MSB) to NCSC.
27 Jul 2026The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force.
2 Aug 2026Article 50 transparency obligations applied to new systems.
2 Dec 2026Systems already on the market must mark AI-generated content.
2 Dec 2027Annex III high-risk obligations apply, deferred from 2 August 2026.

Who Needs an AI Security Layer

Scope this by exposure rather than by headcount. The question is how much reach the AI already in your environment has, and whether anyone can see what it does.

Three tests are usually enough. Can you list the AI tools and accounts your staff used this week, including the ones IT never approved? Does any of them hold credentials reaching mail, files, source code or a customer system? Can you reconstruct afterwards what an assistant read and then did?

The comparison people reach for is AI detection and response versus MDR, and it is the wrong shape. MDR watches endpoints, identities, networks and cloud workloads, and this is not an argument against it. MDR sees a process starting. It does not see the instruction that caused it.

Where the AI Layer Bites First

  • Copilots and Assistants : Anything reading mail, files and chat inherits the reach of its user.
  • Coding Agents : Repository and pipeline access turns one bad instruction into committed code.
  • Customer-Facing Bots : Untrusted input arrives by design, so injection is an operating condition.
  • Unsanctioned Tools : Accounts opened on a personal card sit outside every control you have paid for.

The Three Failure Modes Your Existing Monitoring Misses

Shadow AI, prompt injection and hijacked agents are the three that matter for most organisations. One is a governance failure, one is a design property of language models and one is an access-control failure.

Shadow AI and the Data Exits Nobody Approved

Shadow AI is the use of AI tools and accounts that IT and security never sanctioned. It resembles the shadow IT wave of the 2010s with one difference. A file-sharing account stores your data. An AI tool processes it.

The governance picture went backwards in 2026. IBM found 68% of breached organisations had no process to govern AI use or detect shadow AI, up from 63%, while the share requiring IT approval before deploying a tool fell from 45% to 38%. The share of studied breaches involving shadow AI doubled, from 20% to 43%.

Prompt Injection and the Instruction You Did Not Write

Prompt injection is the delivery of attacker instructions through content a model reads. It works because a language model takes instructions and data through the same channel and cannot reliably tell them apart. OWASP has kept it at number one across editions and states that it is unclear whether fool-proof prevention exists, which is why the controls have to sit around the model.

EchoLeak in Microsoft 365 Copilot

In June 2025 a vulnerability in Microsoft 365 Copilot, tracked as CVE-2025-32711 and rated 9.3, showed what indirect injection looks like in production. One crafted email was enough and the user never clicked anything. When Copilot later drew that email into context, hidden instructions inside it directed the assistant to pull internal content and send it out.

Microsoft called it AI command injection allowing an unauthorised attacker to disclose information over a network, fixed it server-side and reported no exploitation in the wild. The lesson survives the patch. The payload was ordinary text with no malware signature.

Agent Hijack and Excessive Agency

Agent hijack is the plain-English name for what OWASP calls excessive agency. An agent holds permissions, calls tools and chains steps together without a human confirming each one, so an attacker who controls its instructions inherits that reach. The 2026 OWASP ranking moved excessive agency from sixth to third, weighting practitioner consensus at 75% alongside analysis of 6,639 documented incidents at 25%.

GTG-1002 and the Agent That Ran the Intrusion

In November 2025 Anthropic disclosed a campaign detected two months earlier and attributed with high confidence to a Chinese state-sponsored group it tracks as GTG-1002. The operators posed as a security firm running authorised testing, then drove Claude Code against roughly thirty targets across technology, finance, chemical manufacturing and government. Anthropic reported the AI executed 80 to 90% of tactical operations and that a small number of intrusions succeeded.

The account rests on the vendor’s own disclosure with no independent validation published, so treat the detail with caution. Whoever controls an agent’s instructions controls a capable operator.

What Getting This Wrong Costs

EU AI Act penalties have applied since 2 August 2025, and Article 99 sets three tiers by obligation rather than by harm. The figure quoted most often in board papers, EUR 35 million or 7% of worldwide annual turnover, applies only to the prohibited practices in Article 5. Applying it to a transparency or high-risk failure is the commonest error in AI Act commentary. Those sit at EUR 15 million or 3%.

