The adoption of artificial intelligence in enterprise settings brings significant business value but also generates new information security and data protection challenges. Many Hungarian organisations have an AI strategy, yet practical experience shows that several risks only become visible during actual deployment and use. Based on international and local experience, Atos presents a five-level maturity model that describes the security challenges and the technical, organisational and governance measures needed at each stage.
1. Ad Hoc level
The lowest maturity stage is ad hoc AI usage, where AI-based tools and services appear across different parts of the organisation but are not integrated into corporate processes. Isolated solutions typically do not connect to central monitoring, logging or access control systems, and often do not communicate with each other. Employees may start using AI tools on their own initiative and without controls — a phenomenon known as "Shadow AI."
At this stage the organisation has limited visibility into data movement, processing and how AI-generated outputs are used. Common deficiencies include lack of identity and access management, logging, monitoring and data protection controls. Completely eliminating Shadow AI is practically impossible because employees can circumvent corporate controls using personal devices or freely available services.
The primary task at this level is to create an organisational culture that encourages safe and governed AI use. Increasing visibility into AI usage and removing ad hoc practices as soon as possible are key objectives.
Sándor Dénes, AI expert at Atos Hungary, notes that many domestic small and medium-sized enterprises experiment with AI systems but often fall short of expectations because the solutions do not fit existing systems. In many cases Shadow AI becomes institutionalised, and surveys frequently reveal surprise that data collection was happening at all.
2. Discovery level
In the Discovery phase the organisation consciously maps its AI landscape: it inventories the AI tools and services in use and reveals connections, dependencies and data flows. AI systems are integrated into corporate monitoring and telemetry infrastructure, allowing visibility into which resources they use, which systems they access, who uses them and with what privileges.
This stage starts the creation of baselines — recorded patterns of normal operation — which form the basis for later anomaly detection. Security focus shifts to protecting integrations, managing API access, controlling backend privileges, and regulating write and modification rights. The key outcome of Discovery is that the organisation can measure and understand AI behaviour, not just deploy it.
3. Governance level
At the Governance level the organisation has an AI strategy, a regulatory framework and clearly defined responsibilities. Policies for AI use appear, alongside role and responsibility definitions (RACI), auditable processes, and concrete access, logging and monitoring requirements.
Many organisations feel they have reached the desired security posture at this point. In reality, AI-specific threats often become particularly relevant at this stage — for example prompt injection. A document, PDF or data source may contain hidden instructions that the model interprets as executable directives rather than mere data, potentially causing the AI to perform actions not intended by the user.
Defences include prompt hardening, separation of instructions and data, restricting and controlling tool calls (tool gating), output validation, and human-in-the-loop approval points. At this level the emphasis is on controlling AI behaviour rather than only regulating its use.
As the expert points out: it is not uncommon for a seemingly legitimate document to contain hidden instructions that prompt an AI agent to request or modify data within its privileges but against the user’s intent. Preventing such incidents requires strict input separation, appropriate tool controls and human approval processes.
4. Detection level
Reaching the Detection level means the organisation has sufficient historic data and operational experience to automatically recognise deviations from normal behaviour. Using previously established baselines, it can identify anomalous usage patterns, unusual resource consumption, suspicious AI-agent behaviour, prompt injection attempts and privilege anomalies.
At this stage mere rules are no longer enough: operations must be continuously monitored, interpreted and, when necessary, managed. Malicious or faulty behaviour can cause significant business risk, including data leakage, reputational damage, excessive resource consumption or disruption of critical business processes. These risks already exist at lower maturity levels but can reach a magnitude at Detection that justifies proactive detection and rapid-response capabilities.
5. Enforcement level
The highest maturity stage is Enforcement, where the organisation not only monitors and analyses behaviour but can dynamically intervene and enforce compliance with security policies. Intent-Based Access Control (IBAC) plays a central role: it goes beyond traditional role-based access control by evaluating not just whether an entity has permissions but whether the requested action is justified by the current business intent and task.
IBAC enables verification that an AI is performing the intended business task, using only necessary data, employing only required tools and privileges, and avoiding unauthorised access or data exfiltration. The goal of Enforcement is to enable automatic prevention and mitigation of risks, representing the most mature and resilient AI-security operating model.
Hernádi József, CEO of Atos Hungary, emphasises: “It is important to stress that AI security is not a single-technology issue. Developing an AI strategy or deploying a few protective tools is not sufficient. AI security is a multi-layered, system-level risk area that can only be effectively managed by considering the entire IT, data handling and governance environment.”
Conclusion
Atos’s model illustrates that developing AI security is a stepwise process: each maturity level introduces new visibility, control and detection requirements. The objective is to move from an initial ad hoc environment to an operating model with dynamic rule enforcement and business-context-aware controls where risks are prevented and handled automatically.



