You have probably noticed the pattern by now: your executives want “AI everywhere,” vendors are pitching magical copilots for security, and regulators are asking pointed questions about model risk. But when you look around the room and ask “Who here actually knows how to secure this stuff?” the silence is loud.

AI has slipped into nearly every corner of modern infrastructure: recommendation systems, fraud detection, internal copilots, autonomous agents, and public-facing chatbots. Yet your security team and developers were trained for web apps, networks, and maybe a bit of cloud – not for jailbreaking large language models or defending against data poisoning attacks.

This is the heart of the AI security skills shortage. We do not just lack cybersecurity people in general (though that is a problem). We lack people who can reason about models, data pipelines, prompt injection, agentic behavior, and governance frameworks – and then turn that into practical controls. As AI becomes critical infrastructure, this shortage turns into a simple, uncomfortable question: who will actually protect our AI systems?

The skills gap just got an AI-shaped hole

You are not imagining it: the baseline cybersecurity workforce shortage is already severe. Industry studies and workforce trackers consistently report millions of unfilled cybersecurity roles worldwide, with many organizations saying they cannot find candidates with the right skills even for traditional security functions like cloud, identity, and incident response.NIST analysis of AI and the cybersecurity workforce

Now layer AI on top of that.

Recent workforce research shows that AI-related security skills have jumped into the top tier of in-demand capabilities, as organizations scramble to secure generative AI, agentic systems, and AI-augmented operations.IBM’s summary of the ISC2 Cybersecurity Workforce Study At the same time, many security leaders admit they do not know exactly which AI skills they should even be hiring for, much less how to assess them.

You end up with a paradox:

  • Boards, regulators, and customers demand “secure and trustworthy AI.”
  • Attackers are already using AI to scale phishing, malware generation, and reconnaissance.
  • Security teams are still learning the vocabulary – let alone how to test or certify an AI system.

The result is a widening gap between what your organization is deploying and what your people actually know how to defend.

Why AI systems are a different kind of security problem

It is tempting to treat AI like “just another app” and throw standard appsec at it. You absolutely still need identity, access control, logging, and secure SDLC. But AI systems are also vulnerable in ways traditional web apps are not.

NIST’s AI Risk Management Framework (AI RMF) calls out “secure and resilient” as a core property of trustworthy AI and highlights model-specific risks like data poisoning, adversarial input manipulation, and model theft.NIST AI Risk Management Framework In practice, that means your defenders now have to think about:

  • Prompt injection and jailbreaks: Attackers craft inputs that trick models like ChatGPT, Claude, or Gemini into ignoring instructions, leaking secrets, or calling tools in dangerous ways.
  • Training data poisoning: If an attacker can influence the data used to train or fine-tune your models, they can bias outcomes or plant latent backdoors.
  • Model extraction and theft: Repeated queries might let an attacker approximate your proprietary model or steal its behavior.
  • Adversarial examples: Slightly modified inputs (an image, text, even audio) that look normal to humans but cause the model to make critical mistakes.
  • Agentic behavior: AI agents that can call APIs, modify files, and chain actions, dramatically raising the blast radius when something goes wrong.

These risks cut across traditional silos: data science, MLOps, cloud security, application security, and governance. Very few professionals were trained to think across all of these at once.

What “AI security skills” actually mean in practice

One problem with closing the skills gap is that “AI security” sounds vague. If you are trying to hire or upskill, it helps to be specific about what skills you actually need.

Real-world AI security competence usually blends several domains:

  • Classical cybersecurity: Threat modeling, identity and access management, logging and monitoring, incident response, secure deployment.
  • ML and data literacy: Understanding how models are trained, evaluated, and deployed (especially LLMs and transformer architectures); knowing what a dataset, feature store, or embedding index is.
  • AI-specific threat modeling: Identifying prompt injection vectors, data poisoning risks, model theft scenarios, and abuse of AI agents or tool-calling.
  • Risk and governance: Mapping systems to frameworks like NIST AI RMF, documenting intended use, impact on people, and external regulatory requirements.
  • Hands-on testing: Red-teaming and “jailbreak” testing of ChatGPT-style systems, adversarial testing of vision or speech models, and fuzzing AI inputs.

NIST emphasizes that security for AI is not just about hardening models, but about the full lifecycle – from data collection and training to deployment, monitoring, and retirement.NIST AI research on security and resilience That requires people who understand both the technical guts and the socio-technical impact.

If your current team is strong in network security but weak in ML, or vice versa, you effectively have only half a defender.

AI helps defenders – but demands new judgment

It is not all bad news. AI is also becoming a force multiplier for security teams, especially when you are understaffed.

