SAP’s Cybersecurity Strategy for Generative AI
Generative Artificial Intelligence (GenAI) is revolutionizing the way companies work. It not only boosts efficiency and creativity but also transforms entire business processes—from product development to customer service. However, it’s important to recognize that these new opportunities also bring new risks. SAP® addresses these challenges with a clear mission: to ensure the secure, responsible, and ethically sound use of GenAI.
What is Generative Artificial Intelligence (GenAI)?
Generative Artificial Intelligence (GenAI) refers to AI systems capable of independently creating new content such as text, images, code, or audio. Unlike traditional AI, which primarily analyzes or classifies, GenAI actively generates new outcomes based on large datasets.
Examples: ChatGPT, DALL·E, GitHub Copilot
Application Areas: Marketing, customer service, software development, product design
GenAI offers significant potential for efficiency and innovation, but it also requires clear rules for safety and ethics within the organization.
Three risk dimensions in focus:
Adoption, Vulnerabilities, Abuse
SAP’s cybersecurity strategy analyzes GenAI based on three key risk dimensions:
1. Adoption Risks – Risks during implementation
Potential dangers during the adoption of GenAI include data leaks, lack of transparency, and unintended errors. To address these risks, SAP provides comprehensive training, clearly defined governance structures, and modern access controls.
2. Vulnerability Risks – Emerging weaknesses
Attack vectors such as prompt injection, flawed token processing, or so-called hallucinations of AI systems require new defense strategies. SAP counters these threats with explainable AI models, standardized security patterns, and ongoing vulnerability assessments.
3. Weaponization Risks – Abuse by attackers
It’s important to note that generative AI can also be misused to create exploits or automate phishing attacks. To proactively mitigate this risk, SAP uses red teaming methods to identify and address vulnerabilities early on.
Security by Design:
The NIST Cybersecurity Framework for GenAI
SAP® follows a proven model: the NIST Cybersecurity Framework. This framework has been consistently adapted to meet the demands of Generative AI, with six core security functions:
-
Govern: Ethical guidelines and clear responsibilities for handling AI
-
Identify: Protection of especially sensitive data during training and operation
-
Protect: Technical and organizational measures to prevent attacks
-
Detect: Real-time monitoring and explainable security analytics
-
Respond: Response strategies for both traditional and novel attack scenarios
-
Recover: Sustainable improvement through root cause analysis and lessons learned
Data Security as a Core Principle
At the heart of the security strategy is the protection of sensitive information:
It is crucial to ensure the highest level of protection for personal data, corporate know-how, and intellectual property.
-
Consistent data classification and anonymization
-
Protective measures across all processing layers
-
Defense mechanisms against model manipulation and intellectual property theft
Collaboration is key
When it comes to cybersecurity in the context of GenAI, it’s important to recognize that this is not merely a technical challenge—it must be seen as a collective responsibility. SAP® places strong emphasis on close collaboration with customers, partners, and the broader community. It is important to highlight that AI technologies are intended to support human work, not replace it. People remain the decisive factor.
Conclusion:
Security is not a compromise – it’s a must
SAP® demonstrates impressively how responsible use of AI can succeed: through holistic strategies, technical excellence, and a culture of collaboration. This enables organizations to harness the tremendous potential of generative AI without losing sight of security.