The Swedish overlay is separate and already live. Cybersäkerhetslagen (SFS 2025:1506) brought NIS2 into Swedish law on 15 January 2026 with no transition period, and its duties attach to the network and information systems an entity uses. An AI assistant wired into mail and file storage sits inside that perimeter. Since 1 July 2026 significant incidents go to Nationellt cybersäkerhetscenter.

For most organisations the unregulated cost is larger. IBM put AI-enabled breaches at an average of USD 6 million against a global average of USD 4.99 million.

The Penalty Bands in One Place

Each cap is the higher of the fixed sum and the percentage. SMEs and start-ups take the lower.

  • AI Act Article 5 prohibited practices: up to EUR 35 million or 7% of worldwide annual turnover
  • Most other AI Act breaches, including Article 50 transparency: up to EUR 15 million or 3%
  • Incorrect or misleading information to authorities: up to EUR 7.5 million or 1%
  • NIS2 essential entities under Cybersäkerhetslagen: up to EUR 10 million or 2% of global turnover

What to Do Before You Buy Anything

Start with discovery, because you cannot govern an inventory you do not have. Identity logs show which AI services staff signed into, expense data shows which subscriptions were bought outside procurement and proxy logs show where traffic goes.

Then map reach rather than usage. For every AI tool and agent on the list, record what data it can read, which systems it can write to and whose credentials it uses. A little-used tool with broad access is a bigger problem than a popular one that reads nothing sensitive.

Only then decide what to buy. Ask which OWASP categories a provider detects, what an alert looks like when an agent is manipulated mid-task, and what gets blocked rather than logged. A provider who cannot show the difference between an AI event and an endpoint event is selling you what you have.

How to Keep AI Use Governed

In 2026 the NSA, the UK National Cyber Security Centre, the Canadian Centre for Cyber Security and New Zealand’s NCSC issued joint guidance on securing agentic AI. Model-level safeguards are not enough on their own, and agentic systems should be assumed capable of behaving unexpectedly.

Their control set translates into operational work. Restrict what agents can reach, especially sensitive data and critical systems. Scope credentials to the task rather than to the user. Keep a human in the loop for consequential actions. Sandbox agents that read untrusted input. Keep a way to shut an agent down, and test it.

Apply this proportionately to the autonomy a system actually has, and make approval faster rather than heavier, because slow approval is what creates shadow AI.

Where This Leaves You

AIDR does not replace the monitoring you already run. It covers a layer that endpoint, identity and network tooling were not built to see, and the evidence that this layer is under attack is on the public record.

Do the discovery first. List the AI tools, accounts and agents in your environment this month with the data each can reach, then take that list to your existing provider.

Frequently Asked Questions

What is AIDR?

AIDR stands for AI detection and response. It is the practice of monitoring and responding to security events in an organisation’s AI layer, covering the tools staff use, the prompts and data moving through them, the models it runs and the agents acting with real credentials.

Do I need AI security tooling if I already have MDR?

It depends on reach rather than on AI maturity. If an AI tool in your estate holds credentials that touch mail, files, code or customer data, and nobody can reconstruct what it read and then did, you have an unmonitored layer that MDR was not built to see.

What is the difference between AIDR and MDR?

MDR watches endpoints, identities, networks and cloud workloads, then escalates what it finds. AIDR watches the AI layer, meaning prompts, models, AI data flows and agent actions. MDR sees a process start. AIDR is aimed at the instruction behind it and what the agent did next.

Does the EU AI Act require us to monitor AI use?

Not as a single monitoring duty. The Act sets obligations by role and risk class, with Article 50 transparency applying to new systems from 2 August 2026 and standalone high-risk obligations deferred to 2 December 2027. Penalties have applied since 2 August 2025.

We have not approved any AI tools. Do we still have shadow AI?

Almost certainly, because shadow AI is unsanctioned use and it grows where approval is slow or absent. IBM found 68% of breached organisations had no process to govern AI use or detect shadow AI, and the share of studied breaches involving it doubled in a year.

eBuilder Security offers AI Detection and Response as a managed service. The AI Detection and Response service page sets out what the service covers.

This post is also available in: Svenska