Security professionals are already using tools like ChatGPT, Claude, and Gemini to:

  • Draft detection rules and scripts faster (then review them carefully).
  • Summarize long incident reports or log trails.
  • Generate “first pass” threat intelligence summaries and correlation hypotheses.
  • Explain obscure vulnerabilities or logs in more approachable language.

Studies of cybersecurity practitioners show strong adoption of AI tools, but also highlight a new burden: deciding when to trust AI output. A significant share of security pros using AI say they spend substantial time reviewing, correcting, or discarding AI-generated recommendations.Recent coverage of AI use by cyber professionals

That introduces a new class of skills:

  • Knowing when an AI suggestion is plausible but wrong.
  • Understanding where hallucinations are most likely.
  • Ensuring sensitive data is not accidentally fed into third-party AI tools.
  • Designing “human-on-the-loop” workflows, where AI proposes and humans dispose.

In other words, using AI well in security requires critical thinking, domain knowledge, and judgment – the very human capacities that are already in short supply.

Training, hiring, or outsourcing: none are easy

So how are organizations trying to close the AI security skills gap? Most are experimenting on multiple fronts at once.

1. Upskilling existing security and engineering staff

This is often the fastest path. Security pros are being nudged (or pushed) to learn:

  • Basic ML concepts (training vs inference, overfitting, embeddings).
  • AI-specific threat models and attack techniques.
  • How to apply frameworks like NIST AI RMF to real projects.

Professional bodies and standards groups are starting to respond. For example, NIST’s AI Resource Center publishes guides and playbooks to help organizations operationalize AI risk management.
NIST AI Resource Center (AIRC)

You can expect more certifications and course content to bake AI topics into mainstream security training over the next few years.

2. Hiring hybrid “AI security” roles

Some organizations are trying to hire dedicated AI security engineers or AI risk leads – people who can sit between data science and security and speak both languages. The problem is obvious: everybody wants them, almost nobody has them, and expectations are often unrealistic (10 years of LLM red-teaming experience, anyone?).

This is driving:

  • High competition and salaries for people who can show credible hands-on AI security experience.
  • A lot of “learning on the job,” even for people hired as supposed experts.
  • Frustration when job descriptions demand everything from deep MLOps to policy drafting.

3. Leaning on vendors and managed services

Security vendors are rushing to market with “LLM firewalls,” “prompt shields,” “AI red-teaming as a service,” and so on. Managed security service providers (MSSPs) are also building AI security offerings, including AI-driven pentesting and AI monitoring.

These can be helpful, but they are not a substitute for internal skills. You still need people inside your organization who understand:

  • What the vendor tools are actually doing.
  • How they integrate with your existing controls.
  • How to interpret their outputs and make decisions.

Think of vendors as force multipliers, not guardians of last resort.

So who will protect our AI systems?

No single group can cover the gap alone. Realistically, AI security will become a shared responsibility across multiple roles:

  • Security engineers and architects who learn enough ML to design robust controls.
  • ML and data engineers who learn enough security to build safer pipelines and deployments.
  • Product and risk leaders who own AI use cases and align them with frameworks like NIST AI RMF.
  • External partners (red teams, MSSPs, auditors) who stress-test and validate.

The uncomfortable truth is that for the next few years, many organizations will be running mission-critical AI systems with incomplete defenses simply because the right skills are scarce and still being defined. Your job is to make sure you are not blindly in that group.

What you can do next, starting now

You do not have to solve the global AI security skills shortage. You only have to start closing the gap in your own sphere of control. Here are three concrete moves you can take in the next 30–60 days:

  1. Map your AI exposure and name an owner.
    Make a simple inventory: where are you using AI today (internal tools, customer-facing features, third-party copilots, shadow AI in departments)? For each one, name a security owner and a business owner. If there is an AI project with no clear owner, that is your first red flag.

  2. Create a focused AI security learning path for your team.
    Pick a small group of motivated security and engineering staff and give them time and budget to upskill on AI-specific threats and frameworks. Use reputable sources that connect NIST AI RMF to practical security work, and encourage hands-on experimentation with tools like ChatGPT, Claude, and Gemini – including safe red-teaming exercises against your own prototypes.

  3. Pilot one AI-aware control and measure the impact.
    Do not try to boil the ocean. Choose a single high-risk AI system and implement one meaningful control: an LLM firewall in front of a chatbot, stronger access controls for model management, or an AI-specific incident runbook. Measure outcomes (blocked prompt injections, fewer data exposure risks, clearer decision trails) and use that evidence to justify further investment.

The AI security skills shortage is real, but it is not static. Every experiment you run, every person you upskill, and every control you operationalize is one more step toward a world where our AI systems are not just powerful, but genuinely protected.