Light Mode
Home Tools Work Partners Archive
Lab Note 10 min read 21 August 2026 SL-LN-26-002

Why SaintsLink Is Researching AI Security

S
SaintsLink Research
Official Publication

There is a point in the development of any technology where it stops being something people experiment with and starts becoming part of how things operate. Artificial intelligence is approaching that point.

Businesses are using AI to write, analyse, communicate, develop software, automate processes, make decisions, and interact with customers. Developers are embedding models into applications. Companies are connecting AI systems to internal knowledge bases, APIs, databases and operational tools. The next stage is already beginning to emerge: AI systems that do not simply answer questions, but take action.

That changes the conversation.

For SaintsLink, the question is no longer simply what artificial intelligence can do. The more important question is: what infrastructure will be required for AI to be trusted at scale? That question is what led us into AI security.

We are not researching AI security because it is currently one of the most discussed areas of technology. We are researching it because we believe the security problems surrounding AI will become increasingly important as AI moves deeper into business infrastructure. The earlier we understand those problems, the better positioned we are to build around them.

Why We Started Looking

Technology has always created new opportunities and new risks at the same time. The internet changed how businesses communicate and operate. Cloud computing changed where infrastructure lived. Mobile computing changed how people interacted with software. Each transition created an entirely new security landscape.

AI is different because the technology itself participates in the interaction.

A traditional application generally follows rules defined by developers. An AI system can interpret information, generate outputs, reason across context, interact with tools and, increasingly, make decisions within defined boundaries. That creates a different kind of attack surface.

A business might connect an AI system to its customer database. It might give an AI assistant access to internal documents. It might allow an AI agent to send emails, create records, execute workflows or interact with external services. The model may be powerful, but power without appropriate boundaries introduces risk.

This is where we believe AI security becomes more than another category within cybersecurity. It becomes an infrastructure problem.

The Attack Surface Is Expanding

One of the first things our research made clear is that securing AI cannot simply mean securing the model. The model is only one component.

An AI-enabled system can involve users, interfaces, prompts, models, data, retrieval systems, APIs, tools, agents and the underlying infrastructure. Every connection introduces another consideration.

A model can be manipulated through malicious inputs. Sensitive information can potentially be exposed through poorly designed workflows. Retrieval systems can introduce untrusted or manipulated information into model context. APIs can provide access to systems far beyond what the model itself was originally designed to access.

Agents introduce another layer entirely because they can transform AI from something that produces an answer into something that does something. The security perimeter therefore becomes much larger. And that is one of the reasons we believe traditional security thinking will need to evolve alongside AI adoption.

From Models to Agents

The emergence of AI agents is particularly important to our research.

A chatbot answering a question is one thing. An AI system that can access a database, retrieve company information, interact with APIs, create or modify records, send communications, execute workflows, use external tools and make decisions within predefined boundaries is something else entirely. The difference is agency.

Once an AI system can act, questions around identity, authorisation, permissions, monitoring, auditability and containment become increasingly important. What happens when an agent has access to information it does not need? What happens when a malicious instruction attempts to manipulate the agent? What happens when an agent is given a tool that can perform an action with real-world consequences? What happens when several agents interact with one another?

These are not theoretical questions that can simply be postponed until AI becomes more advanced. The infrastructure is being built now.

The Research We Have Undertaken

This is why our current AI-security research has gone considerably deeper than a conventional article or market overview.

SaintsLink has undertaken an extensive research project examining the emerging AI-security landscape across its technical, operational and strategic dimensions. The resulting research document is approximately 547 pages and 64,898 words. It is one of the largest research projects we have undertaken to date.

The document examines areas including AI threats, attack surfaces, security frameworks, model risks, data security, AI agents, governance, infrastructure and the broader evolution of security as artificial intelligence becomes embedded into software and business systems.

The full research document is being made available through the SaintsLink Library. But the document itself is not the destination. It is the beginning.

What We Are Trying to Understand

Our objective is not simply to catalogue vulnerabilities. That would be useful, but insufficient.

We want to understand what a secure AI operating environment could eventually look like. That means thinking beyond individual models and individual vulnerabilities. We are interested in the layers surrounding AI.

How should models be tested? How should AI applications be monitored? How should sensitive information be protected? How should agents be given permissions? How should AI systems communicate with other systems? How can organisations detect malicious behaviour? How can security teams understand what an AI system has done? How should multiple models be evaluated against the same security standards?

And perhaps most importantly: how do we build AI systems that are powerful without making them unnecessarily dangerous? These questions are shaping the direction of our research.

Where Genesis Fits

Genesis is particularly important to this conversation. Genesis is our AI initiative — but our ambition for it extends beyond simply creating another AI assistant. We are interested in what happens when intelligence becomes part of a larger operational system.

Genesis is therefore an important component of our broader AI strategy, and AI security needs to be considered alongside that strategy from the beginning. We do not want security to be something added after an AI product has been built. We want to understand how security can exist within the architecture itself.

That means considering areas such as identity — who is interacting with the system — permissions, context, monitoring, validation, containment, auditability and model security. These are not features we are claiming to have solved today. They are areas we are actively trying to understand. That distinction matters.

