Your organization almost certainly uses more AI than your security team knows about. According to the Cloud Security Alliance, over half of enterprise generative AI adoption is shadow AI, and 89% of enterprise AI usage is invisible to security teams (CSA, 2026). IBM's 2025 Cost of a Data Breach Report found that one in five breached organizations suffered a breach involving shadow AI (IBM, 2025).
So the question isn't whether your AI governance covers your footprint. It's whether any of it would hold up against someone actively trying to break it.
Governance describes what should happen. It says nothing about what does.
The standard already expects more than paperwork
The US doesn't have a federal AI law. What it has is the NIST AI Risk Management Framework, and it doesn't stop at documentation. The framework's Measure function calls for testing, evaluation, validation, and verification of AI systems across their lifecycle: not just whether risks were identified on paper, but whether the system behaves safely under real conditions. A policy binder doesn't satisfy it. Test results do.
This is the same gap Lares has written about in every other domain: compliance measures whether controls are documented, while attackers measure whether they work. AI is simply the newest place where that gap opens up, and it's opening fast because adoption is outpacing every governance process built to contain it.
And the pressure isn't waiting on Congress. Cyber insurers are asking how AI risk gets validated. Enterprise customers are writing AI security requirements into contracts. Boards are asking what happens when the AI does something nobody predicted. Every one of those conversations ends at the same place: show me the evidence.
What adversarial AI testing actually covers
AI systems fail in ways that don't look like traditional software vulnerabilities, which is why traditional testing misses them. When Lares tests an AI deployment adversarially, the team attacks it the way a real adversary would, working from the failure modes catalogued in the OWASP LLM Top 10, the OWASP Top 10 for MCP, and the OWASP Top 10 for Agentic Applications:
Instruction manipulation. Direct prompt injection overrides what the model was told to do. Indirect prompt injection poisons the context the model reads: a retrieved document, a webpage, an email in the inbox it's summarizing. The model follows attacker objectives while appearing to follow yours.
Tool and permission abuse. Modern agents send email, query databases, and call internal APIs. Excessive agency paired with over-scoped permissions turns a helpful assistant into a confused deputy: an insider that follows instructions perfectly, just not yours.
Data extraction. Models trained on or connected to sensitive data can be coaxed into revealing it, one carefully phrased question at a time. Training data, RAG context, conversation memory. All of it is in scope.
None of this surfaces in a governance review. It surfaces when someone deliberately tries to break the system. The frameworks exist. What's missing in most organizations is the evidence that their own deployments survive them.
The Adversarial AI Assessment
Lares runs this as a structured assessment in three tiers. Enter at whichever matches your maturity:
- AI Footprint Discovery. Before you can secure your AI, you have to find all of it, including the shadow AI your governance doesn't know about. Deliberate, expert-led reconnaissance, not scan output. The gap that matters is the one a scanner can't see.
- Adversarial AI Testing. Hands-on testing against real attack techniques: prompt manipulation, agent tool abuse, data extraction. Findings map to NIST AI RMF and the OWASP frameworks, with MITRE ATLAS as the technique layer. The output isn't a list of theoretical risks. It's evidence of what an attacker could actually do, mapped to the defenses that stopped them and the ones that didn't.
- AI Retesting Cadence. Models change, integrations change, data connections change. A one-time test goes stale fast. The retesting cadence keeps validation continuous so the evidence stays current as the footprint evolves.
The throughline is the same principle behind everything Lares does: don't tell us your controls work. Show us, under realistic attack conditions, with your team involved in closing what we find.
If your organization has AI governance in place but has never tested what its AI systems actually do under attack, that's the gap to close first.
Meet with Lares to scope an Adversarial AI Assessment.
Sources
- Cloud Security Alliance, Shadow AI Apps: The Enterprise Attack Surface That Outpaces Monitoring (2026)
- IBM, Cost of a Data Breach Report 2025 (2025)
- NIST, AI Risk Management Framework 1.0 (2023)
- OWASP GenAI Security Project, OWASP Top 10 for Agentic Applications for 2026 (2025)
Related Article

Empowering Organizations to Maximize Their Security Potential.
Lares is a security consulting firm that helps companies secure electronic, physical, intellectual, and financial assets through a unique blend of assessment, testing, and coaching since 2008.
18+ Years
In business
600+
Customers worldwide
4,500+
Engagements