AI Security Is an Engineering Problem — How to Solve It at Every Layer of the Agent Stack
NVIDIA’s chief security officer argues that AI security is an engineering problem requiring defined requirements, enforceable controls, named owners and evidence that protections work. This piece takes each of those four against measured practice: a survey of 750 senior technology leaders in the UK and US found 7.2% have a formally accountable individual, 48% of production agents running unsecured, 54% already hit by an incident, and confidence in visibility rising nine points while monitoring coverage stayed flat. It walks the three-layer model of models, harnesses and runtimes, the worked prompt-injection case NVIDIA uses, the tooling now attached to each layer, and the structural test for telling a real boundary from a guardrail.