Skip to content
Layer 6The governance stack/ Runtime

Runtime Security & Observability

What is happening right now — and would we notice?

The live control plane across every other layer: screening prompts and responses in the request path, detecting injection and leakage as they happen, watching posture across the AI estate, tracing every call end to end, keeping audit-grade logs, and holding the line on cost. This is where Gartner's TRiSM and Google's SAIF converge on the same message — policy that is not enforced at runtime is advice.

The risk, in one line

If you cannot see it in a trace or a log, you cannot govern it, prove it, or stop it.

Why leadership should care

  • 97% of organizations with AI-related breaches lacked proper AI access controls, and 63% had no AI governance policy at all (IBM, 2025) — the gap between stated policy and runtime reality is where breaches live.
  • Attackers already operate agentically: the first reported AI-orchestrated espionage campaign (disclosed Nov 2025) ran 80–90% of its operation through a jailbroken agent. Defense must run at the same speed.
  • Auditability is becoming a legal artifact: EU record-keeping duties and incident-reporting clocks assume you can reconstruct what your AI did and when.
97%
of organizations with AI-related breaches lacked AI access controls — IBM Cost of a Data Breach, 2025
Decisions only leadership can make
  • What minimum runtime screening applies to every AI call in the enterprise — the floor no team may drop below?
  • What must be reconstructable after an incident: prompts, sources, tools, approvals — and for how long?
  • Is AI security posture on the CISO dashboard with the same weight as cloud posture?
Read the claims right
PracticeGartner AI TRiSM (runtime enforcement)PracticeMITRE ATLASRegulationEU AI Act logging & incident dutiesVendor capabilityGoogle SAIF / CoSAI
How Google Cloud approaches this

Cards link to official documentation. Status is a snapshot (August 2026) — verify per component before contractual commitments. Full mapping and honest gaps: 08 · Google Cloud.

In the room — discussion points

Paper policies fail at machine speed. Runtime enforcement is where governance becomes real.

  • Gartner's TRiSM message in one line: AI governance needs runtime technical enforcement, not just policies. This layer is that enforcement.
  • Model Armor's floor settings are the CISO's favorite control: an organization-wide minimum no team can drop below — enforced even in the network path.
  • EchoLeak was zero-click. The defense that would have caught it lives here: treat retrieved content as untrusted, screen egress, watch anomalies.
  • Ask what percentage of AI interactions are fully reconstructable today. That number is the audit posture.
Questions to ask your organization
  • What screening applies to every model call in your enterprise today — including apps that bypassed the platform team?
  • Could you reconstruct a specific AI interaction from last Tuesday — prompt, sources, tools, output?
  • Who watches for anomalous AI behavior, and what happened the last time something looked wrong?
  • Are your AI assets in your security posture tooling, or only your VMs and buckets?
  • What would a prompt-injection attempt against your flagship AI app look like in your SOC?