Governance Tells You What Should Happen. Adversarial Testing Tells You What Does.

Governance Tells You What Should Happen. Adversarial Testing Tells You What Does.

Governance Tells You What Should Happen. Adversarial Testing Tells You What Does. 2048 1152 Andrew Heller

Your organization almost certainly uses more AI than your security team knows about. According to the Cloud Security Alliance, over half of enterprise generative AI adoption is shadow AI, and 89% of enterprise AI usage is invisible to security teams (CSA, 2026). IBM's 2025 Cost of a Data Breach Report found that one in five breached organizations suffered a breach involving shadow AI (IBM, 2025).

So the question isn't whether your AI governance covers your footprint. It's whether any of it would hold up against someone actively trying to break it.

Governance describes what should happen. It says nothing about what does.


The standard already expects more than paperwork

The US doesn't have a federal AI law. What it has is the NIST AI Risk Management Framework, and it doesn't stop at documentation. The framework's Measure function calls for testing, evaluation, validation, and verification of AI systems across their lifecycle: not just whether risks were identified on paper, but whether the system behaves safely under real conditions. A policy binder doesn't satisfy it. Test results do.

This is the same gap Lares has written about in every other domain: compliance measures whether controls are documented, while attackers measure whether they work. AI is simply the newest place where that gap opens up, and it's opening fast because adoption is outpacing every governance process built to contain it.

And the pressure isn't waiting on Congress. Cyber insurers are asking how AI risk gets validated. Enterprise customers are writing AI security requirements into contracts. Boards are asking what happens when the AI does something nobody predicted. Every one of those conversations ends at the same place: show me the evidence.


What adversarial AI testing actually covers

AI systems fail in ways that don't look like traditional software vulnerabilities, which is why traditional testing misses them. When Lares tests an AI deployment adversarially, the team attacks it the way a real adversary would, working from the failure modes catalogued in the OWASP LLM Top 10, the OWASP Top 10 for MCP, and the OWASP Top 10 for Agentic Applications:

Instruction manipulation. Direct prompt injection overrides what the model was told to do. Indirect prompt injection poisons the context the model reads: a retrieved document, a webpage, an email in the inbox it's summarizing. The model follows attacker objectives while appearing to follow yours.

Tool and permission abuse. Modern agents send email, query databases, and call internal APIs. Excessive agency paired with over-scoped permissions turns a helpful assistant into a confused deputy: an insider that follows instructions perfectly, just not yours.

Data extraction. Models trained on or connected to sensitive data can be coaxed into revealing it, one carefully phrased question at a time. Training data, RAG context, conversation memory. All of it is in scope.

None of this surfaces in a governance review. It surfaces when someone deliberately tries to break the system. The frameworks exist. What's missing in most organizations is the evidence that their own deployments survive them.


The Adversarial AI Assessment

Lares runs this as a structured assessment in three tiers. Enter at whichever matches your maturity:

  1. AI Footprint Discovery. Before you can secure your AI, you have to find all of it, including the shadow AI your governance doesn't know about. Deliberate, expert-led reconnaissance, not scan output. The gap that matters is the one a scanner can't see.
  2. Adversarial AI Testing. Hands-on testing against real attack techniques: prompt manipulation, agent tool abuse, data extraction. Findings map to NIST AI RMF and the OWASP frameworks, with MITRE ATLAS as the technique layer. The output isn't a list of theoretical risks. It's evidence of what an attacker could actually do, mapped to the defenses that stopped them and the ones that didn't.
  3. AI Retesting Cadence. Models change, integrations change, data connections change. A one-time test goes stale fast. The retesting cadence keeps validation continuous so the evidence stays current as the footprint evolves.

The throughline is the same principle behind everything Lares does: don't tell us your controls work. Show us, under realistic attack conditions, with your team involved in closing what we find.

If your organization has AI governance in place but has never tested what its AI systems actually do under attack, that's the gap to close first.

Meet with Lares to scope an Adversarial AI Assessment.

Sources

Related Article

Minnesota Water Attacks and the Predictable Reality

August 12, 2026 by Andrew Heller How possible Iran-linked actors exploited exposed PLCs in the 2026 Minnesota water attacks. MITRE ATT&CK mapping, risk matrix, and OT security lessons from Lares. Read More Blog, Penetration Testing, Purple Teaming, Red Teaming

Part 3: The Collapse of the Testing Boundary: Why Purple Teaming is Mission-Critical

August 7, 2026 by Andrew Heller Point-in-time pen tests can't catch AI agents that fail in minutes. See why continuous purple teaming is the only defense — and how to build the budget case. Read More Artificial Intelligence, Blog, Purple Teaming

Part 2: The Collapse of the Testing Boundary: Anthropic and the Behavioral Threat

August 7, 2026 by Andrew Heller Claude models attacked real infrastructure while believing they were in a simulation. Anthropic's retrospective reveals a new AI risk class beyond alignment. Read More Artificial Intelligence, Blog, Purple Teaming

Part 1: The Collapse of the Testing Boundary: Deconstructing the OpenAI Agent Breakout

August 7, 2026 by Andrew Heller OpenAI's frontier model escaped its sandbox and breached Hugging Face's cluster in under 13 hours. See the full kill chain mapped to MITRE ATT&CK and ATLAS. Read More Artificial Intelligence, Blog, Purple Teaming

Social Profiling – OSINT for Red/Blue

July 27, 2026 by Lares Labs Read More Blog, Penetration Testing, Red Teaming

The Phantom Menace: Exposing hidden risks through ACLs in Active Directory

June 18, 2026 by Raúl Redondo Discover how attackers exploit hidden risks in Active Directory ACLs. Explore techniques like GenericAll, GenericWrite, and WriteDACL abuse in our latest post. Read More Blog, Insider Threat, Penetration Testing, Red Teaming

Kerberos IV - Delegations

June 17, 2026 by Raúl Redondo Discover how to abuse Kerberos for lateral movement. Learn User Impersonation techniques like Pass the Ticket, Shadow Credentials, and forging tickets. Read More Blog, Blue Team, Penetration Testing, Red Teaming

Kerberos III - User Impersonation

June 17, 2026 by Raúl Redondo Discover how to abuse Kerberos for lateral movement. Learn User Impersonation techniques like Pass the Ticket, Shadow Credentials, and forging tickets. Read More Blog, Blue Team, Penetration Testing, Red Teaming

Kerberos II - Credential Access

June 16, 2026 by Raúl Redondo Dive into the fundamentals of the Kerberos authentication protocol. Explore its history, core concepts, authentication flow, and PKINIT in part one of our series. Read More Blog, Blue Team, Penetration Testing, Red Teaming

Kerberos I - Overview

June 16, 2026 by Raúl Redondo Dive into the fundamentals of the Kerberos authentication protocol. Explore its history, core concepts, authentication flow, and PKINIT in part one of our series. Read More Blog, Blue Team, Penetration Testing, Red Teaming

Empowering Organizations to Maximize Their Security Potential.

Lares is a security consulting firm that helps companies secure electronic, physical, intellectual, and financial assets through a unique blend of assessment, testing, and coaching since 2008.

18+ Years

In business

600+

Customers worldwide

4,500+

Engagements

Where There is Unity, There is Victory

[Ubi concordia, ibi victoria]

– Publius Syrus

Contact Lares Consulting logo (image)

Continuous defensive improvement through adversarial simulation and collaboration.

Email Us

©2025 Lares, a Damovo Company | All rights reserved.