From Research to Infrastructure

Our research has led us to think about AI security as a progression rather than a single product. We are currently exploring a broader roadmap that moves from understanding the problem toward building increasingly capable security infrastructure.

The early stage is research: understand the threat landscape, study existing frameworks, identify gaps, test assumptions. From there, our thinking progresses toward areas such as an AI Security Scanner — a system capable of identifying potential weaknesses within AI implementations — an AI Security Lab for controlled experimentation and security testing, multi-model security testing across comparable scenarios, an AI Security Gateway positioned between AI systems and the environments they interact with, and eventually a more comprehensive AI Security Operations capability.

This is a roadmap for research and exploration, not a claim that all of these systems already exist. We are deliberately documenting the direction because we believe understanding where technology is going is part of deciding where SaintsLink should go.

Why We Are Taking This Seriously

There is a temptation in technology to wait. Wait until the market is established. Wait until customers start asking. Wait until competitors have built something. Wait until the problem becomes obvious.

That approach can work for some businesses. It is not how we want to build SaintsLink.

We want to spend time understanding technologies before their full consequences become obvious. That does not mean chasing every trend — in fact, it means the opposite. We need to distinguish between technologies that are temporarily interesting and technologies that are likely to become foundational. AI increasingly looks like the latter. And if AI becomes infrastructure, then AI security will become infrastructure too.

The African Context Matters

There is another reason this research matters to us. SaintsLink is being built with Africa firmly within its long-term perspective.

AI adoption in African businesses will not happen in exactly the same way as it does in Silicon Valley, Europe or other highly developed technology markets. Businesses operate within different infrastructure constraints, regulatory environments, budgets, skills environments and levels of digital maturity. That creates both challenges and opportunities.

We believe AI security should not become something that only large global enterprises can afford. If AI becomes part of how African businesses operate, then the security infrastructure surrounding that AI needs to be accessible, practical and appropriate to those businesses as well. That is an area we intend to understand more deeply.

Research Before Product

One of the principles we have repeatedly returned to at SaintsLink is that research should come before unnecessary building. It is tempting to see a problem and immediately start writing software. We would rather understand the problem first.

What already exists? What works? What does not? Where are the gaps? What assumptions are wrong? What are the actual technical constraints? What would customers genuinely need? What should be built — and, perhaps most importantly, what should not be built?

The size of our AI-security research project is partly a reflection of this philosophy. We would rather spend significant time understanding the landscape than rush into building something simply because the opportunity looks attractive.

What Comes Next

The next stage is experimentation. Research tells us what the landscape looks like. The next question is whether our assumptions survive contact with reality. That means testing: testing models, testing prompts, testing AI applications, testing agents, testing integrations, testing security controls, and testing where existing frameworks succeed and where they leave gaps.

A research document can explain a vulnerability. A controlled environment allows us to investigate it. Eventually, experimentation can inform engineering. And engineering can inform infrastructure. That is the progression we are interested in: research, then experimentation, then validation, then engineering, then infrastructure. We are not trying to skip steps.

A Long-Term Research Area

AI security is unlikely to be a short-term project for SaintsLink. We expect the subject itself to evolve. The risks associated with today's models may not be the same as those associated with increasingly autonomous systems. The security architecture required for a chatbot is different from the architecture required for an AI agent managing business operations.

That means our research will need to evolve with the technology. We expect to continue studying AI agents, model security, prompt injection, data security, AI governance, AI infrastructure, multi-model environments, autonomous systems, AI supply chains, enterprise AI security and AI safety and reliability. The objective is not to produce one definitive answer. The objective is to keep learning.

What We Believe

Our current position is relatively simple. AI will increasingly become part of business infrastructure. As that happens, the security surrounding AI cannot remain an afterthought. Security needs to exist across the entire AI stack: models, data, applications, users, agents, tools, APIs, infrastructure, and the connections between them.

We believe the organisations that understand this early will have an advantage — not simply because they will be more secure, but because they will be more capable of trusting the systems they build. Trust is ultimately what this research is about. Not making AI less powerful. Making it possible to use that power responsibly.

The Work Ahead

The 547-page research document represents a significant amount of work. But we do not consider it a finished answer. We consider it a starting point. It gives us a foundation from which to ask better questions, conduct better experiments and eventually make better engineering decisions.

The next phase will require testing. Then building. Then testing again. Some ideas will work. Some will not. Some problems will prove to be more complicated than we initially expected. That is precisely why we are researching them.

SaintsLink is still early in this journey. We are not presenting ourselves as having solved AI security. We are documenting that we are actively trying to understand it. And that distinction is important to us.

Because the companies that will build meaningful AI infrastructure in the future will not only be the companies that know how to use AI. They will be the companies that understand how to build systems around it that people can trust. That is the problem we want to spend time understanding.

SaintsLink Perspective

This is where our AI security research begins. The research document is available in the SaintsLink Library.

Return to SaintsLink Archive

Related Publications

Products Sep 2026

CRM Documentation v2.1

Updated pipeline tracking features and API webhook integrations.

Read More
Guides Aug 2026

Website Launch Guide

The ultimate 30-point checklist for launching enterprise web applications.

Read More