Framework
Google Secure AI Framework (SAIF)
Un marco conceptual de Google para proteger sistemas de IA a lo largo de su ciclo de vida, basado en seis elementos fundamentales que extienden principios de seguridad conocidos al dominio de la IA.
Lectura práctica
Un marco conceptual de Google para proteger sistemas de IA a lo largo de su ciclo de vida, basado en seis elementos fundamentales que extienden principios de seguridad conocidos al dominio de la IA.
Google’s Secure AI Framework (SAIF) provides a practical, principle-based approach to AI security grounded in Google’s experience deploying AI at scale. It is designed to be adopted incrementally and to complement existing security programmes.
Six core elements
| Element | Principle | Practical implication |
|---|---|---|
| 1. Expand strong security foundations to the AI ecosystem | Apply existing security controls to AI: access management, data protection, network security | Don’t reinvent security — extend what already works |
| 2. Extend detection and response to AI | Incorporate AI-specific threats into detection engineering and incident response playbooks | Prompt injection, model exfiltration, and poisoned training data need dedicated detection patterns |
| 3. Automate defences to keep pace with attacks | Use AI itself to scale threat detection, response, and remediation | AI-powered security operations centre (SOC) for AI-powered threats |
| 4. Harmonise platform-level controls | Centralise security policy and enforcement across AI tools, frameworks, and deployment environments | Consistent controls across Vertex AI, custom deployments, and third-party models |
| 5. Adapt controls to adjust mitigations | Continuously tune AI-specific controls based on observed threats and changing model behaviour | Feedback loops from incidents to control improvement |
| 6. Contextualise AI system risks in surrounding business processes | Evaluate AI risk within the broader enterprise risk framework, not as a standalone concern | AI security decisions informed by business impact, data classification, and regulatory obligations |
ATLAS connection
SAIF’s six elements align with ATLAS controls: strong foundations map to SSO/MFA and approved tool registers; detection and response connect to logging, monitoring, and the incident response pipeline; platform-level controls correspond to standardised tool access; and contextualisation reinforces the ATLAS principle that AI risk is operational risk, not a separate domain.