AI All-in-One series · Enterprise architecture

AI Security Architecture All-in-One by Kai London

Controls bolted on after go-live do not hold. This is the architecture handbook for enterprise AI platforms — where the trust boundaries sit, how identity flows through an agent, what a retrieval layer is allowed to reach, and which decisions you cannot reverse later.

Available on Amazon.

What is inside

Reference architecture

A layered view of an enterprise AI platform, with the control point named at every layer.

LLM, RAG and MCP boundaries

Where untrusted content enters, what it is permitted to influence, and how to stop context becoming instruction.

Identity for agents and workloads

Authentication, authorisation, delegation and least privilege when the caller is a model rather than a person.

Data security and residency

Classification, retention, embeddings and the quiet ways sensitive data leaks into a vector store.

APIs, cloud and the supply chain

Gateways, rate and cost controls, model provenance, and third-party dependencies you do not control.

Zero Trust applied to AI

Continuous verification, segmentation and observability translated from network doctrine into AI platform design.

Who it is for: security and enterprise architects, platform and MLOps engineers, and the CISOs and engineering leaders reviewing their designs.

Zero TrustISO/IEC 42001NIST AI RMFOWASP Top 10 for LLMsISO/IEC 27001

Context is not instruction. Design as if the model will believe everything it reads.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.