THREATS OF ARTIFICIAL INTELLIGENCE TO INFORMATION SECURITY
Jasurbek Mirzabayev
University of Business and Science Information Security, Group 2501
Keywords: artificial intelligence, information security, cybersecurity, prompt injection, sensitive information, deepfake, data poisoning, artificial intelligence agents, security, human oversight.
Abstract
This article analyzes information security issues arising from the rapid development of artificial intelligence technologies. Today, artificial intelligence is widely used not only in such fields as education, healthcare, finance, and industry, but also in ensuring information security. At the same time, the improper or malicious use of these technologies is leading to the emergence of new types of threats. The article examines the main risks associated with artificial intelligence, including prompt injection, sensitive information disclosure, generation of inaccurate information, deepfake technology, data poisoning, excessive privileges granted to artificial intelligence agents, and system prompt leakage. The study emphasizes the importance of human oversight, data protection, access control, and independent verification of generated results when using artificial intelligence. In addition, the impact of artificial intelligence on information security is analyzed from the perspectives of both defensive and offensive capabilities. The results of the study demonstrate that artificial intelligence security cannot be limited to protecting the model itself. The data provided to the system, user permissions, external services, application programming interfaces, and human oversight are also integral components of a comprehensive security system.
References
National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. NIST AI 600-1, 2024.
2. National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST, 2023.
3. OWASP Foundation. OWASP Top 10 for Large Language Model Applications and Generative AI. 2025.
4. OWASP GenAI Security Project. LLM01:2025 – Prompt Injection.
5. OWASP GenAI Security Project. LLM02:2025 – Sensitive Information Disclosure.
6. OWASP GenAI Security Project. LLM06:2025 – Excessive Agency.
7. OWASP GenAI Security Project. LLM07:2025 – System Prompt Leakage.
8. National Institute of Standards and Technology. AI Risk Management Framework Resource Center.
9. Russell, S., & Norvig, P. Artificial Intelligence: A Modern Approach. Pearson.
10. Goodfellow, I., Bengio, Y., & C


