বাংলা E-Paper 📍 Dhaka 📅 Monday | 21 September 2026, 6 Ashswin 1433 PID registration number 06
HEADLINE

Who will watch AI when it is used for cybersecurity?

Published : Monday, 21 September, 2026 at 12:00 AM
Md. Nazmul Huda Masud
There was a time when the central question in cybersecurity was, “Who is trying to get into our system?” Today, the question has become more complicated: “How much can we trust the artificial intelligence to which we are entrusting our security?”

The use of Artificial Intelligence (AI) in cybersecurity is growing rapidly. AI is already playing an important role in analyzing suspicious logs, detecting abnormal behavior, identifying malware, preventing phishing attacks, and analyzing security alerts. In the future, AI-driven Security Operations Centers (SOCs) will be able to analyze enormous volumes of information more rapidly and identify potential threats in a fraction of the time required by humans.

But this creates a fundamental new question: If AI is the watchman of our cybersecurity, then who will watch the watchman? AI is not a magic box. It is a technological system built from data, models, algorithms, software, APIs, identities, and permissions. As a result, AI itself can become a target of attack.

Security researchers and organizations around the world are already working on emerging risks associated with AI-dependent systems. Recent OWASP security frameworks have identified risks such as Prompt Injection, Sensitive Information Disclosure, Supply Chain Vulnerabilities, Data and Model Poisoning, Excessive Agency, and weaknesses in Vectors and Embeddings.

In other words, we are asking AI to detect cyberattacks, while an attacker may attempt to influence the very decision-making process of that AI.

Consider an organization's AI-powered security system analyzing thousands of logs, emails, network traffic, and documents every day. If an attacker can inject information or instructions designed to confuse the AI, the system may make an incorrect decision. This is known as Prompt Injection or a related form of AI manipulation. OWASP research has also identified such attacks as significant risks.


An even greater risk may arise when AI does not merely provide “recommendations” but starts making decisions and taking actions on its own.

Today's AI chatbot might say, “This log appears suspicious.” But tomorrow's Agentic AI might say, “I have identified a suspicious user, restricted the account, isolated the associated device, and notified the Incident Response Team.”

The benefits are enormous, but so are the risks. If an AI Agent is given excessive authority and makes an incorrect decision, a relatively small mistake could cause significant operational disruption. This is precisely why OWASP has developed a dedicated Top 10 risk framework for Agentic Applications in 2026, highlighting risks such as goal manipulation, tool misuse, identity and privilege abuse, supply chain vulnerabilities, and unexpected code execution.

So, should we stop using AI?
Absolutely not. In fact, the opposite is true. We need to expand the use of AI in cybersecurity. However, “AI for Security” and “Security for AI” must advance together. If we entrust AI with the responsibility of protecting our systems, we must give equal importance to protecting AI itself.

First, the Identity and Access Management (IAM) of AI systems must be strengthened. No AI Agent should have more privileges than it actually needs. It should receive only the level of access required for its specific tasks. This is essentially an AI-based application of the Least Privilege principle. Second, AI decisions must not be blindly trusted in every situation. Particularly in areas such as national security, financial transactions, critical infrastructure, border control, and citizen identity systems, Human-in-the-Loop oversight is essential for critical decisions. Third, AI systems require dedicated AI Security Monitoring. It is not enough to use AI to monitor other systems. We must also monitor what the AI itself is doing, which data it is using, which APIs it is calling, what decisions it is making, and whether there are any abnormal changes in its behavior.

Fourth, AI data must be secured. Incorrect or deliberately manipulated data can influence AI decisions. Therefore, Training Data, Fine-tuning Data, Retrieval Data, Vector Databases, and the Model Supply Chain must all fall within the scope of cybersecurity controls. The issue is even more important for Bangladesh. The country is rapidly expanding digital services, online government systems, financial technology, biometric identity systems, smart infrastructure, and AI-based services. As a result, AI will not remain merely a supporting software tool in the future. It will increasingly become part of critical decision-making processes.

Global security research is moving in the same direction. The National Institute of Standards and Technology (NIST) in the United States has developed the AI Risk Management Framework for managing AI-related risks. In 2026, NIST has also been advancing work on a new Profile concerning Trustworthy AI in Critical Infrastructure. At the same time, NIST's Cyber AI Profile initiative seeks to address both cybersecurity risks created through the use of AI and the secure application of AI within a unified framework.

For Bangladesh, therefore, an important question must be raised now: We are adopting AI, but are we developing AI Security at the same pace?
Simply purchasing AI or deploying an AI-based security solution will not guarantee cybersecurity. What will be required is secure AI architecture, regular security testing, adversarial testing, access control, audit trails, model monitoring, data governance, and skilled personnel.

Most importantly, AI must never be regarded as an “infallible security guard.”Because AI can make mistakes. AI can be manipulated. AI's data can be compromised. AI's permissions can be abused. Even AI-dependent supply chains can become vulnerable. Therefore, the cybersecurity philosophy of the future should be: AI will watch over us, but AI must also be watched over.

The cybersecurity competition of the future will not simply be about who can build the most powerful AI. The real competition will be about who can build the most trustworthy, secure, controlled, and accountable AI system. The history of technology has taught us one important lesson: the more powerful a technology becomes, the greater the need for security. AI is no exception.

If we make AI the watchman of our digital fortress, then we must write one more question on the fortress gate:“If the watchman falls asleep, who will wake the watchman?” We need to find the answer to that question today. Because the cybersecurity battle of tomorrow may not simply be a battle between humans and AI. Instead, the most important battle may become a battle between trusted AI and insecure AI.

The writer is an engineer, Special Branch, Bangladesh Police and Joint Secretary, Bangladesh Computer Society


Loading...
Loading...
Editor : Iqbal Sobhan Chowdhury
Published by the Editor on behalf of the Observer Ltd. from Globe Printers, 24/A, New Eskaton Road, Ramna, Dhaka.
Editorial, News and Commercial Offices : Aziz Bhaban (2nd floor), 93, Motijheel C/A, Dhaka-1000.

Phone: PABX- 41053001-06; Advertisement: 41053012; 01793317829, 01550707291, E-mail: [email protected], ‍[email protected] Online: email: [email protected] 41053014; 01550707297 Advertisement: 01550707296
🔝
Advertisement